Privacy Policy
Last updated: · Draft (pre-launch)
Zipppo ("Zipppo", "we", "us") builds a private, searchable index over email that you explicitly connect. This policy explains what we access, how we use it, and the choices you have. By connecting an account you agree to this policy.
What we access
When you connect a Google account, we request Gmail scopes that let us read your messages to build your index, and — once you approve rules — organize your mailbox on your behalf: applying and removing labels, archiving (moving mail out of the inbox), and marking messages read. Zipppo never deletes mail. There is no delete or trash capability anywhere in the product, and every action Zipppo takes is recorded and reversible from your dashboard. We only access the account you connect.
When you connect a Telegram account, you sign in to Telegram with your own phone number and API credentials, and Zipppo reads your direct messages and group chats to include them in your index (broadcast channels are excluded). Access is read-only: Zipppo never sends, edits, or deletes Telegram messages. The sign-in session is stored encrypted like every other credential and is removed when you disconnect the account.
What we store — and what we don't
We do not store your original emails or attachments. Message content is fetched, processed in memory to produce a derived index (extracted text, classifications, and numeric embeddings used for search) plus the working copy that powers your dashboard (subjects, snippets, and message previews), and the original bytes are then discarded. Derived content is encrypted at rest with a key unique to your account and is only ever decrypted for you: in your signed-in browser session and in the worker that maintains your index. Routing metadata used to sort your mail (sender addresses, domains, dates, categories) is stored alongside it.
How we use Google user data
Gmail data is used solely to provide the Zipppo product to you: building and maintaining your personal searchable index and answering your queries. We do not use Gmail data for advertising, and we do not sell it. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing
We do not share your data with third parties except the sub-processors that help us operate the service, and only as needed to provide the product:
- OpenAI — message content is sent to OpenAI's API to extract text, classify mail, and generate the embeddings that power search. This data is processed under OpenAI's API terms: it is not used to train their models.
- Supabase / Amazon Web Services — cloud database and infrastructure hosting for your encrypted index.
- Telegram — only if you connect Telegram notifications: the sender and subject line of messages matching your notify rules are delivered to your Telegram chat.
We do not sell your data. We may disclose information if required by law.
Retention & deletion
Your derived index is retained while your account is active. You can disconnect a mailbox at any time — its stored credentials are deleted immediately and Zipppo stops accessing it. To delete your indexed data as well, email us at the address below; deletion is completed within 30 days. You may also revoke access directly from your Google Account permissions.
Security
Derived content is encrypted at rest with a per-account key (AES-256-GCM); access is restricted to your account, and outbound mail credentials are held in an encrypted vault. Original message bytes are never persisted to durable storage.
Contact
Questions about this policy? Email schwartzidavid@gmail.com.