Legal
Privacy Policy
Effective 11 August 2026
Promise Ledger (“Promise Ledger”, “we”, “us”) helps customer-facing teams detect commitments and promises in email, and turns human-approved detections into a shared, trackable ledger. This policy explains what information we collect, how we use it, who we share it with, and the choices available to you — including how we access and handle Gmail data through Google APIs and Outlook data through Microsoft Graph.
Promise Ledger is an early-stage product currently in private testing. This policy describes what the product actually does today, not aspirational future functionality.
This policy covers your data specifically. For the broader terms governing your use of Promise Ledger, see our Terms of Service.
01
Information we collect
Account information
When you sign in with Google, we receive your name, email address, and profile image from your Google account, and create a corresponding Promise Ledger user and workspace record.
Gmail data
If you connect Gmail, Promise Ledger requests read-only access to your mailbox via the Gmail API. We access message content (subject, body text, sender/recipient headers) and metadata for messages you explicitly scan (an opt-in historical scan, with a window you choose) and for new messages going forward, via Google’s push notification service, so detection can happen automatically without you having to trigger a scan every time.
Promise Ledger never sends, deletes, modifies, or forwards email on your behalf. The Gmail connection is read-only in the product design, not just in this policy.
Outlook data
If you connect Outlook, Promise Ledger requests read-only access to your mailbox via Microsoft Graph. We access message content (subject, body text, sender/recipient information) for messages you explicitly scan (an opt-in historical scan, with a window you choose). Automatic monitoring of new Outlook mail is not built yet — scanning is on demand only, until a future update adds it.
Promise Ledger never sends, deletes, modifies, or forwards email on your behalf. The Outlook connection is read-only in the product design, not just in this policy.
Detected content
When a message appears to contain a commitment or a meeting, we store the specific evidence needed to support that finding — a short quote, the sender, the message date, and a link back to the original message — plus whatever a reviewer edits or decides. We do not keep a permanent copy of your full mailbox.
Usage data
We use basic, privacy-conscious product analytics (Vercel Analytics) to understand aggregate usage of the product. This does not include Gmail or Outlook content.
02
How we use information
We use the information above to: operate your account and workspace; scan and classify email for possible commitments, promises, and meetings; present detections for your review and approval; maintain the ledger, calendar, and audit history of approved items; and improve the product’s reliability and detection quality.
Every AI detection requires a human to approve, edit, or dismiss it before it becomes an official record. Nothing is added to your team’s ledger or calendar automatically.
03
Who we share information with
We do not sell your personal data. We share information only with the service providers necessary to run Promise Ledger, and only for that purpose:
- Google — for authentication and, if you connect it, read-only Gmail access and push notifications of new mail.
- Microsoft — if you connect it, read-only Outlook mailbox access via Microsoft Graph. Microsoft is not used for authentication — signing in to Promise Ledger is Google-only.
- Anthropic (Claude API) — the text of a message may be sent to Anthropic’s API so our AI classifier can determine whether it contains a commitment, its likely direction, and a possible due date or meeting. This applies to both mail you send and mail you receive that reaches the classifier. Anthropic processes this content to return a classification result to Promise Ledger; it is not used by us to train shared models.
- Neon — our database provider, which stores the data described in this policy.
- Vercel — our application hosting provider.
- Resend — our email-delivery provider. Sends the notification emails described in Section 2 (e.g. overdue-promise alerts, weekly summaries), which can include the name of a customer referenced in an approved promise.
We may also disclose information if required by law, or to protect the rights, safety, or property of Promise Ledger, our users, or others.
If your organization requires a signed Data Processing Agreement (a common requirement for EU-based or enterprise customers), one is available on request — contact us using the details in Section 11.
04
Data retention and deletion
We retain account and workspace data for as long as your workspace is active. Gmail and Outlook OAuth tokens are encrypted at rest (AES-256-GCM) and are deleted immediately when you disconnect the mailbox from your Integrations settings — that control is available directly in the product, not just on request. Detected evidence is kept only as long as needed to support review and, once approved, the resulting record in your ledger.
To request deletion of your account or workspace data beyond what the in-product controls already cover, contact us using the details in Section 11.
05
Your choices and controls
- Disconnect Gmail or Outlook at any time from Integrations — this immediately removes the stored access tokens.
- Choose whether and how far back a historical scan looks, or skip it entirely.
- Exclude specific addresses, domains, or your internal team’s own domain from being treated as customer-facing.
- Approve, edit, or dismiss every individual AI detection — nothing is automatic.
- Review Google’s own account permissions at any time at myaccount.google.com/permissions to see or revoke Promise Ledger’s access directly from Google.
- Review Microsoft’s own app permissions at any time at myaccount.microsoft.com/consent-app-access (or ask your IT admin, for organizations that require admin approval) to see or revoke Promise Ledger’s access directly from Microsoft.
06
Cookies
Promise Ledgeruses only strictly-necessary cookies: a session cookie that keeps you signed in, and a short-lived (10-minute) security cookie used only during the Gmail/Outlook connection process to prevent cross-site request forgery. Neither is used for advertising or cross-site tracking, and neither requires prior consent under GDPR/ePrivacy rules, since both are necessary for the service you’ve asked for.
Our product-analytics tool (Vercel Analytics, mentioned in Section 1) does not use cookies at all — it measures aggregate usage without setting any identifier in your browser. We do not use any third-party advertising or marketing cookies, and we do not have a cookie consent banner because we have nothing on this site that needs one.
07
Data security
Data in transit is encrypted (HTTPS/TLS). Gmail and Outlook OAuth tokens are encrypted at rest. Data is scoped per workspace, so one company’s data is not accessible to another’s. Actions taken on detections and connections are recorded in an internal audit trail.
No system is perfectly secure, and as an early-stage product we do not yet claim any formal security certification — we will update this policy if and when that changes.
08
Children's privacy
Promise Ledger is a business tool intended for use by working professionals. It is not directed at, and we do not knowingly collect information from, children under 16.
09
International data transfers
Our service providers (Section 3) operate infrastructure in multiple regions, which may mean your data is processed outside the country you are located in. We rely on those providers’ own safeguards for cross-border transfers rather than maintaining a separate program of our own at this stage.
10
Your data protection rights
If you are located in the European Economic Area, the UK, or another jurisdiction with similar data protection laws, you have the right to: access the personal data we hold about you; correct inaccurate data; request erasure; restrict or object to certain processing; receive your data in a portable format; and withdraw consent where we rely on it. You also have the right to lodge a complaint with your local data protection supervisory authority at any time — this is a right we cannot limit or override, regardless of anything else in this policy.
We act as the controller for your account information (Section 1), processed on the basis of performing our contract with you. For the content of a connected mailbox — which typically includes personal data belonging to other people, such as your customers or colleagues — we act as a processor on behalf of you or your organization, who remains the controller responsible for that data and for the lawful basis to process it. This mirrors our standard Data Processing Agreement, available on request (Section 3).
To exercise any of the rights above, contact us using the details in Section 11 — if the request concerns mailbox content, we may direct you to your organization as the controller for that data where appropriate.
11
Contact us
Questions about this policy, or requests regarding your data, can be sent to privacy@promiseledger.dev.
12
Changes to this policy
We may update this policy as the product changes. We will update the effective date above when we do, and for material changes we will provide a more prominent notice.