Privacy policy

What Messg reads from your mailbox, why it reads it, who else processes it, and how to stop it. Written to match what the code does.

Last updated 9 September 2026.

Who we are

Messg is an inbox assistant for small operators. You connect a mailbox, it reads the enquiries that arrive, and it drafts a reply in your own words for you to review. It is in early access and is operated by the team behind messg.app.

This policy covers www.messg.app and the product signed in behind it. For the purposes of UK and EU data protection law we are the controller of your account data, and a processor of the mail we read on your instruction, which stays yours.

Data protection contact: privacy@messg.app.

What we collect, and why

Three groups, and nothing outside them. There is no analytics product, no advertising network and no data broker in this list.

Your account

Your email address, and the account and team memberships attached to it. You sign in with a one-time link sent to that address, or with Google. We never see or store a password.

Your mailbox

When you connect Gmail we ask Google for these permissions, and only these:

  • gmail.readonly, to read the enquiries that arrive and the past replies the product learns your voice from.
  • gmail.compose, to place a draft in your own Gmail drafts folder, and to send one you have pressed send on yourself.
  • userinfo.email, to know which mailbox you connected.

We deliberately do not request gmail.send. That permission would let software dispatch a message composed in the same breath. gmail.compose can only send a draft that already exists in your drafts folder, which means a draft you have had the chance to read. A permission we never asked for cannot be used by a later change nobody reviewed.

From that mailbox we store: message headers and text (sender, recipients, subject, date, body), thread structure, and attachment metadata (filename, type, size). Two reads happen, and they are different:

  • New mail, going forward. Messages that arrive after you connect are read so they can be classified and, if they are business enquiries, drafted to. Messages dated before your connection are refused by the capture pipeline.
  • Your sent mail, once, to learn your voice. On connection we import up to 18 months of mail you sent, and the threads those replies belong to, so the product can learn how you write. This import can never produce a draft or a reply: it writes mail records and voice examples, and nothing it produces can reach the drafting path.

Your business facts

What you tell us during setup, and the rate cards you enter: prices, what they include, and the notes you want a reply to respect. These exist so a draft can cite where a number came from instead of inventing one.

What we filter out and never draft to

Most mail in a working mailbox is not an enquiry, and the product is built to leave it alone. Before anything reaches a model, deterministic rules run first and cannot be overruled by one. A message is excluded when it carries a bulk or automated header (an unsubscribe link, an auto-submitted marker, a calendar invitation), comes from a no-reply or automated sender, or reads as a receipt, an order or shipping notice, a statement, a one-time code, an out-of-office or a bounce.

Drafting then requires a positive verdict that a message is a business enquiry. Silence is not consent to draft: a message the rules cannot place is marked unclear, and unclear is refused.

How AI is used, and what is sent where

Drafting is done by Anthropic's Claude models, called from our servers with our own API key. To draft one reply we send: the enquiry, the earlier messages on that thread, examples of replies you have written before (as a model of your voice), and the rate card rows and business facts the reply may cite. That is the content that leaves our systems, and it goes to Anthropic and nowhere else.

Learning your voice is not a model call. The pass that pairs your past replies with the questions they answered, and builds your tone profile, runs in our own code on our own servers.

We keep a ledger of every model call so you can see what the product spends on your behalf, on the Usage screen. That ledger records the model, token counts, latency, status and cost. It holds no message content.

Your mail is not used to train anyone's model, ours or Anthropic's, and your voice profile is yours: it is scoped to your account and is never used to write for another operator.

Nothing sends itself. A draft is a proposal. It is placed in your own drafts folder and goes out when you read it and press send. There is no autonomous sending path in this product, and the Gmail permission that would allow one is not requested.

Google user data and Limited Use

Messg's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and in addition to that policy: we use Google user data only to provide and improve the user-facing features described in this policy. We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets, and in that last case only with notice to you. We do not use Google user data for advertising, and we do not serve advertising in this product. We do not allow humans to read Google user data unless we have your explicit consent for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised.

The scopes we request are gmail.readonly and gmail.compose, plus userinfo.email. What each is for is listed under “What we collect, and why” above.

You can revoke this app's access to your Google account at any time at myaccount.google.com/permissions. Revoking stops all reading immediately. It does not delete what we already hold, so if you want that too, see “Deleting your data” below.

Where UK or EU data protection law applies, we rely on:

  • Contract. Reading the mailbox you connected, drafting replies, and keeping your account working are what you asked us to do.
  • Consent. Connecting a mailbox is an explicit act, given through Google's own permission screen and withdrawable at any time by disconnecting or revoking access.
  • Legitimate interests. Keeping the service secure, preventing abuse, recording what the product spends, and diagnosing failures. We log identifiers, statuses and provider error messages; message content is not written to our application logs.
  • Legal obligation. Where the law requires us to keep or disclose something.

The people who write to you did not sign up for this, so their mail is handled only to answer them on your behalf. It is never used to build a profile, a mailing list or a contact database for anyone else, and it is not sold or shared for anyone's marketing.

Who else processes it

Four sub-processors, each doing one job. There are no others, and we do not sell or rent data to anybody.

  • Google (Gmail API). The mailbox itself: reading new mail, importing your sent mail once, and placing drafts in your drafts folder.
  • Anthropic (Claude API). Classifying and drafting. Receives the enquiry text, thread history, your past replies as voice examples, and the facts a reply may cite.
  • Supabase. The database that holds your account, your mail records, your rate cards and your encrypted mailbox credentials, plus the authentication that signs you in. Hosted in the United States.
  • Vercel. Hosting, and page load timing measurement. The timing measurement records how fast pages render; it does not read your mail, and it sets no cookie.

Because those services are in the United States, your data is processed there as well as wherever you are. Transfers out of the UK or the EEA rely on the standard contractual clauses our providers offer.

Security

Your Gmail credentials are the most dangerous thing we hold, and they are treated that way. Access and refresh tokens are encrypted with AES-256-GCM before they are stored, with a key held only in server configuration and a key version recorded on each row so keys can be rotated. Nobody reading the database reads a usable token out of it.

Every page you open reads the database as you, under row-level security, so one account's data cannot be served to another. Background jobs that run without a session carry the account they act for on every statement. Traffic is served over HTTPS only.

No system is perfect. If you find a security problem, write to privacy@messg.app and we will respond.

How long we keep it

  • Mail records, drafts, voice examples and rate cards: for as long as your account is open, because they are what the product reads to draft your next reply.
  • The imported archive: up to 18 months of your sent mail, read once at connection and not extended afterwards.
  • Mailbox credentials: until you disconnect the mailbox or revoke access. Disconnecting deletes the stored Google credentials; if that delete fails, the screen tells you so and asks you to revoke access at Google as well, rather than reporting success it did not achieve.
  • The model call ledger: kept as the record of what was spent on your account. It contains no message content.

Disconnecting a mailbox stops all reading, and deliberately deletes no mail we already hold: a record that vanished on disconnect would be indistinguishable from one that was destroyed. Ask us and we delete it.

Your rights

Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Under the UK GDPR and the EU GDPR you also have the right to restrict or object to processing, the right to data portability, the right to withdraw consent, and the right to complain to your supervisory authority (in the UK, the Information Commissioner's Office).

Under Canadian federal law (PIPEDA) you have the right to access your personal information, to challenge its accuracy, to withdraw consent, and to complain to the Office of the Privacy Commissioner of Canada.

We do not make automated decisions about you that have a legal or similarly significant effect. The product writes drafts; you decide what is sent.

Write to privacy@messg.app and we will answer within 30 days.

Deleting your data

Three steps, and you can stop after any of them.

  • Stop the reading. Disconnect the mailbox in Settings, mailboxes. This stops all reading and deletes the stored Google credentials.
  • Revoke at Google. Remove this app at myaccount.google.com/permissions, which withdraws access independently of us.
  • Delete the account. Email privacy@messg.app from the address you signed in with. We delete the account, its mail records, drafts, voice examples and rate cards, and confirm when it is done. Backups age out on their own schedule and are not used to restore deleted data.

Cookies

We use cookies to keep you signed in and to remember which account you are working in, plus two local preferences stored in your browser. There is no tracking cookie, no advertising cookie and no third-party analytics cookie. Every one of them is named, with its purpose and lifetime, on the cookies page.

Children

Messg is a tool for running a business and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, write to privacy@messg.app and we will delete it.

Changes to this policy

When what we read, send or store changes, this page changes with it, and the date at the top moves. If a change materially affects how your mail is handled, we will tell you by email before it takes effect rather than quietly reposting the page.

Back to top