Legal

Privacy Policy

Effective 2026-09-16 · Contact: tenoclockpostman.email.sorter@gmail.com

Ten O'Clock Postman ("the App", "we", "us") is an email-sorting tool. This policy explains what personal data we collect, why, how we protect it, and the rights you have over it. It is written to comply with Singapore's Personal Data Protection Act 2012 ("PDPA") and, for users elsewhere, the laws named in section 11.

1. Who we are

Ten O'Clock Postman is operated from Singapore. For the purposes of the PDPA we are the organisation responsible for the personal data described here. Our Data Protection Officer can be reached at tenoclockpostman.email.sorter@gmail.com.

2. The short version

  • We read message metadata — sender, subject, date, folder, and read/flagged status — and nothing else. We never read, store, or transmit the body of an email or its attachments.
  • The AI assistant sees that same metadata and never message content, whether you bring your own key or use our managed assistant.
  • Nothing in your mailbox is changed until you approve it, and any change can be undone.
  • We never send mail, reply for you, or permanently delete anything.
  • We do not use your data for advertising, and we do not sell it or share it with anyone for their own purposes.
  • You can disconnect a mailbox or delete your account at any time, and your stored data goes with it.

3. What we collect, why, and for how long

We collect only what is needed to provide the service (the PDPA's purpose limitation obligation). The table lists every category.

CategoryWhat it isWhy we use itHow long we keep it
Account detailsThe email address and display name from your Google or Microsoft sign-in.To create and secure your account, and to contact you about the service.Until you delete your account.
Mailbox metadataSender name and address, subject line, date, current folder or label, read/unread and flagged status, and your folder or label structure.To propose a sorting plan, show you the before-and-after review, detect conflicts before applying, and make undo possible.While the mailbox is connected. Deleted when you disconnect it.
Access tokens and keysThe OAuth token that lets us act on your mailbox, and — only if you bring your own — the AI provider API key you enter.To read metadata and move messages on your behalf; to call the AI provider you chose.Until you disconnect the mailbox or remove the key. Encrypted at rest (AES-256-GCM).
Sorting rules and decisionsYour sorting-rules document, each approve / edit / decline decision, and the history of applied changes with their inverses.To improve later proposals and to let you revert any cleanup.Until you delete your account.
Plan and billing statusWhich plan you are on and whether it is active. Card details are entered on Stripe's pages; we never see or store card numbers.To provide the plan you chose and meet accounting obligations.For as long as required by tax and accounting law.
Technical logsIP address, timestamps, request paths, and error messages generated when you use the app.Security, abuse prevention, and fixing faults.Rolling window of up to 30 days.

When you connect a mailbox we ask Google or Microsoft for the minimum permission that allows creating folders or labels and moving messages: gmail.modify for Gmail, Mail.ReadWrite for Outlook. Neither permits sending mail or permanently deleting it. Your Google or Microsoft password is never shared with us; sign-in happens on their pages.

4. What we never collect or do

The following are never fetched, stored, or sent to any model or third party:

  • Message bodies — the text of your emails
  • Attachments
  • Full thread or conversation content
  • Anything in Trash

And the App is built to be incapable of the following:

  • Send mail or reply on your behalf
  • Permanently delete a message
  • Move anything without your approval
  • Use your mail for advertising, or sell or share it

For completeness, this is the full list of what the assistant is shown when it drafts a proposal:

  • Sender name and email address
  • Subject line
  • Date received
  • Current folder or label
  • Read / unread and flagged status
  • Your folder and label structure

5. Consent and withdrawing it

You give consent when you sign in and when you connect a mailbox, after seeing the permission screen from Google or Microsoft. You may withdraw consent at any time by:

Withdrawing consent means we can no longer propose or apply changes for that mailbox, and undo history for it is removed. We will not withhold any other part of the service as a consequence.

6. How the AI assistant handles your data

The assistant receives a summary made only of the metadata in section 3, together with your sorting rules. Where that summary goes depends on the option you choose in the App:

  • Bring your own key. The summary is sent directly to the AI provider you configured (for example OpenAI, Anthropic, Google, or any OpenAI-compatible endpoint you control, including a model you host yourself), using your own account and key. That provider's terms and privacy policy govern its handling of the data. We do not receive a copy.
  • Managed assistant. The summary is sent to Google Vertex AI (Gemini) inside our own Google Cloud project, solely to generate the proposal. Google does not use data sent to Vertex AI to train its models.

In neither case is any message body, attachment, or thread content included. The model's answer is a structured list of proposed folder changes and moves, which is shown to you for review.

7. Who we share data with, and transfers outside Singapore

We do not sell personal data and we do not share it with anyone for their own purposes. We disclose it only to service providers who process it on our behalf, under contracts that require them to protect it:

  • Google and Microsoft — the mailbox services you connect; the source of the metadata we read and the destination of the moves you approve.
  • Google Cloud (Cloud Run, Cloud Storage; United States) — hosting and encrypted database backups.
  • Google Vertex AI — generates proposals for the managed assistant, as described in section 6.
  • Clerk — account sign-in and session management.
  • Supabase — stores your plan and role. Never receives mailbox data.
  • Stripe — payment processing where paid plans apply. We never see card numbers.

Transfers outside Singapore. Some of these providers store or process data outside Singapore, principally in the United States. In line with section 26 of the PDPA, we transfer data only to recipients bound by contractual obligations that give it a standard of protection comparable to the PDPA, such as the providers' data processing agreements. We may also disclose data where the law requires it, or to protect the rights and safety of users and the service.

8. How we protect your data

  • OAuth tokens and any API key you enter are encrypted at rest with AES-256-GCM. Decrypted values are never written to logs.
  • All traffic between your browser, our servers, and the mailbox and AI providers is encrypted in transit (TLS).
  • We request the least-privilege mailbox scopes described in section 3 and never broaden them without asking you again.
  • Message bodies are never fetched, so they cannot be leaked from our systems.
  • Safety rules — no message deletion, Trash excluded, every change reversible — are enforced in code and covered by automated tests, not left to the AI model's discretion.
  • Access to production systems is restricted to the operator.

9. Retention and deletion

We keep personal data only as long as it serves the purpose it was collected for (the PDPA's retention limitation obligation). Retention periods are listed in the table in section 3. In summary: mailbox metadata and tokens are deleted when you disconnect a mailbox; account data, rules, and history are deleted when you delete your account; encrypted backup copies are overwritten within 30 days; technical logs roll off within 30 days. Billing records are kept only as long as tax and accounting law requires.

You can disconnect a mailbox or delete your account yourself from the App's Setup screen, without contacting us.

10. Your rights under the PDPA

Under the PDPA you have the right to:

  • Access — ask what personal data of yours we hold and how we have used or disclosed it in the past year.
  • Correction — ask us to correct an error or omission in your personal data.
  • Withdraw consent — as described in section 5.
  • Data portability — where the PDPA's portability obligation applies, receive a copy of your data in a usable format. In practice, your sorting rules and history are viewable in the App at any time.

To exercise a right, email tenoclockpostman.email.sorter@gmail.com from the address on your account. We respond within 30 days; if we need longer we will tell you why and when to expect our reply. We do not charge for reasonable requests. If you are not satisfied with our response, you may complain to the Personal Data Protection Commission of Singapore (pdpc.gov.sg).

11. Users outside Singapore (GDPR and CCPA)

If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) or its UK equivalent applies to you. Our lawful bases are your consent, given when you connect a mailbox, and performance of a contract to provide the service you signed up for; for security logging, our legitimate interest in keeping the service safe. In addition to the rights above you may ask us to erase your data, restrict or object to processing, and receive your data in a portable format, and you may lodge a complaint with your local supervisory authority.

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to know what personal information we collect, to delete it, to correct it, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined in the CCPA, and we do not use it for cross-context behavioural advertising.

All of these rights are exercised the same way: email tenoclockpostman.email.sorter@gmail.com.

12. Data breach notification

If we discover a data breach we will assess it promptly. Where the breach is notifiable under Part 6A of the PDPA — because it is likely to cause significant harm to affected individuals or affects 500 or more people — we will notify the Personal Data Protection Commission within 3 calendar days of that assessment, and notify affected users as soon as practicable with what happened, what data was involved, and what we are doing about it. Where other laws require notification, we will comply with them too.

13. Cookies and local storage

The App uses only what it needs to work:

  • Sign-in session cookies, set by our sign-in provider (Clerk), to keep you signed in. These are strictly necessary.
  • Browser local storage for preferences such as your light/dark theme. This never leaves your browser.

We use no advertising cookies, no tracking pixels, and no third-party analytics on the App or on these public pages.

14. Google and Microsoft API policies

Ten O'Clock Postman's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Gmail data only to provide the sorting features you see in the App; we do not transfer it except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with prior notice to you; we never use it for advertising; and no human reads it except with your explicit permission, for security purposes, or to comply with law.

Our use of Microsoft 365 data is limited in the same way and complies with the Microsoft APIs Terms of Use.

15. Children

The service is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.

16. Changes to this policy

We will update the effective date at the top of this page whenever this policy changes. For material changes we will notify active users by email before the change takes effect. Continuing to use the service after that date means you accept the updated policy.

17. Contact and Data Protection Officer

Questions, requests, or complaints about this policy or your personal data: our Data Protection Officer at tenoclockpostman.email.sorter@gmail.com.