What we can and cannot do with your mail
Every sentence on this page is also shown inside the product, at the moment it applies, and each one is backed by a test that must pass before it can appear here.
What each processor receives, why, how deletion works, and which contract evidence is still missing.
When you set up forwarding
- We hold no key to your mailbox. Forwarding is set up inside your own email provider, and you can switch it off there at any time without asking us.
- We can only read what is forwarded to us. We cannot reach into your mailbox for anything else, and we cannot send mail as you.
Your intake address
- We hold no key to your mailbox. Forwarding is set up inside your own email provider, and you can switch it off there at any time without asking us.
- Mail sent to your intake address reaches only your account. No other Sync13 user can read it.
- Anyone not on your accepted-senders list is refused at the door, so even a leaked address cannot put mail into your brief.
- Administering Sync13 does not include reading your mail. No admin screen shows another person’s messages, commitments or brief — the controls cover accounts, access and spend, and nothing else.
When you connect Google
- We hold no key to your mailbox. Forwarding is set up inside your own email provider, and you can switch it off there at any time without asking us.
- You can revoke our access to your Google account at any time from your own Google settings, without contacting us.
- We read message content only when you have turned this on for Pulse and granted the content permission. Either one alone reads nothing.
Anything the AI tells you
- To find commitments, message text goes to the owner’s Included AI provider, your personal provider key under that provider account’s terms, or Cloudflare Workers AI when Internal AI only is on. While processed, it is on that provider’s systems, not only ours.
- Everything we tell you carries the exact line it came from, so you can check our work instead of trusting it.
- What we keep permanently is the derived record — the commitment, the person, the date and the quoted line — not a copy of your mailbox.
Mail we set aside
- Anyone not on your accepted-senders list is refused at the door, so even a leaked address cannot put mail into your brief.
- Mail we set aside is never deleted on our judgement. It is held where you can see it, with the reason, and one click overrules us.
How long we keep things
- A copy of the message body is kept for 30 days for mail we process, 7 days for mail we set aside, and never for mail we refuse. You can shorten any of these to zero, and they can never exceed 90 days.
- What we keep permanently is the derived record — the commitment, the person, the date and the quoted line — not a copy of your mailbox.
The AI processor
- We read message content only when you have turned this on for Pulse and granted the content permission. Either one alone reads nothing.
- To find commitments, message text goes to the owner’s Included AI provider, your personal provider key under that provider account’s terms, or Cloudflare Workers AI when Internal AI only is on. While processed, it is on that provider’s systems, not only ours.
- No person at Sync13 reads your mail, except with your explicit permission, to investigate a security problem, or where the law requires it.
Your access log
- Every time anything reads your mail, a line is written to your access log. We cannot read it without leaving that record.
- No person at Sync13 reads your mail, except with your explicit permission, to investigate a security problem, or where the law requires it.
- Administering Sync13 does not include reading your mail. No admin screen shows another person’s messages, commitments or brief — the controls cover accounts, access and spend, and nothing else.
When you create a password
- Before we save a new password, we send only the first five characters of its one-way fingerprint to Have I Been Pwned. The password and its complete fingerprint never leave Sync13.
Everything starts in one of two places — the mail you forward to your intake address, or a mailbox you connected. From there it reaches Sync13, and the only places it can travel onward are these. This list is generated from the code itself and checked on every build, so it cannot fall behind what the software actually does.
The two doors in: your forwarding address, and any account you connected. Nothing else can put mail into your account.
AI processors — they read your content to produce your output
-
api.anthropic.com
The text of the messages the feature needs to read — including message bodies when a brief is being produced. 1 place in the code -
api.openai.com
The same content as the Anthropic path, when this provider is the one selected for the account. 1 place in the code -
generativelanguage.googleapis.com
The same content as the Anthropic path, when this provider is the one selected for the account. 1 place in the code -
api.deepgram.com
The text you asked to be read aloud, when this is the selected voice provider. 1 place in the code -
api.speechify.ai
The text you asked to be read aloud, when this is the selected voice provider. 1 place in the code -
api.cloudflare.com
The document you asked to be turned into a PDF, sent to the renderer that produces it. 1 place in the code -
Cloudflare Workers AI
The audio of a recording you sent in, to be turned into text. The audio itself is discarded afterwards. 6 places in the code
Your own accounts — content going back where it came from
-
gmail.googleapis.com
A message or draft you asked us to send, into your own mailbox. 6 places in the code -
www.googleapis.com
The event you asked us to create, into your own calendar. 4 places in the code -
oauth2.googleapis.com
Nothing of yours — the grant token exchange only. 3 places in the code -
openidconnect.googleapis.com
Nothing of yours — reads your name and email to create the account. 2 places in the code -
accounts.google.com
Nothing — the consent screen you are sent to. 2 places in the code -
people.googleapis.com
A request for your own contacts. Names come back; none of yours goes out. 1 place in the code
Vendors you connected — they already hold this material
-
mcp.plaud.ai
A request for your own recordings, to the vendor that already holds them. 1 place in the code -
api.linear.app
A query for the issues in the workspace you connected. 1 place in the code
Credential safety — a privacy-preserving breach check
-
api.pwnedpasswords.com
Only the first five characters of the prospective password’s one-way SHA-1 fingerprint; never the password or its complete fingerprint. 1 place in the code
Our own infrastructure — no content of yours in the payload
-
api.cloudflare.com
Nothing of yours — our own billing and usage totals. 2 places in the code
Some rows say nothing of yours leaves — a token exchange or a request for your own data. They are listed anyway, because a list you have to trust is not the same as a list you can check.
Processor register
Unknown evidence is shown as unknown. A missing contract, account setting or region cannot be filled in by reading source code and is never replaced with a reassuring guess.
- Destinations
- Email Routing, Workers, D1, R2, api.cloudflare.com, binding:AI
- What it receives
- Account data, forwarded mail and recordings, derived records, encrypted credentials, authored documents and encrypted database backups, depending on the feature used.
- Why
- Receive mail, run Sync13, store the user’s records, make encrypted backups, transcribe audio, embed derived text and render requested documents.
- Retention and deletion
- Message bodies follow the visible 0–90 day application window; refused mail bodies are never stored. Derived records persist until the user deletes them. Encrypted backups can outlive the live row; a verified bucket lifecycle is still open and is not represented as complete.
- Terms evidence
- The code-owned storage, deletion and encryption paths are tested. Current Cloudflare contract, DPA and account retention evidence must be attached before a customer island is approved.
- Subprocessors and region
- Cloudflare’s current subprocessor list and the chosen account data region are not evidenced in this repository yet.
- Destinations
- api.anthropic.com
- What it receives
- The text, document or image content needed to produce the requested output, including message text when Relay extracts a commitment.
- Why
- Platform-funded processing while the owner selects Anthropic for Included AI, or user-funded processing when a person deliberately selects an Anthropic personal key.
- Retention and deletion
- The Schram Media account console was checked on 29 July 2026: retention was on for 30 days and Zero Data Retention was not enabled. Provider-side deletion follows that provider account, not Sync13’s message-body delete button.
- Terms evidence
- Dated account-console evidence exists in the security ledger. ZDR would require provider approval; Sync13 does not claim it is enabled.
- Subprocessors and region
- The current Anthropic DPA, subprocessor list and account data-region evidence are not attached to this repository yet.
- Destinations
- api.openai.com
- What it receives
- The text, document or image chunks needed for the requested output when OpenAI is the owner-activated Included AI provider, or when a user deliberately selects an OpenAI personal key.
- Why
- Platform-funded or user-funded model processing through Sync13’s one server-side AI funnel.
- Retention and deletion
- Sync13 sends Responses requests with store=false. Provider-side abuse monitoring, retention and deletion still follow the OpenAI account and contract behind the active key; repository evidence for that account is not attached, so Sync13 states no retention number here.
- Terms evidence
- The adapter behavior is code-tested. Current OpenAI contract, DPA, account data controls and any approved retention exception must be attached before customer-island approval.
- Subprocessors and region
- The current OpenAI subprocessor list and the chosen account processing region are not evidenced in this repository yet.
- Destinations
- generativelanguage.googleapis.com
- What it receives
- The same requested feature content as the Included AI path, only when the account owner selects Gemini and supplies a personal provider key.
- Why
- User-selected model processing through Sync13’s single server-side AI seam.
- Retention and deletion
- Provider-side retention and deletion follow the Google account behind the personal key. Sync13 has no account-level proof for that external account and therefore states no retention number here.
- Terms evidence
- Personal-key processing is not covered by the Schram Media Anthropic evidence. The account owner must verify the applicable provider terms.
- Subprocessors and region
- Controlled by the external provider account; not evidenced by Sync13.
- Destinations
- api.deepgram.com, api.speechify.ai
- What it receives
- Only the text the user explicitly asks Sync13 to read aloud.
- Why
- Generate a selected spoken-voice version of that text.
- Retention and deletion
- No provider-side retention period is evidenced in this repository, so Sync13 states no number and does not equate deleting the local document with deleting a provider-side processing record.
- Terms evidence
- Provider contract and account evidence remain required before these options are approved for customer content.
- Subprocessors and region
- The current DPA, subprocessor lists and processing regions are not evidenced in this repository yet.