MailHandled

Privacy policy

Your mail is yours

MailHandled is a personal assistant for your email, calendar, and files, made by Hoshmand AI. This policy says exactly what we access, why, and what we will never do with it. Effective October 3, 2026.

What we access, and why

You choose which accounts to connect; MailHandled can only reach what you connect, through each provider's official API:

  • Gmail / Outlook mail, to sort incoming mail, label it in your inbox, detect urgent messages, and prepare reply drafts that wait for your approval. Mail it screens out as noise is also marked as read, because leaving it bold would be the mailbox telling you two different things about it; everything else, including the automatic mail it gives one line, stays unread. When you connect Gmail it also reads the past year of message headers (who wrote, whether you replied and when, what you starred) to learn who you answer and what you never open. Short previews are read to spot a follow-up and are not kept; it keeps only those counts, and the subject line of anything that slipped. When someone follows up on mail it had screened, or you answer the daily quick check, it keeps that email's sender, subject line and what it had decided, to measure how often screening is wrong. A reply is sent only when you press Send on it yourself, and nothing is ever deleted or archived. We also read your signature settings so drafts carry your real signature, and your sent mail so drafts sound like you. If you opt in to subscription tracking, we additionally read receipt and renewal emails (only mail matching receipt patterns) to show your upcoming charges, you can turn this off and erase what was learned at any time.
  • Google Calendar, to show your agenda, detect conflicts across your calendars, and make the changes you press a button for: adding an event you approve from an email, answering an invitation when you press Accept or Decline (declining a meeting you organized removes it, and the other guests are told), and, if you press Combine calendars, sharing your other calendars view-only with your primary account.
  • Google Drive, to file email attachments, and the documents it prepares when someone asks you for one by email, into a folder MailHandled creates. A prepared document is a draft for you to read; it is sent to nobody unless you send it. We use the narrow drive.file permission: MailHandled can only see files it created itself, never the rest of your Drive.
  • Account basics, your name, email address, and profile photo, to create your account and show it's you.

What we never do

  • We never send a reply on our own initiative. Mail goes from your account to anyone else only when you press a button: sending a reply you have read, or asking a sender to unsubscribe you (which some senders accept only as an email from your address). Every reply is written as a draft first, and it sits in your Drafts folder until you send it, from MailHandled or from your own mail app, whichever you prefer.
  • The only mail MailHandled sends by itself goes to you and nobody else, at your own address: an alert when urgent mail arrives, a note if one of your mailboxes stops being readable, and, once a week if there is anything to report, a short summary of your week. It is sent from your main mailbox to itself. An alert about mail in one of your other mailboxes carries only the sender and the subject line, so the words of an email never leave the mailbox they arrived in, and no alert goes out through a mailbox that is not your main one. If your main mailbox is not connected, a mailbox alerts itself instead; when none of your mailboxes can carry it, it comes from ours (described below). You can stop the weekly summary from Settings.
  • We never delete or archive your mail.
  • We never use your data to train AI models, ours or anyone else's.
  • We never sell your data, share it with advertisers, or use it for advertising of any kind.
  • No human reads your mail. Processing is fully automated; our staff access your content only if you explicitly ask us to help debug a problem.

How your data is processed and stored

When MailHandled sorts your mail or writes a draft, the relevant message content is sent to Anthropic, our AI provider, for processing under an agreement that prohibits training on your data, and is not retained by them beyond short-term operational needs. A scanned document with no text in it is read by the same provider, by looking at the page.

So that you can find a filed document by what it says rather than only by its filename, the text of documents you have filed is also sent to DeepInfra, which converts short passages into the numerical form that search needs. Those two companies are the only outside services that read the body of your mail and documents. A third, named below, carries notices about your account and sees only the few fields those notices contain.

When MailHandled has to tell you about your account itself, a mailbox that has stopped being readable or an urgent alert whose usual route failed, and neither your phone nor one of your own mailboxes can carry the message, it sends a plain email through Resend from our own address to the address you sign in with. That email names the account and what went wrong; an urgent alert sent this way carries the sender and the subject line of the email that triggered it, the mailbox it arrived on, one line saying why it was judged urgent, and a link back into MailHandled. It never carries the body of your mail. Resend sees those fields and your sign-in address, and nothing else.

Our application runs on Vercel and our database on Neon. We store: your account details, the labels and decisions the assistant made (your audit trail), drafts awaiting your approval, the preferences it has learned from your feedback, and the text of documents you have filed, kept as short passages beside those numbers so that a search can show you which passage matched. The documents themselves stay in your own Google Drive. We keep a link, never a copy. We do not store copies of your mailbox, with one exception you should know about: so that drafts sound like you, we keep up to 40 short excerpts of mail you have sent from each connected mailbox (the first 700 characters of each, with its subject and recipient), and replace them as you send more. Deleting a document deletes every passage we hold from it, disconnecting a mailbox deletes its excerpts, and closing your account deletes all of it.

The keys that let MailHandled reach your accounts are encrypted with a key held separately from the database, so a copy of the database alone cannot open your mailbox. Everything else is encrypted in transit and at rest by our hosting provider.

Google user data: Limited Use

MailHandled's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: Google user data is used only to provide the features described above, never for ads, never sold, never used to train AI models, and never read by humans except with your explicit permission for support.

Your control: revoke and delete

Disconnect any account in one click from Settings, under Accounts. For every account, our copy of the key is deleted and that access ends at once. Google gives Gmail, Calendar and Drive on the same Google account one shared permission, so when the last of them on that account is disconnected MailHandled hands the permission back to Google, and it disappears from your Google account as well. You can also revoke MailHandled yourself from your Google Account permissions or Microsoft account at any time. To delete your MailHandled account and all stored data, email support@hoshmand.ai. Deletion completes within 30 days.

Changes and contact

If this policy changes materially, we'll email account holders before the change takes effect. Questions: support@hoshmand.ai. MailHandled is built by Hoshmand AI, McLean, Virginia, USA. See also our Trust & safety page and Terms of service.