Privacy Policy — Butler (working title)
_Draft v1.1, 2026-07-20. Plain language on purpose; every commitment here is
also an engineering constraint (see COMPLIANCE.md §6). Interim pilot domain:
butler.heyfirstname.io. Lawyer pass + legal entity details before
P2/verification submission._
The short version: Butler reads replies from the clients you list, and
leaves reply drafts in your Gmail. It cannot send email. We don't store your
messages. Your email never trains AI models. Disconnecting erases what little
we keep.
What Butler accesses, and why
When you connect Gmail you grant three permissions:
- Read your email (
gmail.readonly) — used for two things only: detecting
new messages from the client roster you configure, and (once, at setup)
reading your own sent replies so your drafts sound like you.
- Manage drafts (
gmail.compose) — used to create reply drafts. Google's
consent screen describes this permission as "manage drafts and send emails"
because Google offers no drafts-only permission — but **Butler has no
sending code path**. Not sending is the product's core rule, and it is a
contractual commitment in our terms.
- Manage labels (
gmail.labels) — used to create and apply theAI/…
labels that show you what Butler has seen, drafted, or escalated.
Butler deliberately does NOT request permissions that would let it archive,
delete, move, or send mail.
What we store — and what we never store
- We never store the content of your email. Message bodies are processed
in memory to triage and draft, then discarded.
- We keep only operational metadata: message and thread IDs, Gmail history
cursors, triage labels, draft IDs, your client roster and settings, and the
per-client facts you provide.
- Your Gmail access token is stored encrypted; the decryption key is held
separately from the database.
AI processing
Draft text is generated by Anthropic's Claude models via Anthropic's
commercial API, acting as our service provider. Anthropic does not use this
data to train its models. **We never use your Google user data to create,
train, or improve generalized AI or machine-learning models.** The only
"learning" Butler does is building and refreshing a private writing profile
scoped to your account alone — it is never combined with, or used for, any
other customer.
Google API Services — Limited Use disclosure
Butler's use and transfer of information received from Google APIs adheres to
the Google API Services User Data Policy,
including the Limited Use requirements. We use Google user data only to
provide and improve Butler's user-facing features, never for advertising,
never sold, and transferred to third parties only as necessary to provide the
feature (Anthropic, as described above), for security, or to comply with law.
Your controls
- Disconnect any time — one click in settings revokes Butler's Google
access. You can also revoke from your
Google account permissions page.
- Deletion — on disconnect (or on request), all stored metadata tied to
your account is erased within 30 days. Nothing else exists to delete.
- Export/questions — email us at [email protected].
Retention, security, changes
Operational metadata is kept while your account is active and for at most 30
days after disconnect. Data is encrypted in transit (TLS) and at rest. If
this policy changes materially we will email you before the change takes
effect; the current version always lives at butler.heyfirstname.io/privacy.html.
_Operator: Point Visible (full legal details to be added at the P2 lawyer
pass). Contact: [email protected]._