Last updated: September 11, 2026
Triage ("we," "us," "our") provides an AI-assisted email triage service. This policy explains what information we collect, how we use it, and the choices you have. Triage is currently in early development; this policy will be expanded as the product grows.
Account information. When you sign in (via Google, Microsoft, or email/password), we store your email address and a unique identifier for your account.
Connected mailbox data. When you connect a Gmail account, we request
access to read and modify your email via Google's gmail.modify scope. We use
this access to identify messages that need your attention and to apply your triage
decisions (e.g. labeling a message as handled). We store, per connected mailbox:
an OAuth refresh token (encrypted, see "How we protect your data" below), the sender
and subject line of messages we've processed, and the triage decision you or our
classifier made about each one. We do not store the full body of your emails.
AI-assisted classification. For messages our rules-based and history-based logic can't confidently route on their own, and only if you've explicitly opted your account into AI-assisted triage (this is off by default), a short preview of that message's content may be sent to Anthropic's API to help decide how to route it. This is a single, stateless request — nothing about your account or prior emails is retained by that request. If you haven't opted in, or if this feature isn't configured, ambiguous messages are simply left for you to review by hand.
OAuth refresh tokens for connected mailboxes are encrypted before storage, using a per-connection encryption key that is itself protected by a cloud key-management service (Google Cloud KMS). Access to your data is scoped so that only the specific service that needs it (mailbox syncing) can decrypt it.
Triage's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
You can disconnect a mailbox at any time, which stops further access and allows you to request deletion of the associated stored data. You can request deletion of your account and all associated data by contacting us at the address below.
We'll update the "Last updated" date above when this policy changes. Material changes will be communicated to account holders directly.
Questions about this policy: hello@smartsby.com