The boring pages, written plainly.
Short sections in ordinary English. The formal versions are linked at the bottom of each.
What we collect
Your account details, and for each message: the sender, a one-way hash of the subject, the category it was given and your corrections. Section 3 lists every item.
What we never store
Message bodies, attachments, contact lists. A body is held in memory only while it is sorted or shown to you, and is never written down.
Who else sees it
If you leave "Read message text" on (the default, shown to you before sorting starts), our model provider reads a short masked excerpt with the sender and subject, and keeps none of it. No one at Sortmail reads your mail.
How long we keep it
Your sorting history while your account is open; the activity log for 90 days. Delete your account and it is purged within 24 hours, apart from the billing records the law makes us keep.
Sortmail privacy policy
This is the operative text. Where it differs from the summary above, this controls.
This policy explains how Gal Etrog, the founder who runs Sortmail ("Sortmail", "we", "us"), handles personal data when you visit getsortmail.com or use the Sortmail service.
Before the service opens to customers, Sortmail will be operated by a Wyoming limited liability company. From that day this policy names the company and its registered address; nothing about how your data is handled changes.
It is written to be read. Where a section carries a legal obligation we have said so plainly rather than hiding it in defined terms.
1. Who is responsible for your data
For your Sortmail account — your email address, your settings, your categories, your corrections and your billing record — Sortmail, that is Gal Etrog, is the controller. We decide why and how that data is processed, and this policy governs it.
Where you connect a mailbox that belongs to an organisation rather than to you personally, that organisation is generally the controller of the correspondence in it, and Sortmail acts as a processor on its behalf. Our Data Processing Agreement governs that relationship and is available at /legal/dpa.
You can contact us about anything in this policy at [email protected].
2. Where Sortmail operates, and which rules we follow
Sortmail is sold to customers in the United States. It is run by Gal Etrog from Israel, and the service and its data are hosted in Germany, in the European Union.
Because the data is hosted in the EU and anyone can reach the site, we hold ourselves to the EU General Data Protection Regulation (GDPR) and the UK GDPR for everyone: the lawful bases, the rights and the safeguards in this policy are the ones those laws require, whether or not they apply to you by law.
We have not appointed a data protection officer: at Sortmail's size its processing is not on the scale that makes one mandatory under Article 37, and we will appoint one if that changes. Gal Etrog is responsible for data protection and answers at [email protected].
3. What we collect, why, and on what legal basis
Every category below is listed with the purpose it serves and the lawful basis we rely on under Article 6 of the GDPR. If a purpose is not listed here, we are not pursuing it.
4. Sensitive data
We do not ask for special category data under Article 9. We cannot control what arrives in your mailbox, and a message may reveal health, beliefs, trade union membership or similar. That is exactly why the architecture keeps no bodies: a message that mentions a diagnosis produces the same stored record as any other message — a sender, a domain, a hashed subject, a category.
We do not infer sensitive characteristics about you, and we do not build a profile of you for any purpose other than sorting your own mail into your own categories.
5. What we never store
This is the central design commitment of the product, and it is enforced by the schema, not by policy alone.
- Message bodies. A body exists only in memory: in our worker for as long as sorting takes, and, when you open a message in Sortmail, for as long as it takes to pass it to your browser. It is then discarded.
- Attachments. We record whether an attachment exists. We never read, store or transmit its contents.
- Raw subject lines. We store only a keyed hash of the normalised subject. The key is one secret, held by Sortmail outside the database and the same for every account, and the hash is one-way: it cannot be turned back into the subject. Someone who held both our database and that key could test whether a guessed subject matches, which is why the key is kept apart.
- Contact lists, address books or calendars. We never request those scopes.
- Anything at all in an advertising profile. We do not run ads, do not sell data, and do not share data with brokers.
5.1 How this is enforced
The database has no column for a body, snippet, attachment or raw subject, and an automated test fails our build if one is ever added. Queue payloads are schema-checked and reject unknown fields. Our logger writes only an allowlist of known-safe keys. These tests are part of the evidence we supply to our independent security assessor.
5.2 Reading a message in Sortmail
When you open a message in Sortmail, our worker fetches it from your mailbox at that moment and passes it, through our web server, to your browser, where it is shown in a sandboxed frame with remote images blocked. The subject lines in the app's lists are fetched the same way. None of it is written to our database, our queue or our logs, and it is fetched again the next time you look.
6. Google user data and Limited Use
Sortmail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means all of the following.
- We request one Gmail scope, gmail.modify, because applying and removing labels and archiving mail is the product. Sortmail never sends, drafts, trashes or deletes mail. Be aware that gmail.modify is broad: Google offers no narrower permission that can label and archive, and gmail.modify would also technically allow sending and moving mail to the trash. That our code does neither is a commitment, checked in the annual independent security assessment Google requires for this permission, not a technical impossibility. We do not request mail.google.com, so nothing can be deleted permanently. We do not request contacts, Drive or calendar.
- We use Gmail data only to provide the features you can see in the product — sorting and labelling your mail, explaining each decision, showing you a message or its subject line when you open Sortmail, and the digest — and to improve those features. We use it for nothing else.
- We transfer Gmail data only to the sub-processors in section 8 that deliver those features — the model providers, which receive a masked excerpt to choose a category, and the hosting and network providers it passes through on its way to you — and otherwise only where required for security, to comply with law, or as part of a merger where we have given you prior notice and obtained consent where required.
- We never use Gmail data for advertising of any kind, including retargeting and personalised or interest-based advertising, and we never sell it.
- No human at Sortmail reads your messages, and there is no tool that would let one. The support and admin tools show an account's address, plan, status and counts of what was sorted — never a message, a subject line or a sender. If you want help with a particular message, describe it or forward it to us yourself; we will not open it on your behalf. Access to the production database is limited to the founder, who runs the service, and is used to operate it and to investigate security incidents, never to read an account's data.
- We do not use your mail, or anything derived from it, to develop, train, improve or fine-tune any generalised artificial intelligence or machine learning model. Our model providers are contractually barred from retaining your data or training on it.
7. How the automated sorting works
Sorting by model is ON by default. Straight after you grant access, and before anything is sorted, the categories step of the connect flow shows this as a ticked box labelled "Read message text to sort accurately". You can untick it there, and change it per mailbox at any time in Settings. Nothing is sent to the model before you have seen that box. With it off, only the headers of your mail ever leave your mailbox — and only Newsletters and System can be filled, because Receipts, Personal and Actionable need the words to tell them apart. We state the default plainly because a default that sends part of a message to a third party should never be discovered after the fact.
Every message is first matched against deterministic rules — yours and the ones created from your corrections. If a rule matches, that decides the category and no model is involved.
If no rule matches, we try the signals in the message's own headers, such as a mailing-list header, and the decisions already made for mail from the same sender. Only if those are inconclusive do we call a language model, and then we send the minimum that works: the sender's full email address, the subject, and at most the first 400 characters of the body, with obvious card numbers, national identifiers and one-time codes masked before the call, together with the names and descriptions of your categories to choose from. We send no message id, no recipient address and no account identifier. The model returns a category and a confidence, and nothing else. Nothing about the text is logged; we log only the decision and the token count.
If our primary model provider is unavailable, the same request goes to our backup, Google's Vertex AI, under the same zero-retention and no-training terms, for a capped share of requests. It is never used because an answer was uncertain, only because the primary could not answer.
Where confidence is below our threshold, the message goes to your fallback category and the interface says so.
The "why this is here" panel shows what decided any message — your rule, a header signal, or the model and how sure it was — and you can override it. An override becomes a rule that beats the model permanently.
This is automated processing, but it does not produce legal or similarly significant effects: it decides which folder a message appears in, and you can change that decision at any time. We do not consider it to be automated decision-making within the meaning of Article 22, and we do not use it to make decisions about you.
9. International transfers
Sortmail's servers, its database and its encryption keys are in Germany: servers rented from Hetzner, and the database and key service on Amazon Web Services in Frankfurt. Personal data leaves the European Economic Area when a provider outside it processes it — the sub-processor list names each one and where it processes — and when Sortmail's founder works on the service from Israel.
Israel and the United Kingdom are recognised by the European Commission as giving adequate protection, and the UK recognises Israel in the same way. For recipients in the United States we rely on the EU-US Data Privacy Framework, and its UK extension, where the recipient is certified under it, and otherwise on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 — Module Two, controller to processor — with the UK International Data Transfer Addendum for UK data. We assess each transfer before it starts and keep the assessment on file.
The region and the mechanism for each sub-processor are on the sub-processor list, and the DPA sets out the terms that apply to them.
10. How long we keep things
11. Your rights
If the GDPR or UK GDPR applies to you, you have the rights below. We honour them for everyone, regardless of where you live, because the machinery is the same.
- Access — get a copy of what we hold. Account → Security → Download my data gives you one JSON file with everything we hold about your account, including every message fingerprint. It is built when you ask, inside your signed-in session (we may ask you to sign in again first), stays available for one hour, and is never stored, emailed or sent as a link. It leaves out only credentials — the hashes that look up your sessions and sign-in links, and your encrypted mailbox permission — and says so inside the file.
- Rectification — correct anything inaccurate. Most of it you can edit directly.
- Erasure — delete your account and everything attached to it. Account → Delete stops your subscription's renewal, signs you out everywhere and queues the purge at once. The purge first revokes Sortmail's permission at Google, then deletes your mailbox tokens and everything in section 10 that is not a billing record, within 24 hours. Microsoft works differently; see 11.2.
- Restriction and objection — ask us to stop a particular processing activity, including any processing based on legitimate interests.
- Portability — the export is machine-readable JSON, yours to take elsewhere.
- Withdraw consent — where we rely on consent, such as optional embeddings or marketing email, you can withdraw it at any time without affecting what was lawful before.
- Not to be subject to decisions made solely by automated means that affect you significantly — sorting makes no such decision (section 7).
- Complain — to a data protection authority: in the EU, the one where you live or work; in the UK, the ICO (ico.org.uk). We would rather you told us first, at [email protected].
11.1 How quickly we respond
We respond to rights requests within one month, and we will tell you if we need the extension the law allows for a complex request. Exports and deletions are automated and usually complete within minutes rather than days.
We do not charge for these, and we do not require a reason.
11.2 Removing Sortmail's access to your mailbox
On Gmail, deleting your account or disconnecting the mailbox revokes Sortmail's permission at Google itself.
Microsoft offers apps no way to revoke a permission they have been given. For an Outlook or Microsoft 365 mailbox we delete our copy of its tokens, so Sortmail can never use the permission again, and we stop renewing the subscription through which Microsoft tells us about new mail; Microsoft ends it within seven days at most, and nothing it sends in the meantime is acted on. The permission itself stays listed in your Microsoft account until you remove it: for a personal account at account.live.com/consent/Manage, and for a work or school account at myapps.microsoft.com or through your administrator.
You can remove Sortmail at your provider at any time, whatever you do here: for Google at myaccount.google.com/connections.
12. California residents
Sortmail is a small business and does not currently meet the thresholds that make a business subject to the California Consumer Privacy Act. We grant the rights below anyway, because we have built the machinery to honour them and see no reason to withhold them.
The categories of personal information we collect, the purpose for each and the retention period are set out in sections 3 and 10 above. Those sections are the notice at collection.
We have not sold or shared personal information as those terms are defined by the CCPA, and we have no plans to. There is therefore no "Do Not Sell or Share My Personal Information" mechanism to offer — because there is nothing to opt out of. If that ever changes, we will say so here before it does, not after.
We do not use personal information for cross-context behavioural advertising, and we do not use sensitive personal information for any purpose beyond providing the service you asked for.
You may exercise the rights to know, delete, correct and limit through Account → Security, or by writing to [email protected]. We will not discriminate against you for exercising any of them. Residents of other US states with a consumer privacy law have the same rights, through the same routes.
13. Children
Sortmail is not intended for anyone under 16, and we do not knowingly create accounts for them. If you believe a child has an account, tell us at [email protected] and we will delete it.
15. Security
A summary is at /legal/security. In short: TLS 1.2 or better everywhere, AES-256-GCM envelope encryption for OAuth tokens under a key that is separate from the database key, a web tier that has no permission to decrypt those tokens at all, least-privilege access, logged administrative actions, and an annual independent security assessment required by Google for applications using restricted Gmail scopes.
If you find a vulnerability, write to [email protected]. We will acknowledge within one business day and we will not pursue researchers acting in good faith.
16. If something goes wrong
If a breach is likely to result in a risk to your rights and freedoms, we notify the relevant supervisory authority within 72 hours of becoming aware of it, and we tell affected users without undue delay where the risk is high.
We will tell you what happened, what data was involved, what we have done, and what you should do — in that order, and without euphemism.
18. Changes to this policy
If we change this policy materially we will email you before the change takes effect, and where the change introduces a new use of your data we will ask you to consent to it rather than assume your silence is agreement.
Every version is dated, and previous versions remain available on request.