How FollowUpEasy handles your data

Last updated: July 17, 2026

What we structurally skip

Our scan only looks at mutual, two-way email conversations. We structurally filter out:

  • Newsletters and mailing lists
  • Automated notifications (GitHub, Slack, calendar, etc.)
  • Marketing and transactional emails
  • One-way messages with no reply history
  • Attachments (never accessed)

What data we access

  • Message headers and metadata for all sent and received messages (sender, recipient, date, subject line). Used to identify relationships and measure how long they've been quiet.
  • Email message content (for specific contacts only). Relevant portions of conversation threads with contacts that qualify for judgment are processed to generate relationship summaries and draft follow-ups. To learn your writing style, a small sample of your own recent sent messages is also read; those raw emails aren't kept, but a few example sentences from them are stored in your style profile (so drafts sound like you), and excerpts are sent to Anthropic to build it. We do not make copies of your full mailbox.

What data we store

  • Contact records for the relationships in your map (name, email, last contact date, and the judged relationship summaries and prose shown on your desk)
  • Conversation excerpts from threads with contacts our scan selects for judgment, used to generate summaries and drafts — up to roughly 1,500 characters per selected message, which for a short message can be its full text. Context saved for contacts the judge decides are not substantive relationships is currently retained too, until you delete your account. We do not make copies of your full mailbox.
  • Generated drafts created for your review
  • Style profile derived from a sample of your own recent sent messages — a description of how you write, plus a few characteristic example sentences quoted from that mail, used to make drafts sound like you
  • Suppressed contacts you've dismissed, so we don't resurface them
  • Account and billing records — your email address, subscription status, and Stripe billing references. Card details live with Stripe; we never see the full number.

What we never store

  • A copy of your mailbox, or message content beyond the per-message excerpt cap above
  • Attachments
  • Mail sent to you by contacts who never qualify for judgment — their messages are never fetched. (The writing-style sample reads only messages you yourself wrote; the raw emails aren't kept, though a few example sentences are — see your style profile above.)

How we protect your data

  • Encryption in transit — All connections to FollowUpEasy use HTTPS/TLS encryption. Data transmitted between your browser, our servers, and third-party APIs (Google, Anthropic) is encrypted in transit.
  • Encryption at rest — Stored data (contact records, conversation excerpts, drafts, style profiles) is held in a managed PostgreSQL database with encryption at rest enabled.
  • OAuth token security — Gmail OAuth tokens are stored securely and used only to access Gmail on your behalf. When you disconnect, we delete our copy immediately and ask Google to revoke the grant. Deleting our copy is entirely up to us and always happens; the revocation is a request to Google, so if Google is unavailable it can fail — you can always revoke access yourself at Google Account Permissions, which is final either way.
  • Access control — No user can access another user's data. Administrative access is limited to the application operator for debugging, support, and security/maintenance purposes.
  • Minimal data retention — We store only the data needed to provide the service: capped conversation excerpts, judged summaries, drafts, and your style profile. Never attachments, never a copy of your mailbox.
  • No data sharing or selling — Your data is never sold, shared with advertisers, or used for purposes other than providing the FollowUpEasy service.
  • No AI model training on your data — Email content processed through the Anthropic Claude API is not used to train AI models. Anthropic's commercial terms prohibit training models on customer content — a contractual bar, not a settings toggle. Content sent to Anthropic is retained by Anthropic for up to 30 days under Anthropic's standard retention, then deleted — subject to legal and abuse-prevention exceptions.

Data retention

Your data is retained while your account is active. When you delete your account, it is removed immediately from the live application; encrypted database backups that may still contain it roll off within a few days. Excerpts already sent to Anthropic for AI processing are deleted from Anthropic's systems within Anthropic's standard retention window (batched judging: up to 29 days; other API traffic: up to 30 days), subject to legal and abuse-prevention exceptions under which Anthropic may retain flagged inputs longer.

We never send anything on your behalf

FollowUpEasy creates drafts in your Gmail account. You review, edit, and send from your own inbox.

Revoking access and deleting data

You can disconnect Gmail and delete all your data at any time from your account settings. This will:

  • Delete our copy of your Gmail credentials immediately, and ask Google to revoke the grant
  • Delete all stored data (scan results, drafts, conversation excerpts, style profile)
  • Sign you out

Drafts you already saved or sent in Gmail are in your Gmail account, not ours. You can also revoke access directly from Google Account Permissions.

Third-party services

FollowUpEasy uses the following services to operate:

  • Google Gmail API — to read email metadata and content, and to create drafts in your Gmail account.
  • Anthropic Claude API — to assess relationships and generate draft emails. Conversation excerpts are sent to Claude for processing, retained by Anthropic for up to 30 days under its standard retention (subject to legal and abuse-prevention exceptions), then deleted. Anthropic does not use API inputs to train models.
  • Render — cloud hosting provider where the application and its database run.
  • Cloudflare — CDN and edge network in front of the site; sees requests in transit to route and protect them.
  • Stripe — payment processing for subscriptions. Your card details go to Stripe directly; we never see the full number.
  • Resend — delivers the emails we send you (scan notifications and your weekly reading). Those emails include lines from your map, so Resend processes them in transit.
  • PostHog — product analytics. Receives your account email address as the analytics identifier plus product events (pages viewed, actions taken). No email content is sent to PostHog.

Contact

Questions about how we handle your data? Email Dave directly: dave@followupeasy.com.