The full breakdown, for IT, security, and compliance review. For the plain-language version everyone else should read, see Privacy & Security.
Four capture channels are live today: email (any provider, not just one), a photo you snap or upload, a text you forward to your dedicated BlindSpot number, and something you type in directly. Voicemail is the one channel still on the roadmap, not yet built.
When you connect an inbox — Gmail, Outlook, Yahoo, iCloud, or another provider — you're granting a read-only permission (for Gmail specifically, Google calls it gmail.readonly; other providers have their own equivalent). This isn't just a promise in our privacy policy — your provider's own permission system makes it technically impossible for BlindSpot to send, delete, label, archive, or edit anything in your mailbox. We only ever look at mail you've already sent, to spot commitments you've made.
The other three channels are all opt-in, one-time actions you take, not standing access we hold: a photo you snap or upload is read once for its text and discarded (see section 2), a text you forward arrives through Twilio to your dedicated BlindSpot number, and anything you type in is exactly what it looks like — text you wrote, submitted directly. None of these give BlindSpot any access beyond the specific thing you sent it.
We do not store your full emails, the photos you send, or full text-message threads.
When something — an email, a forwarded text, a photo, or a typed note — looks like a commitment, we save:
A photo itself is never stored — it's processed in memory for its text and discarded immediately after. The rest of an email, or a text thread, that we didn't flag is never copied anywhere either. We only ever read what's needed to check for a commitment, in the moment we check it.
Two more limits on the stored excerpt/key-info text specifically: a best-effort filter strips obvious sensitive data (things that look like account numbers, IDs, or credentials) before it's ever saved — it catches common patterns, not everything, so it's one layer, not a guarantee. And once a commitment has been resolved for 90 days, the verbatim excerpt is cleared automatically — the title, summary, key info, and status stay (that's the actual point of the app), but the original source text doesn't sit around indefinitely.
This isn't just an app-level check we could get wrong — it's enforced at the database itself via row-level security (RLS). Every account's commitments are tagged with that account's ID, and the database is configured to refuse to return rows that don't belong to whoever's logged in, so a bug in the application code alone can't leak your data to another account — the database is the thing saying no. That said, RLS is only as good as the policies configured on each table; we hold ourselves to enabling it correctly on every table that holds account-scoped data, and treat any gap found in that as a priority fix, not a footnote.
Every party that sees any of your data, and exactly what each one sees:
No ad networks. No data brokers. Nothing is sold, ever.
One mailbox: Settings → the mailbox's own disconnect control. BlindSpot stops reading it immediately — the underlying OAuth connection (or, for IMAP, the stored app-password) is deleted server-side, not just hidden in the UI. Commitments already captured from it stay in your list; reconnecting later is a normal new connection, not a restore.
Everything: Settings → "Delete my account." Type DELETE to confirm, and in one step it removes every commitment, disconnects every mailbox, and deletes your login — no one on our side has to do it by hand.
Worth being direct about the account-deletion path: it's immediate and permanent. There's no grace period and no way to undo it once you've confirmed. If you're not certain, don't type DELETE yet — ask first.