Legal
Privacy Policy
Mudroom is built around a narrow promise: use the minimum Gmail data needed to decide what needs your attention, keep that data private, and give you a clean way to leave.
Effective and last updated August 26, 2026 at 10:15 PM CT
1. Scope
This policy explains how Mudroom handles information when you visit the website, connect a Gmail account, review classifications, enable Gmail filing, restore mail, or correct a decision. It applies to the Mudroom service and its supporting infrastructure. It does not govern Google, Anthropic, Neon, Vercel, or other services under their own terms and policies.
2. Information Mudroom accesses
Google account and authorization data
Mudroom receives your Gmail address, the permissions Google actually granted, and OAuth tokens needed to keep the connection working. The refresh token is encrypted at rest with AES-256-GCM. Access tokens are short-lived and held only in a small in-process cache. Tokens are never intentionally written to application logs.
Gmail metadata
Mudroom stores limited message metadata needed for synchronization and classification: Google message and thread identifiers, sender name and address, subject, message date, Gmail label identifiers, whether bulk-mail headers were present, and classification results. A scan of Sent mail records relationship facts such as whether you previously emailed a sender and which threads you participated in; it does not store sent message bodies.
Message content
Deterministic classification does not fetch a message body. Only an ambiguous message that reaches the model layer may be fetched in full. Mudroom converts the content to text, removes hidden content, caps the excerpt, classifies it in memory, and discards it. There is no message-body column, body cache, or body log.
Information you provide
Mudroom stores explicit correction clicks and, if you choose to provide it, a short classification-context statement about the kinds of email that would be expensive for you to miss. Mudroom does not learn from scrolling, dwell time, opens, unread state, or ignored rows.
3. How information is used
Mudroom uses this information only to:
- connect and authenticate your Gmail account;
- synchronize the minimum message metadata needed for the service;
- produce and explain hold or surface decisions;
- apply your explicit, account-specific corrections;
- after you explicitly activate Gmail filing, label HOLD decisions and archive them by removing INBOX;
- restore individually corrected or bulk-restored messages to Inbox;
- secure, troubleshoot, and operate Mudroom; and
- revoke access and delete your Mudroom data when you disconnect.
Gmail filing is off by default for every account. If you separately turn it on after reviewing the dry run, Mudroom creates or reuses theMudroom/Held label, applies it to classified HOLD messages, and archives those messages by removing INBOX. Archived messages remain in All Mail and searchable. Mudroom does not delete, trash, compose, or send mail. It requests only the single gmail.modify scope.
4. Google user data and Limited Use
Mudroom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Mudroom does not sell Google user data, use it for advertising, build advertising profiles, determine creditworthiness, or transfer it to data brokers. Mudroom does not use Google Workspace data to develop, improve, or train generalized or non-personalized AI or machine-learning models. Data is not pooled across users for training or recommendations.
5. Service providers and disclosures
Mudroom does not sell personal information. It uses a small number of service providers to operate the service:
- Google provides Gmail and OAuth. Mudroom sends requests to Google only to provide the connected-Gmail feature you requested.
- Neon hosts the PostgreSQL database containing account, encrypted-token, message-metadata, decision, and correction records.
- Vercel hosts the web application and processes ordinary request and infrastructure data needed to deliver it. Mudroom routes application logging through redaction controls designed to exclude tokens, addresses, subjects, and message content.
- Anthropic provides the Layer 6 classifier through the commercial Anthropic API. When a message is not resolved by Mudroom's deterministic rules, Mudroom sends the sender address and name, the subject, Gmail label identifiers, and a sanitized body excerpt of up to about 2,000 characters. The API call is stateless and has no executable tools; one forced, inert output tool constrains the response to Mudroom's classification schema. No data is pooled across users. Under Anthropic's commercial terms, Anthropic may not train models on customer content. Anthropic automatically deletes API inputs and outputs within 30 days, except where its automated systems flag content for Usage Policy violations, in which case it may retain inputs and outputs for up to two years and classification scores for up to seven years. Mudroom does not currently operate under a zero-data-retention agreement, and will update this page if that changes.
Mudroom may also disclose information when required by law, to protect users or the service from fraud or abuse, or as part of a business transfer with notice and protections appropriate to the data involved.
6. Retention and deletion
Account records and message metadata are retained while your Gmail connection exists so review, correction, synchronization, and explicitly enabled filing features work. Mudroom also stores whether filing is enabled, when it was first enabled, when a hold was applied, and the HTTP status associated with audited Gmail mutations. Mudroom does not claim an automatic retention schedule that the software does not yet enforce. When you use Disconnect, Mudroom attempts to revoke the Google token and then permanently deletes the user row and all linked account, token, message, sender, thread, decision, correction, summary, and audit records from its database. Database deletion proceeds even if Google's revoke endpoint is unavailable or the grant was already revoked.
Message content sent to the Layer 6 classifier is never stored by Mudroom. It is fetched, sanitized, classified in memory, and discarded. Mudroom's database holds only message metadata, the resulting decision, a reason code, confidence, and mailbox-action audit state. Anthropic's own retention of that content is described in section 5.
Infrastructure providers may retain encrypted backups or security logs for limited periods under their own retention schedules. Google data is never intentionally placed in application logs.
7. Security
Mudroom uses PKCE and one-time state values for OAuth, encrypted refresh tokens, signed HTTP-only session cookies, same-origin checks on mutations, user-scoped database operations, and redacted logging. Model output is constrained to a fixed schema, untrusted email content is isolated from instructions, and every classifier failure defaults to surfacing the message. The public Data Use & AI Safety page explains these controls in plain language.
No online service can guarantee absolute security. If you believe your connection or data is at risk, disconnect Mudroom and contact support.
8. Your choices
- You can skip or clear the optional classification context.
- You can undo explicit classification corrections.
- Gmail filing is off until you explicitly activate it.
- You can turn off new holds or bulk-restore everything Mudroom archived; both restoration actions add INBOX and remove the Mudroom held label.
- You can disconnect at any time from Mudroom or revoke access from your Google Account permissions page.
- You may contact support to ask what information is associated with your account or request deletion if you cannot access the Disconnect action.
9. Children
Mudroom is not directed to children under 13 and is not intended to collect their personal information. Do not use the service if you cannot legally consent to these data practices in your jurisdiction.
10. Changes to this policy
Material changes will be posted here with a new effective date. If a change materially expands how Gmail data is used or shared, Mudroom will provide additional notice and obtain consent when required before the new use begins.
Contact
Questions about these terms or Mudroom's data practices can be sent to shaidt137@gmail.com. The service is operated as mudroom LLC.