Privacy Policy

Last updated: 2026-04-14

DRAFT — reviewed by AI, NOT yet reviewed by a lawyer. This document must be reviewed by qualified legal counsel before Truepost collects personal data from real users. It is published here as a working draft so that early testers and reviewers can comment on it. Do not rely on it as a finalized statement of Truepost's legal obligations.

1. Who we are

Truepost is an email client built around the idea that your inbox should feel like a conversation, not a filing cabinet. The Truepost app is operated by Truepost, LLC (a United States limited liability company, currently being formed). The marketing site lives at truepost.com and the app itself runs at truepost.net. In this policy, "Truepost," "we," "us," and "our" mean Truepost, LLC.

Truepost is privacy-first by design. We try to hold as little of your data as possible, for as short a time as possible, and only for purposes you would reasonably expect from an email client.

2. What we collect

Account and authentication data

To connect Truepost to your Gmail, Yahoo, or Outlook mailbox, you sign in through your provider's OAuth2 flow. Truepost receives an OAuth access token and refresh token from your provider. These tokens are stored on your own device (in files named token-{email}.json) and are used only to fetch your mail from your provider on your behalf. We do not upload, copy, or back up those tokens to any Truepost server.

Email content and metadata

Truepost fetches your email messages — headers, bodies, attachments, folders, and labels — directly from your provider via IMAP (or, where applicable, the Gmail API) so that the app can display them. By default, email content is processed on your device and is not transmitted to Truepost-operated servers. Some lightweight metadata (such as conversation grouping, signature detection, and quote stripping) is computed locally as well.

Device and diagnostic data

If you opt in to crash reports or diagnostics, we may collect technical information such as app version, operating system, error stack traces, and anonymized usage counters. We do not include the contents of your email in diagnostics.

Information you give us directly

If you contact us by email, fill out a form on truepost.com, or join the beta waitlist, we collect whatever you send (your name, email address, and the contents of your message).

3. How we use it

We use the data described above only to:

  • Authenticate you with your email provider and keep you signed in.
  • Fetch, display, organize, search, send, and reply to your mail.
  • Group messages into conversations and clean up redundant quoted text.
  • Diagnose crashes and improve reliability (when you opt in).
  • Respond to support requests you send us.
  • Comply with legal obligations.

We do not sell your personal information. We do not use your email content to build advertising profiles. We do not show ads in Truepost. We do not train generic, third-party AI models on your mail.

4. Who we share it with

Truepost shares your information only in these narrow cases:

  • Your email providers. When Truepost talks to Gmail, Yahoo, or Outlook on your behalf, your OAuth tokens and requests go to those providers under their own privacy terms.
  • Service providers we rely on. Hosting, error reporting, and similar infrastructure providers may process limited data strictly to operate Truepost. These vendors are bound by contract to use the data only for the services they provide to us.
  • Legal compliance. If we receive a valid legal order, we may disclose information to the extent legally required. We will push back on overbroad requests where we can.
  • Business transfers. If Truepost is acquired or merged, your information may transfer to the successor entity, which will remain bound by a privacy policy at least as protective as this one.

5. Google API Limited Use disclosure

Truepost uses Google APIs (including the Gmail API) to access your Google account when you choose to connect Gmail. Truepost's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Truepost commits that:
  • We use information obtained through Google APIs only to provide and improve user-facing features that are prominent in the Truepost user interface (i.e., reading, organizing, searching, sending, and replying to your mail).
  • We do not transfer this information to others except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not use this information to serve advertisements, including retargeted, personalized, or interest-based advertising.
  • We do not allow humans to read this information unless we have your affirmative consent for specific messages, doing so is necessary for security purposes (such as investigating abuse), to comply with applicable law, or for Truepost's internal operations — and even then only when the data has been aggregated and anonymized where feasible.
  • We do not use Gmail data to develop, improve, or train generalized or non-personalized AI and/or machine learning models. Any AI features Truepost offers operate on your messages only to deliver the requested feature to you (see section 13).

You can review and revoke Truepost's access to your Google account at any time at myaccount.google.com/permissions.

6. Retention and deletion

Because most Truepost data lives on your own device, deleting it is usually as simple as signing out of an account or uninstalling the app — this removes your local OAuth tokens and cached message data. For data we hold on our side (for example, support emails or diagnostics you opted in to), we retain it only as long as needed for the purpose it was collected, and then we delete or anonymize it. You can ask us to delete data we hold about you at any time using the contact information below.

7. Security

We use OAuth2 and TLS for all connections to email providers, store tokens on-device, and limit access to any server-side systems we operate. No system is perfectly secure, but we follow industry practices and are actively building toward optional client-side end-to-end encryption for users who want even stronger guarantees. If we ever experience a breach that affects your personal information, we will notify you and the relevant authorities as required by law.

8. Cookies and tracking

The marketing site at truepost.com uses only the cookies necessary for the site to function (for example, to remember that you dismissed a banner). We do not load third-party advertising trackers. The Truepost app itself uses session cookies to keep you signed in and does not run cross-site tracking pixels.

9. GDPR (European users)

If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent laws give you specific rights over your personal data. Truepost is the "controller" of the limited personal data we hold about you.

Lawful bases

We process your personal data on these lawful bases:

  • Contract. To provide Truepost to you when you sign up.
  • Legitimate interests. To keep the service secure, prevent abuse, and improve reliability — balanced against your privacy.
  • Consent. For optional features such as crash reporting or AI features, where we ask you to opt in.
  • Legal obligation. Where we must process data to comply with law.

Your rights

  • Access — ask what personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your data ("right to be forgotten").
  • Portability — receive your data in a portable format.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — at any time, where processing is based on consent.

To exercise any of these rights, email privacy@truepost.com. You also have the right to lodge a complaint with your local data protection supervisory authority (for example, the CNIL in France, the ICO in the United Kingdom, or your national equivalent).

International transfers

Truepost is based in the United States. Where personal data of European users is transferred to the US or other jurisdictions outside the EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) and apply additional safeguards as appropriate. You can request a copy of the relevant transfer mechanism by contacting us.

Data Protection Officer

Truepost has not formally appointed a Data Protection Officer because our processing does not currently meet the GDPR thresholds that require one. For all data protection questions, contact our privacy team at privacy@truepost.com.

10. CCPA / CPRA (California users)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your personal information.

Categories of personal information we collect

  • Identifiers — your email address, account ID at your provider.
  • Customer records — name, contact details if you give them to us.
  • Internet or other electronic activity — limited diagnostic and crash data, only if you opt in.
  • Geolocation — approximate location derived from your IP for security and abuse prevention only; no precise location.
  • Contents of your email — fetched from your provider and processed on your device. We treat the contents of your communications as sensitive personal information.

Your California rights

  • Right to know what personal information we collect, use, disclose, and retain.
  • Right to delete personal information we hold about you.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information.
  • Right to limit the use of sensitive personal information to what is necessary to provide the service.
  • Right to non-discrimination for exercising any of these rights.

Do Not Sell or Share My Personal Information

Truepost does not sell your personal information, and Truepost does not share your personal information for cross-context behavioral advertising. Because we do neither, there is no opt-out to exercise — but if you would still like written confirmation in your specific case, email privacy@truepost.com with the subject line "Do Not Sell or Share."

Sensitive personal information

We use your email contents (which we treat as sensitive personal information) only to provide you with the Truepost service that you requested. We do not use it to infer characteristics about you and we do not disclose it for any purpose that would require a CPRA opt-out.

To exercise any California right, contact privacy@truepost.com. We will verify your request using the email account associated with your Truepost session and respond within the timelines required by law. Authorized agents may submit requests on your behalf with proof of authorization.

11. HIPAA and healthcare use

The current consumer version of Truepost is not a HIPAA-compliant service. Truepost, LLC is not acting as a Business Associate to any covered entity through the standard consumer tier, and we have not signed a Business Associate Agreement (BAA) with consumer-tier users. Healthcare providers, health plans, healthcare clearinghouses, and their business associates must not use the consumer tier of Truepost to create, receive, maintain, or transmit Protected Health Information (PHI) as defined by HIPAA without first signing a BAA with us.

We are actively working on a HIPAA-covered Truepost tier for healthcare customers, which will be offered under a separate Business Associate Agreement, with administrative, physical, and technical safeguards appropriate for PHI. If you are a covered entity interested in this tier, contact us at privacy@truepost.com.

12. Children

Truepost is not directed to children under 13, and we do not knowingly collect personal information from children under 13, in line with the Children's Online Privacy Protection Act (COPPA). If you believe a child under 13 has provided personal information to Truepost, contact privacy@truepost.com and we will delete it. For users in the EEA and UK, we apply the equivalent local minimum age (typically 16, or as set by the user's member state).

13. AI features

Truepost is building optional AI-powered features such as spam detection, summarization, and suggested replies. These features are opt-in. When you enable them:

  • We process only the messages you choose, only for the feature you requested, and only for as long as needed to return the result.
  • We do not use your messages to train generalized AI models for ourselves or for any third party.
  • Where AI features are powered by a third-party model provider, we contractually require that provider to delete inputs after processing and to refrain from training on your data.
  • You can disable AI features at any time in Truepost's settings.

14. Changes to this policy

We will update this policy as Truepost evolves — for example, when we launch the HIPAA tier, add new features, or change vendors. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you in the app or by email before the changes take effect.

15. Contact us

Questions, requests, or complaints about privacy at Truepost? We want to hear from you.

Email: privacy@truepost.com
Mailing address: Truepost, LLC
[LLC mailing address — to be filled]