BlindSpot
Nothing slips through the cracks
← Back to Privacy & Security

Technical Security Details

The full breakdown, for IT, security, and compliance review. For the plain-language version everyone else should read, see Privacy & Security.

Four capture channels are live today: email (any provider, not just one), a photo you snap or upload, a text you forward to your dedicated BlindSpot number, and something you type in directly. Voicemail is the one channel still on the roadmap, not yet built.

1What we can see

Read-only, enforced by your provider

When you connect an inbox — Gmail, Outlook, Yahoo, iCloud, or another provider — you're granting a read-only permission (for Gmail specifically, Google calls it gmail.readonly; other providers have their own equivalent). This isn't just a promise in our privacy policy — your provider's own permission system makes it technically impossible for BlindSpot to send, delete, label, archive, or edit anything in your mailbox. We only ever look at mail you've already sent, to spot commitments you've made.

The other three channels are all opt-in, one-time actions you take, not standing access we hold: a photo you snap or upload is read once for its text and discarded (see section 2), a text you forward arrives through Twilio to your dedicated BlindSpot number, and anything you type in is exactly what it looks like — text you wrote, submitted directly. None of these give BlindSpot any access beyond the specific thing you sent it.

2What we store — and what we don't

We do not store your full emails, the photos you send, or full text-message threads.

When something — an email, a forwarded text, a photo, or a typed note — looks like a commitment, we save:

A photo itself is never stored — it's processed in memory for its text and discarded immediately after. The rest of an email, or a text thread, that we didn't flag is never copied anywhere either. We only ever read what's needed to check for a commitment, in the moment we check it.

Two more limits on the stored excerpt/key-info text specifically: a best-effort filter strips obvious sensitive data (things that look like account numbers, IDs, or credentials) before it's ever saved — it catches common patterns, not everything, so it's one layer, not a guarantee. And once a commitment has been resolved for 90 days, the verbatim excerpt is cleared automatically — the title, summary, key info, and status stay (that's the actual point of the app), but the original source text doesn't sit around indefinitely.

3Encryption

4Your data is walled off from everyone else's

This isn't just an app-level check we could get wrong — it's enforced at the database itself via row-level security (RLS). Every account's commitments are tagged with that account's ID, and the database is configured to refuse to return rows that don't belong to whoever's logged in, so a bug in the application code alone can't leak your data to another account — the database is the thing saying no. That said, RLS is only as good as the policies configured on each table; we hold ourselves to enabling it correctly on every table that holds account-scoped data, and treat any gap found in that as a priority fix, not a footnote.

5Who else touches your data

Every party that sees any of your data, and exactly what each one sees:

No ad networks. No data brokers. Nothing is sold, ever.

6Disconnecting a mailbox, or deleting your account

One mailbox: Settings → the mailbox's own disconnect control. BlindSpot stops reading it immediately — the underlying OAuth connection (or, for IMAP, the stored app-password) is deleted server-side, not just hidden in the UI. Commitments already captured from it stay in your list; reconnecting later is a normal new connection, not a restore.

Everything: Settings → "Delete my account." Type DELETE to confirm, and in one step it removes every commitment, disconnects every mailbox, and deletes your login — no one on our side has to do it by hand.

Worth being direct about the account-deletion path: it's immediate and permanent. There's no grace period and no way to undo it once you've confirmed. If you're not certain, don't type DELETE yet — ask first.

Questions about any of this — ask directly, no ticket system required. Prefer the plain-language version? Go back →