Privacy
Your email is yours. Here is exactly what Lumen Mail accesses, where it lives, who else touches it, and how to erase it — in plain language.
What Google data we access
Lumen Mail connects to Gmail using two scopes — gmail.modify and gmail.send — and accesses only the following:
• Message content: the plain-text and HTML bodies of your messages, and Gmail's own preview snippet.
• Message headers: sender name and address, recipients, subject, date, thread identifier, and the List-Unsubscribe headers that power one-tap unsubscribe.
• Gmail labels and state: which labels a message carries (including Inbox), and whether it is unread or starred.
• Attachment metadata only: file name, type, and size. We never download or store the contents of your attachments.
• Account identifiers: the email address of the connected Gmail account and its Google account id, so we can tell your accounts apart.
gmail.modify also lets the app act on your mail when you triage it — add and remove labels, archive, and move to Trash. gmail.send is used only to send a reply that you have reviewed and explicitly confirmed. We never read or change anything outside your mailbox, and we do not access Drive, Calendar, Contacts, or any other Google service.
How we use it
Your Gmail data is used for one purpose: to provide the features you see in the app. Specifically:
• Prioritization: scoring how much each message deserves your attention, and grouping low-priority mail, so the app can show you what matters first.
• Summaries and quick replies: generating a short summary and one-tap reply suggestions for a message you open.
• Voice replies: turning what you dictate into a draft. To make it sound like you, we use a few of your own previously sent emails as a writing-style sample. The draft is always yours to edit, and is never sent without your confirmation.
• Semantic search: your messages are split into passages and converted into numeric vectors (embeddings) so you can search by meaning and ask questions about your inbox. Answers are grounded in, and cite, your own emails.
• Notifications: writing the text of a push notification for an important message.
• Learning your preferences: your triage decisions per sender adjust future prioritization — inside your account only.
We do not use your Gmail data — raw, aggregated, or anonymized — for advertising, profiling, credit or lending decisions, resale, or any purpose other than providing and improving these user-facing features.
Where your data is stored
To prioritize, search, and work offline, Lumen Mail keeps a synchronized copy of your mail — message content, headers, labels, and attachment metadata — in its own database, together with the search index (passages and their embeddings) and the AI summaries and reply suggestions already generated for you. Your Gmail OAuth tokens are also stored server-side so the app can sync in the background; they are encrypted at rest. The iPhone app additionally keeps a local cache of your mail and your triage decisions, so the inbox works without a connection. This copy exists to run the product for you — see Retention and deletion for how to erase it.
Who else processes your data
We do not sell your data and we do not share it with data brokers, advertisers, or ad networks. Your Gmail data is shared only with the service providers that make the features work, each acting on our instructions:
• Anthropic (Claude): receives the content of the specific messages being processed, to produce prioritization, summaries, quick replies, voice-reply drafts, notification text, and search answers.
• Voyage AI: receives message passages to convert into embeddings for semantic search.
• Render: hosts our application servers and database, where the data described above is stored.
• Apple (APNs): delivers push notifications. Notification text may transit Apple's service to reach your device.
Our AI providers process your data under terms that prohibit using it to train or improve their models. We may also disclose data where required by law, or to investigate and prevent fraud, abuse, or security incidents.
How we protect it
Gmail OAuth access and refresh tokens are encrypted at rest in our database with application-level encryption, and are never exposed to the app or to any third party. All traffic — between the app and our servers, between our servers and Google, and between our servers and our AI providers — is encrypted in transit with TLS. Access to production systems is restricted to the people who operate the service, and every API request is authenticated and scoped so one account can only ever reach its own data. On your iPhone, credentials are held in the system keychain and cached mail in app-private storage protected by the device's own encryption. No method of storage or transmission is ever 100% secure, so we keep only what the features require.
Retention and deletion
We keep your synchronized mail for as long as your account is connected, because the product needs it to prioritize and search. You can erase it at any time:
• Disconnect the Gmail account in the app. This deletes our copy of that account's messages, its search index and embeddings, the learned sender signals, and the stored OAuth tokens.
• Sign out or delete the app to clear the cached mail and triage decisions held on your iPhone.
• Revoke access at Google from your Google account permissions page at any time, independently of us. Revoking stops all further access immediately.
• Ask us to delete everything by emailing [email protected]. We delete your account and associated data within 30 days.
Message content sent to our AI providers for processing is retained by them only transiently, under their standard API terms, and is not used to train their models. Routine operational logs, which do not contain message bodies, are retained for a short period for reliability and security.
Your rights
You can disconnect any connected account at any time from Account & settings in the app, and revoke Lumen Mail's access directly from your Google account. To request access to, correction of, a copy of, or deletion of your personal data, email [email protected] and we will respond within 30 days. Depending on where you live, you may have additional rights under laws such as the GDPR or Brazil's LGPD; we honor those requests regardless of jurisdiction.
Google API Services — Limited Use
Lumen Mail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
In particular, and because Lumen Mail uses AI models that interact with Google Workspace API data: we do not use raw or derived Google user data to develop, improve, or train generalized AI or machine-learning models, and we do not transfer that data to any third party that would use it to train their models. Personalization happens only within the individual user's own account. Human beings do not read your messages, except with your explicit permission (for example, if you send us a message to debug a problem), for security purposes, or where required by law.
Children's privacy
Lumen Mail is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with a new "Last updated" date and, where appropriate, surfaced in the app.
Contact
Questions about privacy or your data? Email [email protected] and we'll help.
Last updated: July 21, 2026.