Skip to content
Sortmailsortmail
Legal

The boring pages, written plainly.

Short sections in ordinary English. The formal versions are linked at the bottom of each.

Last updated 1 October 2026

What we collect

Your account details, and for each message: the sender, a one-way hash of the subject, the category it was given and your corrections. Section 3 lists every item.

What we never store

Message bodies, attachments, contact lists. A body is held in memory only while it is sorted or shown to you, and is never written down.

Who else sees it

If you leave "Read message text" on (the default, shown to you before sorting starts), our model provider reads a short masked excerpt with the sender and subject, and keeps none of it. No one at Sortmail reads your mail.

How long we keep it

Your sorting history while your account is open; the activity log for 90 days. Delete your account and it is purged within 24 hours, apart from the billing records the law makes us keep.

This summary is not the contract. The full privacy document controls.
Formal text

Sortmail privacy policy

This is the operative text. Where it differs from the summary above, this controls.

This policy explains how Gal Etrog, the founder who runs Sortmail ("Sortmail", "we", "us"), handles personal data when you visit getsortmail.com or use the Sortmail service.

Before the service opens to customers, Sortmail will be operated by a Wyoming limited liability company. From that day this policy names the company and its registered address; nothing about how your data is handled changes.

It is written to be read. Where a section carries a legal obligation we have said so plainly rather than hiding it in defined terms.

1. Who is responsible for your data

For your Sortmail account — your email address, your settings, your categories, your corrections and your billing record — Sortmail, that is Gal Etrog, is the controller. We decide why and how that data is processed, and this policy governs it.

Where you connect a mailbox that belongs to an organisation rather than to you personally, that organisation is generally the controller of the correspondence in it, and Sortmail acts as a processor on its behalf. Our Data Processing Agreement governs that relationship and is available at /legal/dpa.

You can contact us about anything in this policy at [email protected].

2. Where Sortmail operates, and which rules we follow

Sortmail is sold to customers in the United States. It is run by Gal Etrog from Israel, and the service and its data are hosted in Germany, in the European Union.

Because the data is hosted in the EU and anyone can reach the site, we hold ourselves to the EU General Data Protection Regulation (GDPR) and the UK GDPR for everyone: the lawful bases, the rights and the safeguards in this policy are the ones those laws require, whether or not they apply to you by law.

We have not appointed a data protection officer: at Sortmail's size its processing is not on the scale that makes one mandatory under Article 37, and we will appoint one if that changes. Gal Etrog is responsible for data protection and answers at [email protected].

3. What we collect, why, and on what legal basis

Every category below is listed with the purpose it serves and the lawful basis we rely on under Article 6 of the GDPR. If a purpose is not listed here, we are not pursuing it.

Account identity — email address, display name, timezone, digest settings, the version of the terms you accepted, and whether you allow marketing email
To create and operate your account and to contact you about the service. Lawful basis: performance of a contract (Art 6(1)(b)). Marketing email is off unless you turn it on, and then rests on your consent (Art 6(1)(a)).
Sign-in data — session records, hashed session tokens, hashed sign-in link tokens, a keyed hash of the network you connected from (never your IP address itself), a coarse browser class, and, if you sign in with Microsoft, your account's permanent id and tenant
To sign you in, to keep the session safe, to show you where you are signed in, and to detect credential abuse. Lawful basis: performance of a contract, and our legitimate interest in securing accounts (Art 6(1)(b) and 6(1)(f)).
Mailbox connection — the provider, your mailbox address, the provider account id, the permissions you granted, sync status, your "Read message text" choice, and the permission itself, encrypted
To connect to your mailbox and apply labels. Lawful basis: performance of a contract (Art 6(1)(b)).
Message fingerprints — the sender's address and domain, the List-Id, a keyed one-way hash of the normalised subject, the provider's message and thread ids, true/false characteristics (has an attachment, is bulk, is automated and similar), when it arrived and was sorted, the category, the confidence, and which rule, signal or model decided it
To sort your mail, to explain each decision to you, and to re-sort without re-reading your mailbox. Lawful basis: performance of a contract (Art 6(1)(b)).
People who email you — the sender address and domain and the List-Id in the fingerprint above
The people who write to you are data subjects too. We hold their address only to sort your mail into your categories, never to contact them or to build anything about them. Lawful basis: your legitimate interest, and ours, in sorting the mail you receive (Art 6(1)(f)).
Your categories, rules and corrections
To make sorting obey you rather than the model. The names and descriptions of your categories are sent to the model with each request, so it can choose among them. Lawful basis: performance of a contract (Art 6(1)(b)).
Optional message embeddings
A numeric vector derived from a message, used to re-sort into new categories without re-reading your mailbox. Off by default, per-user opt-in, deleted after 12 months. Lawful basis: your consent (Art 6(1)(a)), withdrawable at any time in Settings.
Billing record — subscription status, plan, period, renewal date, invoice metadata, your Stripe customer and subscription ids, and your records of consent to automatic renewal and to any added mailbox
To take payment and to meet tax and consumer-law record-keeping duties. Lawful basis: performance of a contract and legal obligation (Art 6(1)(b) and 6(1)(c)). Card details are handled by Stripe, our payment processor, on payment pages hosted by them, and never reach us.
Product milestones — the first time your free preview finished, the first time you viewed it, and the first time you viewed the pricing page, as an account id, a step name and a time
To measure, in aggregate, how many previews become subscriptions. Recorded on our own servers only — no cookies, no client-side tracking, no third-party analytics — and never containing message content. Checkout and payment times are read from the billing record rather than recorded again. Lawful basis: legitimate interest in understanding whether the product works for the people who try it (Art 6(1)(f)).
Why you left — if you choose to tell us after closing checkout or cancelling, one reason from a fixed list (such as "too expensive"), as an account id, the reason and a time
To learn, in aggregate, whether price or something else stops people subscribing or staying. Always optional and only asked after you have already left, so it never stands between you and cancelling. No free text is collected. Lawful basis: legitimate interest in pricing the product fairly (Art 6(1)(f)).
Where you first found us — the campaign tags in the link you first arrived on (utm_source, utm_medium, utm_campaign), the name of the referring website (never the full web address), and when, copied onto your account when you sign up
To work out, in aggregate, which channels bring paying customers and what each costs. Held in one first-party cookie for up to 30 days before you sign up, then on your account; never shared, never sent to an advertising or analytics company. The cookie is not set when your browser sends a Global Privacy Control signal, nor for visitors from the European Economic Area or the United Kingdom, or from anywhere we cannot tell (section 14). Lawful basis: legitimate interest in knowing whether our marketing spend works (Art 6(1)(f)).
Waitlist — your email address, the date you joined, short labels naming the page you joined from and the link that brought you there (never a web address), and the date we sent your invitation
To send you one invitation when a place is available; nothing else is sent unless you opt in. The form is rate-limited using a one-way hash of your address and of your network, held for one hour and never stored with your address. Lawful basis: steps taken at your request before entering a contract (Art 6(1)(b)).
Audit log — which account did what, when, from a hashed network, including your data exports and deletion request
To show you your own history and to investigate security incidents. Lawful basis: legitimate interest in the security and integrity of the service (Art 6(1)(f)). Kept 90 days.
Operational logs and error reports
To keep the service running. Written through an allowlist so that mail content, subjects, addresses and tokens cannot enter them. Lawful basis: legitimate interest (Art 6(1)(f)).
Emails you send us — to support, privacy or security
To answer you. Lawful basis: performance of a contract where it concerns your account, and otherwise our legitimate interest in answering the people who write to us (Art 6(1)(b) and 6(1)(f)).
Visiting the website — your IP address and the request your browser makes
Cloudflare, which carries all traffic to the site, processes your IP address to deliver pages and to protect the site from attack. Our own systems store no IP address: rate limits and security records hold only a keyed hash of the network it belongs to. Lawful basis: legitimate interest in running a secure website (Art 6(1)(f)).

4. Sensitive data

We do not ask for special category data under Article 9. We cannot control what arrives in your mailbox, and a message may reveal health, beliefs, trade union membership or similar. That is exactly why the architecture keeps no bodies: a message that mentions a diagnosis produces the same stored record as any other message — a sender, a domain, a hashed subject, a category.

We do not infer sensitive characteristics about you, and we do not build a profile of you for any purpose other than sorting your own mail into your own categories.

5. What we never store

This is the central design commitment of the product, and it is enforced by the schema, not by policy alone.

  • Message bodies. A body exists only in memory: in our worker for as long as sorting takes, and, when you open a message in Sortmail, for as long as it takes to pass it to your browser. It is then discarded.
  • Attachments. We record whether an attachment exists. We never read, store or transmit its contents.
  • Raw subject lines. We store only a keyed hash of the normalised subject. The key is one secret, held by Sortmail outside the database and the same for every account, and the hash is one-way: it cannot be turned back into the subject. Someone who held both our database and that key could test whether a guessed subject matches, which is why the key is kept apart.
  • Contact lists, address books or calendars. We never request those scopes.
  • Anything at all in an advertising profile. We do not run ads, do not sell data, and do not share data with brokers.

5.1 How this is enforced

The database has no column for a body, snippet, attachment or raw subject, and an automated test fails our build if one is ever added. Queue payloads are schema-checked and reject unknown fields. Our logger writes only an allowlist of known-safe keys. These tests are part of the evidence we supply to our independent security assessor.

5.2 Reading a message in Sortmail

When you open a message in Sortmail, our worker fetches it from your mailbox at that moment and passes it, through our web server, to your browser, where it is shown in a sandboxed frame with remote images blocked. The subject lines in the app's lists are fetched the same way. None of it is written to our database, our queue or our logs, and it is fetched again the next time you look.

6. Google user data and Limited Use

Sortmail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, that means all of the following.

  • We request one Gmail scope, gmail.modify, because applying and removing labels and archiving mail is the product. Sortmail never sends, drafts, trashes or deletes mail. Be aware that gmail.modify is broad: Google offers no narrower permission that can label and archive, and gmail.modify would also technically allow sending and moving mail to the trash. That our code does neither is a commitment, checked in the annual independent security assessment Google requires for this permission, not a technical impossibility. We do not request mail.google.com, so nothing can be deleted permanently. We do not request contacts, Drive or calendar.
  • We use Gmail data only to provide the features you can see in the product — sorting and labelling your mail, explaining each decision, showing you a message or its subject line when you open Sortmail, and the digest — and to improve those features. We use it for nothing else.
  • We transfer Gmail data only to the sub-processors in section 8 that deliver those features — the model providers, which receive a masked excerpt to choose a category, and the hosting and network providers it passes through on its way to you — and otherwise only where required for security, to comply with law, or as part of a merger where we have given you prior notice and obtained consent where required.
  • We never use Gmail data for advertising of any kind, including retargeting and personalised or interest-based advertising, and we never sell it.
  • No human at Sortmail reads your messages, and there is no tool that would let one. The support and admin tools show an account's address, plan, status and counts of what was sorted — never a message, a subject line or a sender. If you want help with a particular message, describe it or forward it to us yourself; we will not open it on your behalf. Access to the production database is limited to the founder, who runs the service, and is used to operate it and to investigate security incidents, never to read an account's data.
  • We do not use your mail, or anything derived from it, to develop, train, improve or fine-tune any generalised artificial intelligence or machine learning model. Our model providers are contractually barred from retaining your data or training on it.

7. How the automated sorting works

Sorting by model is ON by default. Straight after you grant access, and before anything is sorted, the categories step of the connect flow shows this as a ticked box labelled "Read message text to sort accurately". You can untick it there, and change it per mailbox at any time in Settings. Nothing is sent to the model before you have seen that box. With it off, only the headers of your mail ever leave your mailbox — and only Newsletters and System can be filled, because Receipts, Personal and Actionable need the words to tell them apart. We state the default plainly because a default that sends part of a message to a third party should never be discovered after the fact.

Every message is first matched against deterministic rules — yours and the ones created from your corrections. If a rule matches, that decides the category and no model is involved.

If no rule matches, we try the signals in the message's own headers, such as a mailing-list header, and the decisions already made for mail from the same sender. Only if those are inconclusive do we call a language model, and then we send the minimum that works: the sender's full email address, the subject, and at most the first 400 characters of the body, with obvious card numbers, national identifiers and one-time codes masked before the call, together with the names and descriptions of your categories to choose from. We send no message id, no recipient address and no account identifier. The model returns a category and a confidence, and nothing else. Nothing about the text is logged; we log only the decision and the token count.

If our primary model provider is unavailable, the same request goes to our backup, Google's Vertex AI, under the same zero-retention and no-training terms, for a capped share of requests. It is never used because an answer was uncertain, only because the primary could not answer.

Where confidence is below our threshold, the message goes to your fallback category and the interface says so.

The "why this is here" panel shows what decided any message — your rule, a header signal, or the model and how sure it was — and you can override it. An override becomes a rule that beats the model permanently.

This is automated processing, but it does not produce legal or similarly significant effects: it decides which folder a message appears in, and you can change that decision at any time. We do not consider it to be automated decision-making within the meaning of Article 22, and we do not use it to make decisions about you.

8. Who else processes your data

We keep this list short on purpose, and we publish it. Our current sub-processors are listed at getsortmail.com/legal/subprocessors, with the purpose, the data each receives, its region and the transfer mechanism. We give at least 30 days’ notice before adding one.

Message text reaches our model providers only — the primary, and the backup while the primary is down — as the masked excerpt in section 7, which neither keeps. When you open a message in Sortmail, the whole message passes through the servers we rent from Hetzner in Germany and through Cloudflare's network on its way to your browser, in transit only; neither stores it. Our database, payment, email and error-tracking providers never receive message content.

We also disclose data where we are legally compelled to. If we receive a demand for your data we will tell you unless we are legally prohibited from doing so.

9. International transfers

Sortmail's servers, its database and its encryption keys are in Germany: servers rented from Hetzner, and the database and key service on Amazon Web Services in Frankfurt. Personal data leaves the European Economic Area when a provider outside it processes it — the sub-processor list names each one and where it processes — and when Sortmail's founder works on the service from Israel.

Israel and the United Kingdom are recognised by the European Commission as giving adequate protection, and the UK recognises Israel in the same way. For recipients in the United States we rely on the EU-US Data Privacy Framework, and its UK extension, where the recipient is certified under it, and otherwise on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 — Module Two, controller to processor — with the UK International Data Transfer Addendum for UK data. We assess each transfer before it starts and keep the assessment on file.

The region and the mechanism for each sub-processor are on the sub-processor list, and the DPA sets out the terms that apply to them.

10. How long we keep things

Message bodies and attachments
Never written to storage. Held in memory only while a message is sorted or shown to you.
Message fingerprints, categories, rules, corrections
For as long as your account is open. Deleted within 24 hours of an account deletion request.
Optional embeddings
12 months, or until you turn the option off, whichever is sooner.
Product milestones
For as long as your account is open. Deleted within 24 hours of an account deletion request.
Why you left
For as long as your account is open. Deleted within 24 hours of an account deletion request.
Where you first found us
The cookie expires after 30 days. On your account, for as long as it is open; deleted within 24 hours of an account deletion request.
Waitlist entry
Until you sign in to an account with that address, delete your account, or ask us to remove it — and in any case no more than 12 months after you joined, or 90 days after we send your invitation, whichever comes first.
Audit log
90 days.
Data export requests
One hour: the time a download stays available after you ask for it. That you asked, and when, stays in the audit log for its 90 days.
Operational logs
30 days.
Error reports
At most 90 days, the retention of our error-tracking provider.
Sessions
30 days maximum, or 14 days idle, or until you sign out.
Magic-link tokens
15 minutes, and destroyed on first use.
Subscription and invoices
For as long as your account is open, then 7 years after it is deleted, because tax law requires financial records to be kept. Your record of consent to automatic renewal is part of the subscription record and is kept with it, which is longer than California law's minimum of 3 years, or 1 year after the subscription ends.
Consent to an additional mailbox
For as long as your account is open, then until 3 years after you agreed or 1 year after your account was deleted, whichever is later, as California law requires.
Your Stripe customer record
Stripe holds your name, email address, billing address and payment history for us, and keeps them after you delete your Sortmail account, because the same tax rules apply to it. We delete the customer in Stripe 7 years after your account is deleted. Stripe also keeps its own records of payments under the financial regulations it is subject to, as its own privacy policy describes.
Emails we sent you
Our email provider keeps a delivery log of each email we sent you — your address, our subject line, the email itself and whether it was delivered — for up to 30 days, to diagnose delivery problems. For a digest, the email holds your category names, counts and top sender domains, never a subject line or message text.
Deletion requests
A record that you asked for deletion and when it was carried out, holding only the anonymised account id. Kept as long as the anonymised billing records above, as evidence that we honoured the request.
Emails you send us
2 years after the conversation ends.
Backups
Point-in-time history for at most 7 days, and snapshots taken before a change for at most 30 days. A deletion request purges live systems within 24 hours; backup copies expire on this schedule and are never restored to bring deleted data back.

11. Your rights

If the GDPR or UK GDPR applies to you, you have the rights below. We honour them for everyone, regardless of where you live, because the machinery is the same.

  • Access — get a copy of what we hold. Account → Security → Download my data gives you one JSON file with everything we hold about your account, including every message fingerprint. It is built when you ask, inside your signed-in session (we may ask you to sign in again first), stays available for one hour, and is never stored, emailed or sent as a link. It leaves out only credentials — the hashes that look up your sessions and sign-in links, and your encrypted mailbox permission — and says so inside the file.
  • Rectification — correct anything inaccurate. Most of it you can edit directly.
  • Erasure — delete your account and everything attached to it. Account → Delete stops your subscription's renewal, signs you out everywhere and queues the purge at once. The purge first revokes Sortmail's permission at Google, then deletes your mailbox tokens and everything in section 10 that is not a billing record, within 24 hours. Microsoft works differently; see 11.2.
  • Restriction and objection — ask us to stop a particular processing activity, including any processing based on legitimate interests.
  • Portability — the export is machine-readable JSON, yours to take elsewhere.
  • Withdraw consent — where we rely on consent, such as optional embeddings or marketing email, you can withdraw it at any time without affecting what was lawful before.
  • Not to be subject to decisions made solely by automated means that affect you significantly — sorting makes no such decision (section 7).
  • Complain — to a data protection authority: in the EU, the one where you live or work; in the UK, the ICO (ico.org.uk). We would rather you told us first, at [email protected].

11.1 How quickly we respond

We respond to rights requests within one month, and we will tell you if we need the extension the law allows for a complex request. Exports and deletions are automated and usually complete within minutes rather than days.

We do not charge for these, and we do not require a reason.

11.2 Removing Sortmail's access to your mailbox

On Gmail, deleting your account or disconnecting the mailbox revokes Sortmail's permission at Google itself.

Microsoft offers apps no way to revoke a permission they have been given. For an Outlook or Microsoft 365 mailbox we delete our copy of its tokens, so Sortmail can never use the permission again, and we stop renewing the subscription through which Microsoft tells us about new mail; Microsoft ends it within seven days at most, and nothing it sends in the meantime is acted on. The permission itself stays listed in your Microsoft account until you remove it: for a personal account at account.live.com/consent/Manage, and for a work or school account at myapps.microsoft.com or through your administrator.

You can remove Sortmail at your provider at any time, whatever you do here: for Google at myaccount.google.com/connections.

12. California residents

Sortmail is a small business and does not currently meet the thresholds that make a business subject to the California Consumer Privacy Act. We grant the rights below anyway, because we have built the machinery to honour them and see no reason to withhold them.

The categories of personal information we collect, the purpose for each and the retention period are set out in sections 3 and 10 above. Those sections are the notice at collection.

We have not sold or shared personal information as those terms are defined by the CCPA, and we have no plans to. There is therefore no "Do Not Sell or Share My Personal Information" mechanism to offer — because there is nothing to opt out of. If that ever changes, we will say so here before it does, not after.

We do not use personal information for cross-context behavioural advertising, and we do not use sensitive personal information for any purpose beyond providing the service you asked for.

You may exercise the rights to know, delete, correct and limit through Account → Security, or by writing to [email protected]. We will not discriminate against you for exercising any of them. Residents of other US states with a consumer privacy law have the same rights, through the same routes.

13. Children

Sortmail is not intended for anyone under 16, and we do not knowingly create accounts for them. If you believe a child has an account, tell us at [email protected] and we will delete it.

14. Cookies and similar technologies

We set strictly necessary cookies, all first-party and Secure: your session cookie, which keeps you signed in and carries an opaque token that means nothing outside our systems; an anti-forgery token that stops other sites submitting forms as you; and short-lived cookies that protect a sign-in or a mailbox connection while it is in progress, which expire within fifteen minutes and are deleted as soon as it completes.

One more first-party cookie is not strictly necessary: when you arrive from a tagged link or another website, we note the campaign tags and the referring site name (section 3) so we can tell which channels work. It expires after 30 days and is never read by anyone but us. It is not set at all when your browser sends a Global Privacy Control signal, nor when you visit from the European Economic Area or the United Kingdom — or from anywhere we cannot tell — because the law there asks for consent before a cookie like it, and we would rather not set it than ask.

We do not run third-party analytics, advertising pixels or trackers on any page, and we load no third-party scripts on signed-in pages. Our fonts are served from our own domain, so visiting Sortmail does not tell anyone else that you did.

Every cookie we set where consent would be needed is strictly necessary, and none is used for advertising or shared, so there is no consent banner to click through.

15. Security

A summary is at /legal/security. In short: TLS 1.2 or better everywhere, AES-256-GCM envelope encryption for OAuth tokens under a key that is separate from the database key, a web tier that has no permission to decrypt those tokens at all, least-privilege access, logged administrative actions, and an annual independent security assessment required by Google for applications using restricted Gmail scopes.

If you find a vulnerability, write to [email protected]. We will acknowledge within one business day and we will not pursue researchers acting in good faith.

16. If something goes wrong

If a breach is likely to result in a risk to your rights and freedoms, we notify the relevant supervisory authority within 72 hours of becoming aware of it, and we tell affected users without undue delay where the risk is high.

We will tell you what happened, what data was involved, what we have done, and what you should do — in that order, and without euphemism.

17. People who are not Sortmail customers: public posts

Sortmail's founder answers public posts in which people ask for help with their email, on sites such as Reddit, Hacker News, Stack Exchange, Bluesky and Mastodon. To find them we collect public posts about email trouble and store, for each one: its link, its title, up to the first 1,500 characters, the community it was posted in, the author's public handle, when it was posted, and its score and comment count. We keep nothing about a person across posts and build no profile of anyone.

Each post we collect is sent to Google's Gemini model, on Google Cloud's Vertex AI under the same zero-retention terms as our backup classifier, which judges whether it is the kind of problem Sortmail solves and drafts a reply for the founder to edit. Nothing is posted without the founder approving that one reply, and every reply says that its author built Sortmail.

Lawful basis: our legitimate interest in answering public requests for help that our product addresses (Art 6(1)(f)). You may object at any time.

A post we do not answer is deleted 30 days after we found it, and one we set aside 30 days after that. One we answered is kept for a year after the answer, so we can see what came of it. A Bluesky post its author deletes is dropped the next time we look.

To have your post removed from our records, write to [email protected] with its link. We delete it within 30 days, usually much sooner. That removes our copy; a reply already posted in public stays where it was posted unless you ask us to delete that too.

18. Changes to this policy

If we change this policy materially we will email you before the change takes effect, and where the change introduces a new use of your data we will ask you to consent to it rather than assume your silence is agreement.

Every version is dated, and previous versions remain available on request.