TsugiteTsugite

Privacy Policy

Last updated: May 18, 2026

This Privacy Policy describes how Tsugite ("we", "us") collects, uses, and protects information when you use the Tsugite service ("Service").

1. Information We Collect

a. Account information

When you sign in with Google, we receive your Google account ID, email address, and name from Google's OpenID Connect / userinfo endpoints.

b. Gmail access tokens

We store your Google OAuth access token and refresh token, encrypted at rest, in order to read Gmail metadata and message content needed to fulfill forwarding rules you configure. The Gmail scopes we request are limited to gmail.readonly.

c. Forwarding rules and metadata

We store the sender email address, target Slack webhook URL, channel name, workspace name, and the timestamp and result (success/failure) of each forwarding attempt. We do not store the subject line, body, or any content of the forwarded email itself.

d. Billing information

Payment processing is handled by Stripe. We store only the Stripe customer ID and subscription ID; we never receive or store payment card numbers.

2. How We Use Gmail Data (Google Limited Use)

Tsugite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Gmail data only to provide the forwarding feature you explicitly configured. When you create a rule, we may read the sender addresses (not the contents) of your recent inbox messages to suggest senders; these are shown to you once and are not stored.
  • We do not sell Gmail data to third parties.
  • We do not use Gmail data for advertising.
  • We do not use Gmail data to train generalized AI/ML models.
  • We do not allow humans to read Gmail data unless we have your explicit consent for specific support tickets, or as required by law.

3. Email Content Handling

Email content (subject and body) passes through server memory only during forwarding. We do not persist email content to disk or database. Once forwarded to your configured Slack webhook, the content exits our systems and is governed by Slack's data handling.

4. Where Data Is Stored

Account information, forwarding rules, and logs are stored in Cloudflare D1 (SQLite) on Cloudflare's edge network. Access tokens are encrypted using AES-GCM with a secret known only to the Service.

5. Third-Party Sub-Processors

  • Google (Gmail API, OAuth) — sign-in and email reading
  • Slack — destination for forwarded messages
  • Cloudflare — hosting, database, and edge runtime
  • Stripe — payment processing for paid plans

6. Data Retention

We retain account data, forwarding rules, and logs for as long as your account is active. Forwarding logs older than 90 days are automatically purged. When you delete your account, all associated data is deleted within 30 days, except where retention is required by law or for fraud prevention.

7. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. You may also revoke Tsugite's access to your Gmail at any time from your Google Account permissions page. To exercise other rights, contact us at the email below.

8. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

9. Changes to This Policy

We may update this Privacy Policy. Material changes will be communicated via email or in-app notice.

10. Governing Language

This Privacy Policy is written in English. Translations are provided for convenience only. In the event of any discrepancy, the English version prevails.

11. Contact

For privacy questions or to exercise your rights, contact emuemuJP@proton.me.