Data & permissions
Privacy policy
This policy covers burn-mail, a private personal and family email assistant, and this public information website. Questions and data-removal requests can be sent to rburnpegan@gmail.com.
Information accessed
With the account holder's Google authorization, burn-mail can access account identity information and read Gmail message data, including senders, recipients, subjects, dates, labels, snippets, and message bodies. The Gmail connection uses read-only authorization. Other email accounts may be connected separately through IMAP.
How information is used
Email data is used to find relevant messages, prepare personal and family briefings, identify reminders and alerts, and track which actions or alerts have already been handled. Account information identifies the connected mailbox. Authorization tokens allow the private assistant to access that mailbox without asking for a Google password.
AI processing and other recipients
Processing may take place on locally hosted models. When a task uses configured cloud escalation or delegation, selected email content, prompts, summaries, and task context may be sent to OpenAI, or through OpenRouter to the selected model provider. Cloud-provider retention and processing depend on the service, account settings, and selected provider; this policy does not promise that all processing stays local or that those providers have zero retention.
Briefings and alerts may be sent through WhatsApp to configured personal or family recipients. Recipients can retain, copy, or forward what they receive. Account holders should agree with the operator on these destinations before connecting an account. The public information website does not receive mailbox contents or authorization tokens.
Storage and retention
The private environment stores connection settings, authorization credentials, task state, and records used to avoid duplicate actions or alerts. Email excerpts and derived summaries may also be retained in assistant conversations, operational logs, generated reports, and backups. These records may remain until deleted by the operator; no fixed automatic deletion period is promised here.
Deletion requests cover copies under the operator's control. Revoking Google access stops future authorized access but does not automatically remove existing summaries, backups, or copies already delivered to messaging recipients or cloud services.
Security and access
The private assistant is separate from this public website. Access to the private portal is restricted through Tailscale and authentication. Credentials are not published on this site. No system can guarantee absolute security; please do not send passwords, access tokens, or complete sensitive emails to the public support address.
Your choices
You can revoke burn-mail's Google authorization through your Google Account connections. Contact the operator to disconnect a mailbox, change briefing recipients or processing preferences, or request deletion of stored data. The operator may need to verify that you control the affected account before acting.
This public website
This site contains only informational pages. It has no sign-in, forms, advertising, or application analytics scripts. Cloudflare hosts and delivers it and may process ordinary network information such as IP addresses and request metadata for delivery and security. See Cloudflare's privacy policy.
Changes
Updates will be published on this page with a revised effective date. Account holders should review the policy before authorizing a new integration or a material change in processing.