Privacy Policy
Last updated: October 8, 2026. Operator: Kaleidoscope Data LLC ("we", "us"). Contact: support@vetoinbox.com.
Summary
- VetoInbox connects to your Gmail account to find political email and move it to Trash.
- No person reads your email. We do not sell it, use it for ads, or use it to train AI models.
- We do not store the content of your messages.
- You can undo any removal, and you can delete your account and all stored data at any time.
Google API Services User Data Policy: Limited Use
VetoInbox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, this means:
- We use Gmail data only to provide the user-facing features of VetoInbox: classify new mail, label and trash political mail, show you what was removed, and let you undo.
- We do not transfer Gmail data to others except as needed to provide those features (see the OpenAI section), to comply with law, or as part of a merger or sale with notice to you.
- We do not use Gmail data for advertising, and we do not sell it.
- We do not use Gmail data to develop, improve, or train generalized AI or machine learning models.
- No human reads your Gmail data, except with your explicit consent for a specific message (for example, when you ask for support), where needed for security investigations or abuse, or where law requires it.
What we collect
| Data | Why | Kept for |
|---|---|---|
| Google account email address and Google user ID | To identify your account and sign you in | Until you delete your account |
| Google OAuth refresh token (encrypted with Google Cloud KMS) | To access your Gmail while you are away | Until you delete your account or revoke access |
| Message content (sender, subject, text) read from Gmail | To classify each new message | Held in memory only while classifying. Not stored. |
| Metadata of removed messages: Gmail message ID, sender name and address, subject, dates, AI score, action taken | To show your Removed list and support Undo | 30 days |
| Per-message processing record (ID and outcome) | To avoid handling a message twice | 30 days |
| Cached check of whether you have written to a sender (hashed address) | To skip senders you wrote to | 7 or 30 days |
| Your settings and sender allowlist | To apply your choices | Until you delete your account |
| Usage counters (counts of messages processed, no content) | To run and improve the service and plan costs | Up to 400 days |
| Email address you give for the waitlist or an invite | To contact you about the beta | Until you ask us to delete it, or you delete your account |
We do not use analytics or advertising trackers. The service sets one session cookie (__session) to keep you signed in. It contains no email content.
Gmail permission we request
We request the Google permission https://www.googleapis.com/auth/gmail.modify, plus openid and email to identify you. We need gmail.modify to read messages so we can classify them, to create and apply the Auto/Political label, to mark messages read, and to move them to or from Trash. We do not send email. We never permanently delete email. We never mark email as spam.
How we use AI (OpenAI processing disclosure)
To decide whether a message is political, we send a reduced version of it to the OpenAI API. OpenAI acts as our service provider (processor). What we send:
- The sender’s display name and address, the subject line, and whether the message looks like bulk mail.
- The message text, with web links shortened to their domain, your own email address replaced by “[recipient]”, and the text cut to a fixed length.
We do not send attachments, your other headers, or your OAuth tokens. Under OpenAI’s API terms, OpenAI does not use API inputs to train its models by default. OpenAI may retain API inputs for up to 30 days for abuse monitoring. We send this data only to provide the VetoInbox feature, and for no other purpose. OpenAI’s policies are at openai.com/policies. We have not arranged Zero Data Retention with OpenAI, so this 30-day retention applies.
Who else handles data
- Google Cloud (Google LLC) hosts the service in the United States and provides storage, encryption, and messaging infrastructure.
- OpenAI, as described above.
- Payment processor: none. The beta is free, and we do not collect payment information. If we add paid plans, we will update this policy before we collect any payment.
We do not sell personal information and we do not share it for advertising.
Your choices
- Undo. Restore any removed message from the Removed page while it is in Trash.
- Pause or preview. Stop all removal, or switch to label-only mode, in Settings.
- Revoke access. Remove VetoInbox at myaccount.google.com/permissions.
- Delete your account. In Settings, choose Delete account. We stop watching your mailbox, revoke the token, and delete the data we hold. We do not restore trashed mail or remove the
Auto/Politicallabel from your Gmail. You can do that yourself. - Ask us. To access, correct, or delete your data, write to support@vetoinbox.com.
Security
Refresh tokens are encrypted with Google Cloud KMS. Access tokens exist only in memory. Data is encrypted in transit and at rest. Our logs do not contain email addresses, subjects, message text, or tokens. Access to production systems is limited to the operator.
Children
VetoInbox is not for children under 13 (or the age required in your country). We do not knowingly collect their data.
Changes
If we change this policy in a material way, we will update the date above and tell beta users by email.
Contact
Kaleidoscope Data LLC, 2443 Fillmore St #380-5407, San Francisco, CA 94115, USA. support@vetoinbox.com.