RadMail · Legal
Privacy Policy
Last updated July 26, 2026. This policy explains what data RadMail accesses, how we use it, how we store and protect it, and the choices you have. It includes our specific commitments for Google user data.
Who we are
RadMail is an email operating system for agents and their operators: it triages your inbox by importance and urgency, explains why each message surfaced, tracks the commitments in a thread, and drafts replies for review. A hard safety rule sits under everything — money, changed banking details, first-contact senders, and irreversible decisions are held for a human and are never sent autonomously (our defense against business-email compromise).
What data we access
We access only what a feature you turn on needs:
- Account data — your name, email address, and workspace/organization details you provide at sign-up.
- Google / Gmail data (only if you connect Gmail) — with your explicit consent we request the
gmail.readonlyscope, which lets RadMail read your messages and metadata so it can triage them, explain why each surfaced, and draft replies you review. We do not request send, modify, or delete access on Gmail. You can connect Microsoft 365 instead, or use the zero-connection sandbox. - Usage data — standard security and reliability logs (never message content in logs).
Google user data — Limited Use commitments
RadMail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the user-facing features described above.
- We do not transfer or sell Google user data to third parties for advertising, resale, or any unrelated purpose.
- We do not use Google user data for advertising of any kind.
- We do not allow humans to read Google user data, except: with your explicit consent; where necessary for security purposes (such as investigating abuse) or to comply with applicable law; or when the data has been aggregated and anonymized. Email content is fenced as untrusted input to our models and, for regulated tenants, is routed only to a BAA-covered model endpoint.
How we use your data
To operate the product: rank and surface mail, explain the ranking, track commitments, and prepare draft replies for your review. We do not sell your data. We do not use your email content to train third-party foundation models.
How we store and protect it
Data is encrypted in transit and at rest, isolated per tenant with database row-level security, and access is role-based and logged in an append-only audit trail. The full security posture and the list of subprocessors that may process data on our behalf are published on our Trust & Compliance page. For HIPAA tenants we sign a Business Associate Agreement; for federal tenants we operate on FedRAMP-aligned infrastructure under a shared-responsibility model.
Retention & deletion
We retain your data for as long as your account is active. You can disconnect Gmail (or any mailbox) at any time from your settings, and you can revoke RadMail’s access directly from your Google Account permissions. On disconnection we stop accessing new data; on account deletion we delete your stored data and revoke stored tokens. We complete a deletion request within 30 days, including removing your data from encrypted backups on the same cycle. Request deletion any time at the contact below.
Your choices
Connect only the mailboxes you want; disconnect or revoke access at any time; request a copy or deletion of your data. Where applicable law grants additional rights (access, correction, portability, objection), you can exercise them via the contact below.
Contact
Questions about this policy or a data request: email privacy@radmail.ai. We’ll respond within a reasonable time.
RadMail v0.80.0 · Home · Trust & Compliance