FollowUp Memory
Home

Privacy Policy

Last updated September 21, 2026

1. Who operates FollowUp Memory

גבמן השקעות בע״מ (Israeli company no. 513969626), established in Israel, with its registered office at הרצל 10, תל אביב - יפו, מיקוד 6688318, ישראל, אצל מלון תאודור, operates FollowUp Memory and is responsible for the personal data described in this policy. Privacy questions and rights requests may be sent to privacy@followupmemory.com.

2. Information we process

We process account and profile information; the Gmail messages, headers, participants, and labels you choose to connect; Google Calendar events and attendees; commitments, summaries, drafts, and other results generated from that data; product usage, security, and audit records; a keyed one-way eligibility token for the one-time trial; and customer, transaction, and subscription identifiers received from PayPal or retained for legacy PayMe, Paddle and Stripe billing. גבמן השקעות בע״מ is the seller and merchant for paid subscriptions. Payment-card details are entered into and retained by PayPal and are not received or stored by FollowUp Memory. FollowUp Memory does not download email attachments.

If you connect a Microsoft 365 or Outlook.com mailbox instead of Gmail, we process the corresponding Outlook messages, headers, participants, and primary-calendar events and attendees through Microsoft Graph, using read-only delegated permissions (Mail.Read, Calendars.Read, User.Read, and offline access to keep syncing). FollowUp Memory cannot send, change, or delete Outlook email or events.

3. Why we process it

We use this information to authenticate you, import and organize authorized business communication, identify commitments and deadlines, prepare evidence-linked summaries and drafts, synchronize changes, provide support, prevent abuse and repeated use of a one-time trial, secure the service, administer subscriptions, comply with law, and improve reliability. We do not sell connected communication or use it for advertising.

FollowUp Memory is offered to business and professional customers only. This commercial scope does not reduce the privacy rights of employees, contacts, correspondents, attendees, or any other individuals whose personal data appears in an authorized connected account.

4. Google API data and Limited Use

Our handling of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide or improve user-facing FollowUp Memory features. It is not used for advertising, credit decisions, or training generalized AI models. Human access is limited to cases where you consent, support or security requires it, or law requires it.

Data received from Microsoft Graph is held to the same limits: it is used only to provide or improve user-facing FollowUp Memory features, is not sold, and is not used for advertising, credit decisions, or training generalized AI models.

5. AI processing and service providers

The full sanitized text body of each imported non-empty Gmail message, together with message metadata such as sender, recipients, subject, direction, and timestamp, may be sent to OpenAI for commitment extraction; this is not limited to excerpts selected as relevant in advance. Later grounded answers and draft generation send the specific stored records needed for your request. OpenAI Responses are called with provider-side response storage disabled. Supabase provides authentication and database hosting, Vercel hosts the application, Google supplies connected APIs, and optional infrastructure providers may support abuse prevention and monitoring.

PayPal provides hosted checkout and payment processing to גבמן השקעות בע״מ, the seller and merchant. PayPal is not FollowUp Memory’s Merchant of Record. PayPal receives the payment and card information needed to process the subscription and may retain it under PayPal’s own terms and legal obligations; FollowUp Memory receives only the customer, transaction, subscription, status, and reconciliation information needed to administer access and support. PayMe, Paddle and Stripe are retained only to reconcile and wind down legacy billing records and provider callbacks and are not offered for new public checkout. Each provider receives information needed for its function under its own terms and data-protection commitments.

The same AI processing applies to messages imported from a connected Outlook mailbox, and Microsoft supplies the Microsoft Graph API for those mailboxes.

6. Retention and deletion

Connected communication and derived workspace data remain until you delete imported email or delete your account. Disconnecting Google stops future synchronization and removes our OAuth credentials, but keeps already imported workspace data until you delete it separately.

Account deletion is a staged process. We first record the request and make provider billing safe before revoking Google access and deleting the account identity and user-owned application data. For PayPal, this includes checking the subscription through PayPal’s server API and requesting cancellation. If provider work fails, deletion remains in progress and the billing-reconciliation process retries it every ten minutes. Legacy PayMe, Paddle or Stripe records continue through their provider-specific wind-down controls.

After a completed deletion, a minimal billing tombstone containing the provider, provider customer identifier, provider subscription identifier when available, cancellation status, and operational timestamps—but no application user identifier or message content—is retained for 180 days. The subscription identifier allows a late PayPal notification to be matched to this record. This prevents late or replayed billing events from recreating access; expired canceled tombstones are then removed by scheduled cleanup. Operational, security, other billing, and legally required records may have different retention periods. Provider billing, tax, fraud-prevention, and backup records follow the relevant provider’s terms and applicable law.

To enforce the one-time trial, after account deletion we retain in a private table only a one-way HMAC token derived from the verified email address and the trial start and end timestamps. The record contains no email address, application user identifier, or content and is unavailable to clients or ordinary application code. It is retained while the one-time trial program operates and reviewed at least annually, unless applicable law requires earlier deletion. Its sole purpose is to prevent deleting and recreating an account from resetting the trial.

Disconnecting Outlook stops future synchronization and deletes our stored Microsoft tokens. Microsoft does not offer an API for an app to withdraw its own permission for a user, so you remove the permission itself from your Microsoft account’s app permissions. Account deletion also deletes any stored Microsoft tokens.

7. Your choices and rights

You can disconnect Google, revoke access in your Google Account, delete imported email, and request deletion of your FollowUp Memory account from Settings. Account deletion may remain in progress while provider cancellation or a processing payment completes; failed or stuck work is retried as described above. Depending on where you live, you may also request access, correction, portability, restriction, objection, or deletion by contacting privacy@followupmemory.com. We may verify your identity before completing a request.

You can likewise disconnect Outlook in Settings and remove FollowUp Memory from your Microsoft account’s app permissions.

8. Security and international processing

We use tenant isolation, row-level authorization, authenticated encryption for OAuth credentials, provider-specific callback controls, access controls, audit records, and encrypted transport. PayPal webhooks must pass PayPal’s signature verification; subscription status is then checked authoritatively through PayPal’s server API rather than trusted from the webhook alone. No system is perfectly secure. Our providers may process information in countries other than yours, subject to the contractual and legal safeguards applicable to those transfers.

9. Children

FollowUp Memory is a business service and is not directed to children. Do not use the service if you are not legally able to enter into the Terms of Service in your jurisdiction.

10. Changes and contact

We may update this policy as the product, providers, or law changes. Material changes will be identified on this page and, when appropriate, communicated through the service. Contact: privacy@followupmemory.com.