Privacy Policy

Last updated: October 2, 2026

Calibrate LLC (“we,” “our,” or “us”) operates Cleanmail, an AI-powered email digest service available on iOS. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using Cleanmail, you agree to the practices described here.

This policy is hosted at https://cleanmailapp.com/privacy and is referenced from our OAuth consent screen and in-app Settings.


1. Information We Collect

We collect only the information needed to provide and improve Cleanmail.

Information you provide directly:

Information collected from Google APIs (with your authorization):

Information collected automatically:


2. Google API Services and Limited Use

Cleanmail uses the following Google API scopes:

Google API Services Limited Use disclosure: Cleanmail’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:


3. How We Use Your Information

We use your information solely to provide and improve Cleanmail:

We do not sell, rent, or share your personal information with third parties for marketing purposes.


4. Third-Party Sub-Processors

Cleanmail relies on the following third parties to provide its service. Each receives only the data necessary for its function:

ServicePurposeData shared
Supabase (Supabase Inc., hosted in US East, Ohio)Database and serverless functionsYour profile, digest content, events, subscription state
Anthropic (Anthropic PBC)AI summarization and event extraction via the Claude API(a) the subject line and message body of emails from senders you have selected; (b) photos and PDFs you choose to scan; (c) the text of voice notes you record, which your device transcribes before anything is sent; (d) images and PDF attachments inside emails from senders you have selected, read to find dates and events; not stored. Sent at the time of the request and not used to train Anthropic’s models.
Google (Google LLC)Sign-in, Gmail access, Calendar syncOAuth tokens; Gmail messages from selected senders; the individual message you open via “View Email”; Calendar event metadata
Apple (Apple Inc.)Subscription billing via in-app purchasePurchase and subscription status (we never see card numbers or your Apple Account details)
Resend (Resend, Inc.)Transactional email delivery (household invitations)The recipient email address you enter when inviting a household member, and the inviter’s display name
Apple Push Notification serviceDelivery of push notificationsAnonymous device token
Trigger.devScheduled job execution for digest deliveryUser ID and digest ID at scheduled times: no email content

Anthropic is the only third party that receives your email content, your scanned documents, or the text of your voice notes, and it receives them only to produce the summaries and events you asked for. We do not send any of that content to any other AI service. Supabase stores the resulting summaries and events, not the raw email. The full body of an email you open via “View Email” is retrieved from Google and rendered on your device; it is not stored on our servers (see Section 5).

Every sub-processor listed above is bound by its agreement with us to protect the data it receives to a standard equal to or greater than the protections described in this policy, and to use that data only to provide the service described in its row.


5. Data Storage and Location

All data is stored in the Supabase region US East (Ohio). Raw email content is not stored at rest: emails are fetched from Gmail at digest-generation time, sent to Anthropic’s API for summarization, and discarded after the AI-generated summary is written to our database. Likewise, when you open an email via “View Email,” its full body is fetched from Gmail and rendered on your device for that viewing session only; it is not written to our database. Images and PDF attachments inside emails from your selected senders are fetched at digest-generation time only so they can be read for dates and events, and are never saved.

Photos and PDFs you scan are uploaded to a private storage area on our servers only for as long as it takes to read them, then deleted as the final step of the scan, whether it succeeded or failed. Voice notes are transcribed to text on your device; the audio recording itself is never uploaded and is never stored.

The following are stored persistently:


6. Shared Digests (Household)

Cleanmail lets a household share one digest: up to four people in total. The person who creates the digest is the Primary. The Primary can invite up to three other people to join. Any other adults the Primary designates are Household Leads, who can help manage the digest and the permissions of the other people in it; everyone else is a Household Member. Everyone in the household sees the same shared digest. This is different from linking an additional Gmail inbox to your own account (a “linked inbox”), which pools your own mailboxes and does not involve anyone else; this section concerns shared household digests only.

Each person connects their own Google account, and no one can read anyone else’s mailbox. Sender discovery, the search that finds senders to add to a digest, only ever searches the mailbox of the person performing the search. As a result:

Each person’s Gmail credentials remain private to them. Each person’s mailbox feeds the shared digest using that person’s own live authorization; we do not copy one person’s Google access to anyone else.

Leaving or being removed from a shared digest. The Primary can remove any Household Lead or Household Member, and anyone can leave on their own, at any time. When someone leaves or is removed:

To permanently delete your own personal data, see Section 7 (Account Deletion).


7. Data Retention and Account Deletion

Digest history is retained for the period you select in Settings (default 30 days; configurable up to 60 days). Older history is automatically deleted.

You may permanently delete your account and all associated data at any time from within the app: Settings → Delete Account. Account deletion is immediate and removes:

If you are part of a shared digest:

After deletion, no recovery is possible. If you have trouble deleting your account in the app, contact support@cleanmailapp.com and we will delete it manually within 30 days.


8. Your Rights

Depending on your jurisdiction, you may have the right to:

Residents of California (CCPA) and the European Union (GDPR) have additional rights under applicable law. To exercise any of these rights, contact support@cleanmailapp.com.


9. Security

We use industry-standard security measures including TLS-encrypted data transmission, encrypted storage via Supabase, and access controls on our serverless functions. OAuth tokens are stored encrypted at rest and never exposed to client devices.

No system is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you by email within 72 hours and report the incident as required by applicable law.


10. Children’s Privacy

Cleanmail is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided personal information to us, contact support@cleanmailapp.com and we will delete it.


We may disclose personal information when required to do so by law, such as in response to a subpoena, court order, or other legal process. We will notify you of any such request unless prohibited by law.


12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email and by updating the date at the top of this policy. Continued use of Cleanmail after changes take effect constitutes acceptance of the updated policy.


13. Contact

Questions about this Privacy Policy:

Calibrate LLC support@cleanmailapp.com

For privacy-specific inquiries, please include “Privacy” in the subject line.