Privacy Policy

Last updated: September 8, 2026

Who we are

SignalDesk (“SignalDesk”, “we”, “us”) is a personal reading application that collects email newsletters, blog posts, and podcast episodes you subscribe to into a single reading inbox and generates short AI summaries of them. This policy explains what data the application handles and why.

Questions about this policy or about data the application holds about you can be sent to dpstr39@gmail.com.

Information we collect

SignalDesk collects only what it needs to work:

  • Account information. The email address you sign in with, and authentication data held by our authentication provider. If you sign in with Google, we receive your basic profile information (name, email address, profile picture) from that sign-in.
  • Google account data (Gmail). If you choose to connect a Gmail account, we request the gmail.readonly scope. Using it, we read message headers (sender, subject, date, list-unsubscribe headers) to identify newsletters, and read the message body of messages from senders you have confirmed as newsletter sources. We store the address of the connected mailbox, the OAuth access and refresh tokens issued for it, and the content of the newsletter messages we ingest. We do not send email, modify or delete anything in your mailbox, or read messages from senders you have not confirmed as sources.
  • Content you add. Blog feeds and podcasts you subscribe to, along with the articles, episodes, transcripts, and chapter data fetched from those public sources.
  • Reading activity. Read/unread and archive state, highlights you create, collections you organize sources into, and records of AI summarization calls (model used, token counts, and cost) for usage tracking.

SignalDesk does not use advertising or third-party analytics trackers, and does not build advertising profiles.

How we use your information

  • To authenticate you and keep you signed in.
  • To fetch newsletters from your connected Gmail account, and articles and episodes from feeds you subscribe to, and display them in your reading inbox.
  • To generate short AI summaries of that content, shown only to you.
  • To operate the service: retry failed syncs, keep ingestion idempotent, track job status, and monitor AI usage cost.

We do not sell your data, share it with data brokers, or use it for advertising. We do not use your content to train machine learning or AI models, and we do not permit our providers to do so.

Google user data and Limited Use

SignalDesk’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, with respect to data obtained through the Gmail API:

  • We use it only to provide and improve the user-facing features described in this policy — collecting your newsletters into a reading inbox and summarizing them for you.
  • We do not transfer it to others except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
  • We do not use it for serving advertisements of any kind.
  • We do not allow humans to read it, except with your explicit consent for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized.
  • We do not use it to develop, improve, or train generalized AI or machine learning models.

How your information is shared

We share data only with the service providers required to run the application, each acting on our instructions:

  • Vercel — application hosting and serverless execution.
  • Supabase — database and authentication. Newsletter content, feed content, tokens, and account records are stored here.
  • Anthropic— AI summarization. The text of an item is sent to the Anthropic API to produce its summary. Under Anthropic’s commercial terms, API inputs and outputs are not used to train their models.
  • Google — the source of Gmail data, contacted with the token you granted.

We may also disclose information if required by law, or where necessary to investigate abuse or protect the security of the service.

Storage, security, and retention

  • Data is stored in our provider's managed Postgres database, encrypted in transit (TLS) and encrypted at rest by the provider.
  • Row-level security is enabled on every user-scoped table, so records are readable only by the account that owns them.
  • OAuth access and refresh tokens are stored so that scheduled syncs can run without you re-authorizing each time. They are used only to call the Gmail API on your behalf.
  • Ingested content is retained until you delete it or ask us to delete your account. Sync job records and AI usage records are retained for operational history.

No system is perfectly secure. We take reasonable measures to protect your data, but we cannot guarantee absolute security.

Your choices and how to delete your data

  • Disconnect a mailbox. In Settings, choose Disconnect on a connected Gmail account. This deletes the stored tokens for that mailbox and stops all further access to it. Newsletters already ingested remain in your inbox until you delete them.
  • Revoke access at Google.You can revoke SignalDesk’s access to your Google account at any time at myaccount.google.com/permissions. Revoking access immediately stops any further Gmail reads.
  • Delete everything. Email dpstr39@gmail.com to request deletion of your account and all associated data, including stored Gmail content and tokens. We will action the request within 30 days.

Children

SignalDesk is not directed to children under 13, and we do not knowingly collect data from them.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the “Last updated” date above. Continued use of the application after a change means you accept the updated policy.