TsugiteTsugite

This document is legally binding only in English. The page below is presented in English regardless of your selected language.

Privacy Policy

Last updated: May 18, 2026

This Privacy Policy describes how Tsugite ("we", "us") collects, uses, and protects information when you use the Tsugite service ("Service").

1. Information We Collect

a. Account information

When you sign in with Google, we receive your Google account ID, email address, and name from Google's OpenID Connect / userinfo endpoints.

b. Gmail access tokens

We store your Google OAuth access token and refresh token, encrypted at rest, in order to read Gmail metadata and message content needed to fulfill forwarding rules you configure. The Gmail scopes we request are limited to gmail.readonly.

c. Forwarding rules and metadata

For each rule we store what it matches on: a sender email address, a sender domain, a subject keyword, a Gmail label (its identifier and name), or a mailing list (the identifier from the List-ID header, its display name, and the posting and distribution addresses shown when you chose it). We also store the target Slack or Discord webhook URL, channel name, workspace name, and the timestamp and result (success/failure) of each forwarding attempt. When you search for mailing lists or senders, or list your Gmail labels, we read only headers and label names and show the results once; they are not stored. We do not store the subject line, body, or any content of the forwarded email itself.

d. Billing information

Payment processing is handled by Stripe. We store only the Stripe customer ID and subscription ID; we never receive or store payment card numbers.

2. How We Use Gmail Data (Google Limited Use)

Tsugite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Gmail data only to provide the forwarding feature you explicitly configured. We read: the headers of a message (sender, recipient, subject, date, Message-ID and mailing-list headers), its body, and the names and identifiers of the Gmail labels on it. When you set up a rule, we also read the sender and mailing-list headers of your recent messages, and your Gmail label names, so we can offer them as choices; those results are shown to you once and are not stored.
  • We do not sell Gmail data, or transfer it to data brokers, advertisers, or any other party, except to deliver a message to the Slack or Discord channel you chose and to the infrastructure providers listed in section 5.
  • We do not use Gmail data for advertising.
  • We do not use Gmail data to develop, improve, or train generalized AI/ML models, and we do not transfer it to any third-party service that would use it to train its models.
  • We do not allow humans to read Gmail data unless we have your explicit consent for specific support tickets, or as required by law.

3. Email Content Handling

Email content (subject and body) passes through server memory only during forwarding. We do not persist email content to disk or database. Once forwarded to your configured Slack or Discord webhook, the content exits our systems and is governed by that service's data handling.

4. Where Data Is Stored

Account information, forwarding rules, and logs are stored in Cloudflare D1 (SQLite) on Cloudflare's edge network. Google access and refresh tokens, and the webhook URLs of your Slack and Discord channels, are encrypted with AES-GCM using a key held only by the Service and never written to the database in plain text. All traffic to and from the Service uses HTTPS, and the site is served over HTTPS only (HSTS). No message subject or body is ever written to storage, so none exists to be read later. Access to the production environment is limited to the operator of the Service, whose accounts are protected by two-step verification and passkeys.

5. Third-Party Sub-Processors

  • Google (Gmail API, OAuth) — sign-in and email reading
  • Slack — destination for forwarded messages
  • Discord — destination for forwarded messages
  • Cloudflare — hosting, database, and edge runtime
  • Stripe — payment processing for paid plans

6. Data Retention

We retain account data, forwarding rules, and logs for as long as your account is active. We never retain message subjects or bodies at all. Forwarding logs older than 90 days are automatically purged, and the records used to avoid duplicate forwarding are purged after 7 days. You can delete any rule at any time from your dashboard, which deletes its stored settings. To delete your account, contact us at the email below; all associated data, including your stored Google tokens, is deleted within 30 days, except where retention is required by law or for fraud prevention. Revoking access from your Google Account permissions page immediately stops all further access to your Gmail.

7. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. You may also revoke Tsugite's access to your Gmail at any time from your Google Account permissions page. To exercise other rights, contact us at the email below.

8. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

9. Changes to This Policy

We may update this Privacy Policy. Material changes will be communicated via email or in-app notice.

10. Governing Language

This Privacy Policy is written in English. Translations are provided for convenience only. In the event of any discrepancy, the English version prevails.

11. Contact

For privacy questions or to exercise your rights, contact support@tsugite.org.