Privacy policy
This policy describes Inbox × Jev, a personal mailbox triage application operated by Deep AI Research. It is the same policy linked from the homepage and from the Google OAuth consent screen.
Last updated: 3 October 2026.
Who we are
Inbox × Jev is a single-operator tool. It is not offered as a public product to other people’s mailboxes. Questions about this policy or about Gmail access go to the developer contact email listed on the Google Auth Platform branding for this project.
Google user data we access
The application requests the Gmail scope https://www.googleapis.com/auth/gmail.modify. That scope can label, archive, move messages to Trash, and create drafts. It cannot send mail.
Each run fetches message metadata only: selected headers (From, Subject, Date, authentication and list headers) plus Gmail’s own snippet. A full message body is not downloaded. Raw mail is not written into the application store.
How that data is used
Google user data is used only to triage the connected mailbox:
- Apply or remove labels.
- Archive messages or move them to Trash.
- Save draft replies when you configure that action.
- Show run results in the Streamlit interface so you can review and undo them.
Mail that is not settled by header rules or a sender cache is classified by Jev (TypeSafe / Vercel AI Gateway). The model receives a short digest: sender, display name, subject, authentication result, bulk-mail headers, and a snippet truncated to about 300 characters — never the raw message.
If LangSmith tracing is turned on, those same digests may be sent to LangSmith so a run can be inspected. Tracing is optional and off unless you supply a LangSmith key.
Use of Google user data is limited to these practices and to Google’s Limited Use requirements for restricted Gmail scopes.
How data is stored
- OAuth token. After you consent on a machine with a browser, the refresh token is stored as
token.jsonin the local data directory, or as theGMAIL_TOKEN_JSONsecret on Streamlit Community Cloud. The Cloud filesystem is ephemeral; the secret is the durable copy there. - OAuth client. The Desktop client JSON lives beside that token locally, or as
GMAIL_CREDENTIALS_JSONin Cloud secrets. - Run history. Probabilities and verdicts are stored in a local SQLite file (
state.sqlite3). Classifier questions live inclassifiers.json. These files stay on the machine or data directory you configure. They are not a copy of full emails.
We do not sell Google user data. We do not use it for advertising. We do not share it with third parties except the processors named above (Google Gmail API, Vercel AI Gateway / Jev, and LangSmith when you enable tracing), and only to operate the features you turned on.
Retention
The OAuth token remains until you revoke access in your Google Account, delete the Cloud secret, or disconnect the mailbox. Local run history remains until you delete the data directory. Messages moved to Trash follow Gmail’s own retention (typically 30 days).
Your choices
- Revoke access at Google Account permissions.
- Delete
token.jsonlocally, or replaceGMAIL_TOKEN_JSONon Streamlit Cloud. - Leave dry run on so the application writes nothing to Gmail.
- Use Undo run to reverse the last live write.
In-product notice
The application UI shows the connected mailbox, whether the next run is a dry run, and the actions a verdict would take. This page is the durable privacy notice for the same product.