message-triage

Privacy & Data Flow

Message Triage — last updated June 21, 2026

The short version: we analyze, we don’t store

Your browser fetches your Gmail directly from Google. The messages you choose to triage are then sent to our server over an encrypted (HTTPS) connection, where AI analyzes them in memory to produce your triage results. We do not store the content of your messages in our database — it exists only for the moment it takes to analyze it, then it is discarded.

The following never reach our backend at all:

The following passes through our backend in memory to be analyzed, but is never stored:

What our backend does handle

Our backend runs the AI triage on your behalf and stores only the following (never your message content):

Gmail access (optional, in your browser)

OpenAI (AI triage on our backend)

Who you talk to directly

Security

We use HTTPS everywhere (so your messages are encrypted in transit), Argon2id password hashing, optional TOTP two-factor with one-time recovery codes, login rate-limiting, short-lived single-active sessions, and a strict Content-Security-Policy with no third-party scripts. Message content is analyzed in memory only and is never written to our database.

Data retention & deletion

Because we never store your message content, there is no message data to delete — it is analyzed in memory and discarded immediately. Account, subscription, and security records are stored in Azure SQL in the United States. You may cancel anytime from the billing portal and contact us to delete your account.

Google API Services — Limited Use

Message Triage’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Contact

Questions: support@message-triage.com