Effective September 28, 2026

Privacy Policy

AtEmail reads the Gmail accounts you connect so it can show them in one inbox and send the messages that match your rules to the systems you choose. This policy explains exactly what that involves.

Overview

This Privacy Policy describes how OneTouchGrade (“we”, “us”) handles information when you use AtEmail (the “Service”), including the website and the web application.

In short:

  • We access your Gmail data only to provide the features you use in AtEmail.
  • We do not sell your data, and we do not use it for advertising.
  • People at OneTouchGrade do not read your email, except in the narrow cases described in the Limited Use disclosure.
  • Your data is not used to train artificial intelligence models.
  • You can revoke access and ask us to delete your data at any time.

Information we collect

Information you give us

  • Account details: your email address and a password, which we store only as a salted hash.
  • Configuration: the email criteria (rules) you create, and the webhooks you add: a name, a destination URL, optional custom headers, and an optional signing secret.
  • Team data: if you administer a workspace, the users you invite and the roles and permissions you assign them.

Information from your Google account

When you connect a Gmail account, we receive the data described in Google user data below.

Information collected automatically

Our servers record standard technical information, such as IP address, browser type, request times and error details, to operate and secure the Service. We do not use advertising or cross-site tracking cookies. The web application stores its sign-in session in your browser’s local storage, and remembers your light or dark theme preference there.

Google user data

AtEmail connects to Gmail through Google’s OAuth consent screen. You choose which accounts to connect, and you must have the right to grant access to each one. We request the following permissions:

PermissionWhy we need it
View your email messages and settings (gmail.readonly)To sync messages into your unified inbox, show threads and attachments, and evaluate each new message against the rules you create.
Send email on your behalf (gmail.send)To send the messages you compose, reply to, or forward from within AtEmail. We only send a message when you explicitly send it.
Read, compose and send email, and modify labels (gmail.modify)Requested at sign-in. AtEmail does not currently change, label, archive or delete your messages in Gmail.
Your email address and basic profile (userinfo.email, userinfo.profile)To identify which Google account you connected and display its address and name.

What we store

For each connected account we store:

  • OAuth access and refresh tokens, encrypted with AES-256-GCM before they are written to our database.
  • Message data: sender, recipients, subject, date, Gmail labels, the snippet Gmail provides, and the message body in plain text and HTML.
  • Attachment metadata: file name, type and size. The file itself is fetched from Gmail when you open it. If attachment caching is enabled, a copy is kept in our private storage to speed up later downloads.
  • The AI summary generated for a message, if one was generated.

How we use it

We use Google user data only to provide and improve the user-facing features of AtEmail:

  • showing your connected mailboxes in one inbox;
  • matching new messages against the email criteria you create;
  • generating summaries of matched messages;
  • delivering matched messages to the webhook destinations you configure;
  • sending, replying to and forwarding messages when you ask us to; and
  • keeping the Service secure and working, including troubleshooting problems you report.

Limited Use disclosure

AtEmail’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • We use Google user data only to provide or improve user-facing features that are prominent in the AtEmail interface.
  • We transfer Google user data to others only as needed to provide those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets after giving you notice.
  • We do not use or transfer Google user data to serve advertising, including retargeting, personalised or interest-based ads.
  • We do not sell Google user data, and we do not transfer it to data brokers or information resellers.
  • We do not use Google user data to determine creditworthiness or for lending purposes.
  • No person at OneTouchGrade reads your Google user data unless you give us explicit permission for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised for internal operations.
  • We do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models, and we do not permit our service providers to do so.

AI summaries

AtEmail generates a short summary only for messages that match an email criteria rule you created. It does not summarise every message in your mailbox.

To generate a summary we send the sender’s name, the subject, and up to the first 3,000 characters of the plain-text body to OpenAI’s API. OpenAI processes it as our service provider to return the summary. Under OpenAI’s API terms, data sent through the API is not used to train OpenAI’s models. OpenAI may retain API inputs for a limited period to monitor for abuse, as described in its policies.

The summary is stored with the message and included in webhook deliveries for that message.

Webhook deliveries

When a message matches one of your rules, AtEmail sends it to each webhook URL you linked to that rule. The delivery contains the message identifier, subject, sender, recipients, snippet, received time, Gmail labels and AI summary.

These transfers happen because you configured them. The destinations are systems you or your organisation control or have chosen, and their handling of the data is governed by their own terms and policies, not this one. Each delivery is signed with HMAC-SHA256 so your system can verify it came from AtEmail. We refuse destinations on private or internal networks, and we record each delivery attempt, including the status and a portion of the response, so you can audit it.

How we share data

We share data only with service providers that help us run AtEmail, under agreements that limit their use of it to providing services to us:

ProviderPurpose
Google LLCGmail API access, push notifications for new mail (Cloud Pub/Sub), sign-in with Google, and delivery of account email such as verification and password reset over Google Workspace SMTP.
NeonManaged PostgreSQL database that stores account, configuration and message data.
HostingerHosting for the AtEmail API servers and job queue.
VercelHosting for the AtEmail website and web application.
OpenAIGenerating AI summaries of messages that match your rules.
S3-compatible storage (if enabled)Caching attachment files to speed up downloads.

We may also disclose information when required by law, to protect the rights, property or safety of our users or others, or in connection with a merger, acquisition or sale of assets, in which case we will notify you and the recipient will be bound by this policy.

Security

  • All traffic to and from AtEmail is encrypted in transit with TLS.
  • OAuth tokens are encrypted at rest with AES-256-GCM, and the encryption key is stored separately from the database.
  • Access inside a workspace is controlled by roles with granular permissions.
  • Webhook destinations are checked for server-side request forgery when saved and again before every delivery.
  • Access to production systems is limited to personnel who need it to operate the Service.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you as required by law.

Retention and deletion

We keep your data for as long as your AtEmail account and connected Gmail accounts remain active, because the Service needs it to show your inbox and process your rules.

Revoking access

You can revoke AtEmail’s access to a Google account at any time from your Google Account permissions page. Once revoked, we can no longer read, sync or send mail for that account. Disconnecting an account inside AtEmail also stops syncing it.

Deleting your data

Revoking access or disconnecting an account stops new data from being collected, but does not by itself erase data already stored. To delete it, email hello@onetouchgrade.com from the address on your account and tell us which accounts or data to remove. Within 30 days we will permanently delete the Google user data we hold for those accounts, including OAuth tokens, synced messages, attachment metadata and cached files, AI summaries and delivery logs, and revoke our access with Google. Removed data may persist in encrypted backups for a short period until those backups expire.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact us at hello@onetouchgrade.com. We will respond within the time required by applicable law. You also have the right to complain to your local data protection authority.

Other terms

Children

AtEmail is a business tool and is not directed to anyone under 16. We do not knowingly collect personal information from children.

International transfers

Our service providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for those transfers.

Changes to this policy

We will post any changes on this page and update the effective date above. If a change materially affects how we use Google user data, we will notify you and, where required, ask for your consent before the change applies.

Contact us

OneTouchGrade
Vadodara, Gujarat, India - 390019
Privacy requests: hello@onetouchgrade.com

See also our Terms of Service.