Sortr

Privacy

Last updated 25 September 2026

The short version

Sortr sorts your incoming mail against categories you write yourself, and then does what you asked with each category — label it, notify you, or prepare a draft reply. To do that it reads your mail.

Sortr never stores the contents of your messages. It stores enough to show you a list and remember its own decisions, and nothing more. It never sends mail, and it cannot permanently delete mail.

What Sortr stores

  • Your name, email address and profile picture, from the Google account you sign in with.
  • For each message: its Gmail message and thread id, the sender, the subject, the date, the Gmail labels on it, and the short preview snippet Gmail itself generates.
  • What Sortr decided about each message: the category, how confident it was, how urgent it judged the message, and a sentence explaining why.
  • Corrections you make, so Sortr stops repeating a mistake. A correction records the message it was about and what you changed.
  • Your categories, rules and settings, and a record of every action Sortr took or declined to take.

What Sortr never stores

Message bodies and attachments are never written down. Most mail is sorted from the subject and Gmail’s preview snippet alone. When that is genuinely not enough — or when you have asked Sortr to draft a reply — it fetches the message text from Google, uses it for that one request, and discards it. It is never saved to the database, never written to a log, and never included in analytics.

Google user data and Limited Use

Sortr’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, Sortr does not:

  • transfer or sell your Google data to anyone for advertising or any other purpose;
  • use your Google data to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models;
  • allow any person to read your Google data, except where you have explicitly asked us to, where it is necessary for security or to comply with the law, or where the data has been aggregated and made anonymous.

Sortr sends message details to the AI providers named below purely to answer the question you configured — which of your categories a message belongs in, or what a draft reply should say. Those providers do not train on what Sortr sends them.

The permissions Sortr asks for

Sortr requests four Google permissions and no others. Each one exists for a feature you can see:

  • Read, compose and send email (gmail.modify) — to read incoming mail so it can be sorted, and to apply labels, archive or move a message to trash when a category tells it to. Sortr does not call Google’s send endpoint anywhere in its code.
  • Manage drafts (gmail.compose) — to leave a prepared reply in your drafts. You read it and press send. Sortr never does.
  • See and edit labels (gmail.labels) — to create and apply the labels your categories use.
  • Your email address and basic profile — to sign you in and show which mailbox is connected.

Sortr deliberately does not request the broader https://mail.google.com/ permission, which would allow permanently deleting mail. Sortr can archive and it can move a message to trash, where you can still recover it. It cannot delete anything for good.

Who else handles your data

Sortr runs on other companies’ infrastructure. These are all of them:

  • Google — Reads your mailbox through the Gmail API, and signs you in.
  • Vercel — Runs the application.
  • Neon — Stores the database, hosted in Frankfurt.
  • TypeSafe AI — Decides which category a message belongs in. Does not train on what it is sent.
  • OpenAI — Writes draft replies and notification summaries, and turns your corrections into search vectors. Does not train on what it is sent.

Sortr does not sell your data, and does not share it with anyone for advertising.

How it is protected

The token that lets Sortr reach your mailbox is encrypted by Sortr itself before it is stored, with a key held outside the database and tied to your specific mailbox, so a copy of the database alone cannot be used to read anyone’s mail.

Each workspace’s data is separated inside the database itself rather than by application code being careful, so one workspace cannot read another’s — and nothing you correct can ever influence how another workspace’s mail is sorted.

Your control

  • Disconnect at any time. Removing a mailbox in Sortr deletes the stored token along with it.
  • Revoke from Google. You can withdraw Sortr’s access directly at your Google account permissions, without involving us.
  • Delete everything. Ask and we will delete your workspace and all of its data. Deleting the workspace removes every message record, classification and correction belonging to it.

Sortr keeps message records for as long as your workspace exists, because that is the list you browse. It keeps a bounded number of your most recent corrections and discards older ones.

Changes

If this policy changes in a way that affects you, the date at the top changes and we will tell you in the app before the change takes effect.

PrivacyTermsSign in