Postface
Back

Security and data handling

Last updated: September 20, 2026

Postface reads your inbox so you don’t have to. That only works if the way it handles your data is boring and predictable. This page says exactly what happens.

  • Least access, read-only by default

    Gmail and Google Calendar are connected read-only. Postface can send a reply or move an event only when you ask it to in a message and confirm the draft it shows you. Nothing is ever sent or changed on your behalf without that confirmation.

  • Almost nothing is kept

    For each new message Postface stores the sender, subject, a short snippet and a relevance score. That record is deleted 24 hours after it has been included in a digest, and 48 hours at the very latest. Message bodies and attachments are never stored. Calendar events are read when you ask and are not stored at all.

  • Encrypted, and separated per person

    All traffic uses TLS and the database is encrypted at rest. Your Google connection is encrypted with a separate application key and is tied to your account alone; the database enforces row-level rules so one account can never read another's data.

  • Never sold, never used for ads or AI training

    Your data is used for one purpose: producing and delivering your messages. It is not sold, rented or shared for marketing, and it is never used to train AI models. Your phone number and your SMS consent are never shared with anyone for their own marketing.

  • Delete everything, in one tap

    Open Preferences in your Postface home and choose Delete my account. That revokes your Google connection, removes every stored item, and deletes your sign-in immediately. You can also revoke Postface's access directly in your Google Account at any time.

Who else touches your data

  • GoogleSource of the Gmail and Calendar data you connect, read-only.
  • AI providerWrites the summary sentences. Content is processed to produce your message and is not retained or used for training.
  • TwilioDelivers your text messages. Twilio sees the message and your number, and does not use them for anything else.
  • TelegramOnly if you choose to link it as a delivery channel.
  • Lovable Cloud (Supabase)Hosting and the encrypted database.

Google API data

Postface's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The permissions Postface asks for, and the reason for each one, are listed on how Postface uses your Google account. You can review or revoke access at any time at myaccount.google.com/permissions, and read Google’s API Services User Data Policy.

Reporting a problem

Found a vulnerability? Email support@postface.io with the details and how to reproduce it. We answer every report, we will not pursue anyone acting in good faith, and we ask that you give us a reasonable window to fix the issue before publishing it.

Postface