Transparency
Data Use & AI Safety
What Gmail lets Mudroom access is broader than what the product does. This page separates the permission from the behavior and documents both the classifier and mailbox-action safety boundaries.
Effective and last updated August 26, 2026 at 10:15 PM CT
One Google permission
Mudroom requests only gmail.modify. Google describes that permission with broad language that includes reading, composing, sending, and changing mail. Mudroom uses it to read metadata, read a body only for an ambiguous model decision, inspect Sent-mail relationships, obtain synchronization history, and—only after explicit per-account activation—apply the Mudroom/Held label and remove INBOX from HOLD decisions. Removing INBOX archives a message; it remains in All Mail and searchable. Mudroom never sends or deletes mail.
Most decisions do not read a body
Classification is a fixed, first-match-wins cascade. Safety mail surfaces first. Explicit user corrections come next, followed by known sender and thread relationships and one narrow promotions rule. Only the ambiguous remainder reaches the model layer. A message body is fetched only at that final layer, processed in memory, and discarded.
Prompt-injection defense
Email is attacker-controlled data, never model instruction. Mudroom keeps system instructions separate from a clearly delimited untrusted-content block. Before a model call, it converts HTML to text, strips hidden or deceptive layout content, removes control characters, and caps the body excerpt at about 2,000 characters.
The classifier has no executable tools, plugins, shell, filesystem access, or ability to call Gmail. One forced, inert output tool limits the response to a closed set of decisions, reason codes, and a confidence number. Mudroom validates that schema independently. Malformed output, refusal, timeout, low confidence, or any unexpected state always surfaces the message. Injection-shaped patterns are counted only in aggregate; matched text is not logged.
Personalization stays personal
Mudroom personalizes from deterministic sender and thread history, your explicit correction clicks, and an optional 500-character context statement. It does not infer preferences from opens, unread state, dwell time, scrolling, or ignored messages. Corrections are never pooled across users, and Google data is not used to train a shared model.
Model provider
Layer 6 runs on the commercial Anthropic API. Only the ambiguous remainder of your mail reaches it — Mudroom's deterministic rules settle most messages with no model call at all. Anthropic's commercial terms state that Anthropic may not train models on customer content, and API inputs and outputs are deleted within 30 days unless flagged for Usage Policy violations, which extends retention to as long as two years.
Mudroom sends no message content to any other model provider, runs no shared or fine-tuned model across users, and does not operate under a zero-data-retention agreement today. If that arrangement changes, this page changes with it.
Your control
Gmail filing is off by default and requires a separate explicit action after connection and dry-run review. The first run is capped and reports its result. You can turn off new holds, restore one corrected message, run the bulk restore for everything Mudroom archived, clear the optional context, and disconnect at any time. Disconnecting deletes the Mudroom rows linked to your account even if Google's token-revocation request fails; disconnecting alone does not restore previously archived messages, so use bulk restore first if you want them returned to Inbox. Read the full Privacy Policy for storage, providers, retention, and deletion details.
Contact
Questions about these terms or Mudroom's data practices can be sent to shaidt137@gmail.com. The service is operated as mudroom LLC.