Privacy Policy
Last updated August 15, 2026
Launch draft. The production preflight will remain blocked until all legal identity, contact, governing-law, and venue fields are complete and qualified counsel approves this policy.
1. Who operates FollowUp Memory
FollowUp Memory (launch draft), established in country to be confirmed, operates FollowUp Memory and is responsible for the personal data described in this policy. Privacy questions and rights requests may be sent to privacy contact to be confirmed.
2. Information we process
We process account and profile information; the Gmail messages, headers, participants, and labels you choose to connect; Google Calendar events and attendees; commitments, summaries, drafts, and other results generated from that data; product usage, security, and audit records; and customer, transaction, and subscription identifiers received from Paddle. Paddle receives payment and billing details as Merchant of Record. FollowUp Memory does not download email attachments or receive or store full payment-card details.
3. Why we process it
We use this information to authenticate you, import and organize authorized business communication, identify commitments and deadlines, prepare evidence-linked summaries and drafts, synchronize changes, provide support, prevent abuse, secure the service, administer subscriptions, comply with law, and improve reliability. We do not sell connected communication or use it for advertising.
4. Google API data and Limited Use
Our handling of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide or improve user-facing FollowUp Memory features. It is not used for advertising, credit decisions, or training generalized AI models. Human access is limited to cases where you consent, support or security requires it, or law requires it.
5. AI processing and service providers
The full sanitized text body of each imported non-empty Gmail message, together with message metadata such as sender, recipients, subject, direction, and timestamp, may be sent to OpenAI for commitment extraction; this is not limited to excerpts selected as relevant in advance. Later grounded answers and draft generation send the specific stored records needed for your request. OpenAI Responses are called with provider-side response storage disabled. Supabase provides authentication and database hosting, Vercel hosts the application, Google supplies connected APIs, and optional infrastructure providers may support abuse prevention and monitoring.
Paddle acts as Merchant of Record for paid sales and handles checkout, subscription billing, payment processing, applicable transaction taxes, invoices, refunds, and chargebacks. Stripe is retained only to reconcile and wind down legacy Stripe billing records and signed webhooks; it is not offered for new public-launch checkout. Each provider receives information needed for its function under its own terms and data-protection commitments.
6. Retention and deletion
Connected communication and derived workspace data remain until you delete imported email or delete your account. Disconnecting Google stops future synchronization and removes our OAuth credentials, but keeps already imported workspace data until you delete it separately.
Account deletion is a staged process. We first record the request and make provider billing safe before revoking Google access and deleting the account identity and user-owned application data. For Paddle, this includes canceling ready transactions and non-canceled subscriptions and archiving the customer so an abandoned draft checkout cannot later be used to charge. If Paddle reports that a payment is still processing, or if provider work fails, deletion remains in progress and the billing-reconciliation process retries it every ten minutes.
After a completed deletion, a minimal billing tombstone containing the provider and provider customer identifier, cancellation status, and operational timestamps—but no application user identifier or message content—is retained for 180 days. This prevents late or replayed billing events from recreating access; expired canceled tombstones are then removed by scheduled cleanup. Operational, security, other billing, and legally required records may have different retention periods. Provider billing, tax, fraud-prevention, and backup records follow the relevant provider’s terms and applicable law.
7. Your choices and rights
You can disconnect Google, revoke access in your Google Account, delete imported email, and request deletion of your FollowUp Memory account from Settings. Account deletion may remain in progress while provider cancellation or a processing payment completes; failed or stuck work is retried as described above. Depending on where you live, you may also request access, correction, portability, restriction, objection, or deletion by contacting privacy contact to be confirmed. We may verify your identity before completing a request.
8. Security and international processing
We use tenant isolation, row-level authorization, authenticated encryption for OAuth credentials, signed webhooks, access controls, audit records, and encrypted transport. No system is perfectly secure. Our providers may process information in countries other than yours, subject to the contractual and legal safeguards applicable to those transfers.
9. Children
FollowUp Memory is a business service and is not directed to children. Do not use the service if you are not legally able to enter into the Terms of Service in your jurisdiction.
10. Changes and contact
We may update this policy as the product, providers, or law changes. Material changes will be identified on this page and, when appropriate, communicated through the service. Contact: privacy contact to be confirmed.