Mailroom helps you stay on top of your inbox. Here is exactly what it does with your data. Plain language first, precise detail underneath, and more in our security overview.
What it accesses. With your permission, Mailroom reads your mailbox. By default this is read-only: it can never move or delete anything. If you separately turn on the optional Send feature, it can send a reply, but only one you have written and tapped send on. It never sends on its own, and never moves or deletes mail.
What it does. It reads your recent unread mail and works out what needs a reply and what is noise, so it can show you what needs a reply and alert you to urgent items. To do that, the content of those emails is sent securely to our AI provider (Anthropic) purely to summarise and prioritise them.
Your writing style (optional). If you set up "Your voice" in Settings, Mailroom reads a sample of your recently sent mail once, sends it securely to the same AI provider purely to measure HOW you write (tone, length, greeting, sign-off), and keeps only that small style profile. The emails themselves are not kept for this, and the profile never contains message content. You can turn it off in Settings at any time (it stops being used immediately), and the profile is deleted when you disconnect.
What it never does. We never sell, rent or share your data, and only you ever see your inbox. Your email is never used to train any AI model. We never use it for advertising, and never give it to data brokers or resellers.
Your control. You can disconnect at any time, from your email provider's connected-apps settings or from Mailroom itself. Disconnecting deletes your stored data. Access ends immediately.
We ask for the narrowest set that makes the product work. We do not request permission to delete mail, and never have.
| Permission | Why we need it |
|---|---|
| Read your mailGoogle gmail.readonly · Microsoft Mail.Read | To read recent unread messages so we can tell you which need a reply and alert you to urgent ones. This is the core of the product. |
| Send a messageGoogle gmail.send · Microsoft Mail.Send | Optional, and off by default. Only requested if you switch Send on, and only ever used to send a reply you have written and tapped send on. |
| Your name and email addressopenid, email, profile, User.Read | To sign you in and know whose mailbox is whose. You sign in on your provider's own page, so we never see your password. |
| What | How long |
|---|---|
| Your access credential for your mailbox | Until you disconnect. Stored encrypted (AES-256-GCM). |
| A cache of recent message content, so your radar renders without re-fetching | Deleted automatically after 90 days, whether or not you are using the app. Also capped in size, so older entries drop away sooner as new mail arrives. Deleted entirely when you disconnect. |
| Summaries and draft replies generated for you | Deleted automatically after 90 days. Also capped in size, oldest dropped first. Deleted when you disconnect. |
| Activity records (which cards you actioned, and when) | Rotated after 35 days. Records the sender's domain only, never the message, never the full address. |
| A record of messages sent through Mailroom | Time, provider and recipient domain only. Never the message body, never the full recipient address. |
| Your settings, rules and signature | Until you change them or disconnect. |
| Your voice style profile (only if you set up "Your voice": tone, length, greeting and sign-off; never message content) | While your account is connected. Turning it off stops it being used; disconnecting deletes it. The sent mail read to build it is not kept. |
| Your voice example bank (only while "Your voice" is on): when a reply you actually send differs meaningfully from the suggested draft, the email and your reply are kept as an example of how you write, so future drafts sound more like you | Newest 40 examples, each deleted after 6 months. Turning "Your voice" off stops collection immediately; disconnecting deletes them all. |
One company, for one purpose. We keep this list short deliberately.
| Who | What they receive | Why |
|---|---|---|
| AnthropicClaude API | The sender, subject and body text of messages being triaged, and of a message you open. | To produce the priority verdict, summary and suggested reply you see in the app. Anthropic does not train models on this data and retains it only briefly before deleting it. |
| Your email providerGoogle or Microsoft | Nothing new — this is your own mailbox. | Reading your mail, and sending your reply if you enable Send. |
That is the complete list. Your mail is not sent anywhere else, by anyone, for any reason.
Open Mailroom and choose Disconnect, or revoke access from your provider's connected-apps settings. Disconnecting removes your stored credential and deletes your entire data directory: cached messages, summaries, settings, signature and activity records. It is immediate, and we keep no copy. You do not have to email anyone to make it happen.
Your data sits on a private server operated by The Solva Group in a single location, reachable only over an encrypted connection. It is not replicated to third-party clouds. The technical detail is in the security overview.
Questions, or a privacy request? Email mark@thesolvagroup.com and a human replies.
The Solva Group, Victoria, Australia. Last updated 2 August 2026.