1. Overview
This Privacy Policy explains how LetterFinch, a product of Skipper Innovations ("LetterFinch," "we," or "us"), accesses, uses, stores, and protects information when you connect an email account or use the LetterFinch desktop application.
LetterFinch is currently in private development. The present application is local-first: email data and application state are processed and stored on the user’s own device rather than on a LetterFinch-operated mail server.
2. Google user data
When you connect a Google account, LetterFinch requests only the Google permissions displayed during the authorization process. The development application currently requests basic account identity and Gmail access needed to display, organize, search, and manage mail in the application.
Depending on the features you use, Google user data accessed by LetterFinch may include:
- your Google account name, email address, and profile identifier;
- email message content, headers, labels, thread identifiers, and attachment metadata;
- mailbox state needed to synchronize messages and reflect user-directed actions; and
- OAuth credentials needed to maintain the connection.
LetterFinch uses this data only to provide or improve user-facing email features that are visible in the application. We do not sell Google user data, use it for advertising, or use it to train generalized or shared artificial-intelligence models.
3. Local storage and security
LetterFinch stores synchronized message data, search indexes, drafts, and application settings in a local database on your device. Google refresh tokens are stored in the operating system’s secure credential store, such as macOS Keychain, and are not written to the LetterFinch message database.
The current development version does not transmit synchronized Gmail content to a LetterFinch-operated cloud service. Internet connections are made to the email provider to authorize the account and perform user-requested synchronization.
4. Agents and automation
LetterFinch is designed to support both built-in workflows and user-selected external agents. Automated capabilities are intended to be explicitly authorized, narrowly scoped, auditable, and reversible where the underlying email provider permits.
The current development version does not send Google user data to a LetterFinch-operated AI training service. If a future feature transmits email data to an external AI provider, LetterFinch will present a clear disclosure and obtain the user’s affirmative action or consent before that transfer. A user who independently connects an external tool is also responsible for reviewing that tool’s privacy terms and permissions.
5. Retention and deletion
Local data remains on your device until you remove the connected account, delete the application’s local data, or uninstall LetterFinch and remove its application-support files. Disconnecting an account removes LetterFinch’s stored OAuth credential for that account. You may also revoke LetterFinch through your Google Account’s third-party connections page.
During private development, diagnostic records are kept locally and are designed not to contain OAuth tokens or full credential values.
6. Your choices
- You choose which accounts to connect.
- You may disconnect an account from LetterFinch at any time.
- You may revoke Google access from your Google Account settings.
- You may contact us to ask how LetterFinch handles a particular category of data.
7. Changes to this policy
We may update this policy as LetterFinch develops. Material changes to data use will be disclosed before they take effect, and the effective date at the top of this page will be updated.
8. Contact
Questions about LetterFinch privacy or Google user data can be sent to [email protected].
Skipper Innovations
Murfreesboro, Tennessee, United States