Privacy Policy
Effective Date: October 2, 2026
1. Overview
This policy describes how Forrel Mail collects, stores, and processes information when you use the service.
2. Information We Collect
- Account & Workspace Information: Name, business email, organization name, password hash, and billing details.
- Mailbox Credentials: OAuth 2.0 access and refresh tokens used to authenticate with Google APIs. All refresh tokens are encrypted at rest using AES-256-GCM.
- Prospect & Outreach Data: Professional business contact information (name, work email, title, company, public LinkedIn URL) imported by you or enrolled in campaigns.
- Message Content: Email subject lines, headers, body text, and thread timestamps necessary to execute outbound dispatches, detect prospect replies, and classify buying intent.
3. Google API Services User Data Policy Compliance (Limited Use Disclosure)
Forrel Mail uses Google user data only to provide or improve the features you request and to protect service security, consistent with the Google API Services User Data Policy Limited Use requirements. The AI provider disclosure below describes processing for those features:
- The current Google OAuth scopes are:
gmail.send,gmail.readonly,gmail.settings.basic,userinfo.email, anduserinfo.profilefor mailbox connection and account profile information. - For AI-assisted features you request, relevant business and prospect information and email or conversation text may be sent through Vercel AI Gateway to its configured model providers for strategy generation, message writing, reply analysis, or qualification. These providers are listed on our Service Providers List. We do not sell Google user data or use it for advertising.
- Humans cannot read your email messages unless: (i) you give explicit consent to resolve a specific technical support issue; (ii) necessary for security purposes (such as investigating abuse); or (iii) required by applicable law.
4. Data Retention and Deletion
The default retention setting is 90 days and workspace administrators can configure it from 7 to 3,650 days. When the retention job runs, it scrubs aged conversation message bodies and related text and deletes selected expired drafts; some message metadata and other workspace records may remain. This process does not immediately erase all workspace data. Mailbox disconnection and workspace deletion have separate effects:
- A disconnected mailbox is disabled locally and its credentials are removed from the active credential store. A background task attempts to stop the Gmail watch and revoke the Google token; provider revocation is best effort. Existing email and conversation history is retained subject to workspace retention and deletion.
- Pending dispatches are cancelled and the mailbox is removed from active synchronization. Some in-flight sends or provider cleanup operations may finish asynchronously.
- A workspace deletion request is scheduled with a grace period. The period may be set from 1 to 30 days; the workspace DELETE action uses 14 days. Once due, the workspace and its related database records are deleted. Minimal suppression hashes are retained to honor opt-outs.
5. Service Providers
The service uses third-party providers for hosting, database management, and AI processing. For the current list of providers and their roles, see our Service Providers List.
6. Your Rights (GDPR & CCPA)
Depending on your location, you may have rights to access, correct, export, or delete your personal data. During the supervised alpha, ask your workspace administrator to submit a privacy request on your behalf. A dedicated privacy contact has not yet been configured.
7. Contact Us
If you have questions about this Privacy Policy or our data practices during the supervised alpha, ask your workspace administrator to raise them on your behalf. A dedicated privacy contact has not yet been configured.