Privacy policy
Effective 30 August 2026 · Serif is operated by Jesse J. Anderson · support@serif.email
Serif is an email client. With your permission it connects to your Gmail mailbox, shows you your mail, and writes your actions back to Gmail. This policy says what Serif accesses, what it stores, what it does with it, and how it leaves, for both the app and this website. Serif is in private development; this policy is published ahead of launch so that it governs the first mailbox ever connected.
The short version: Serif keeps a copy of your mail only while your mailbox is connected, uses it only to show it to you, never deletes anything from Gmail, and never shows it to advertisers, data brokers, AI training pipelines, or people.
What Serif accesses
When you connect a Gmail mailbox, you grant Serif access through Google’s consent screen, limited to these scopes:
- Read and modify your mail (
gmail.modify): to sync your messages into Serif, to write your actions (archive, star, read, send, reply) back to Gmail, and to keep the two in step. This scope cannot permanently delete mail, and Serif never moves anything to Gmail’s trash. - Manage labels (
gmail.labels): Serif records where you have placed things using hiddenSerif/labels in your own mailbox, so your choices survive in Gmail too. - Basic identity (name, email address, Google account ID): to sign you in and to name the mailbox you connected.
Serif asks for nothing broader, and it asks separately for each mailbox you choose to connect.
What Serif stores
- A copy of the messages in your mailbox within the sync window you choose at connection, including their attachments, and the cleaned reading versions Serif renders from them.
- Your senders, rules, placements, folders, and reading state: the things you arrange inside Serif.
- Your name, email address, and the sessions that keep you signed in.
- The OAuth tokens that let Serif reach Gmail. These are encrypted at the application layer (AES-256-GCM) with a key that is never stored in the database, on top of the disk encryption everything else gets.
What Serif does with it—and never does
Your mail is used for exactly one thing: showing it to you, inside Serif’s own features. Concretely, and as policy:
- No advertising, and no selling or renting data to anyone.
- No training AI or machine-learning models on your mail.
- No human at Serif reads your mail. The only exception is support, with your explicit consent, for that incident only.
- Mail content never reaches Serif’s logs; logs carry IDs, counts and error codes, not subjects, bodies or addresses.
Serif’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Who else touches the data
Serif runs on service providers who process data on its behalf: Vercel (application hosting), Supabase (database hosting, encrypted at rest), and Plausible (cookieless website analytics, aggregate visit counts only — it never sees your mail). They are not licensed to use your data for anything of their own. Beyond that, Serif discloses data only if the law compels it. There are no other recipients: no advertisers, no data brokers.
How long Serif keeps it
For as long as the mailbox is connected, and no longer.
- Serif mirrors Gmail. Delete a message in Gmail and it leaves Serif on the next sync. Serif never keeps mail you no longer have, and never deletes mail from Gmail.
- Disconnecting a mailbox destroys everything Serif holds for it (messages, renders, senders and rules) and revokes Serif’s access token at Google in the same act. If changes you made in Serif have not yet reached Gmail, you are told before confirming.
- Closing your account signs you out everywhere and disconnects every mailbox at once; the remaining account records are deleted within 30 days. Billing records are kept as long as the law requires, and nothing else is.
- A lapsed subscription pauses syncing and sending; your already-synced mail stays readable for 30 days, and after 60 days the account is treated as closed.
- Database backups expire on the provider’s own short schedule and are never selectively restored.
Security
Data moves over TLS and rests on encrypted disks. Mailbox credentials are additionally encrypted at the application layer, with the key held outside the database, so neither a leaked backup nor a leaked connection string exposes them. If a breach ever affects your data, you will be told what happened and what it touched.
Cookies and analytics
The Serif app sets one cookie: a session cookie that keeps you signed in. This website sets no cookies. Its visit counts come from Plausible, a cookieless analytics service that keeps no personal data and no identifiers, only aggregate counts. Fonts are served from this domain rather than a third party.
Your choices
- Disconnect a mailbox or close your account at any time, inside Serif.
- Revoke Serif’s access yourself at myaccount.google.com/permissions; Serif treats a revoked token as a disconnect.
- Your mail needs no export, because it never left Gmail: everything Serif shows is already in your mailbox.
- For anything else—a question, a copy of the data Serif holds about you, or a complaint—write to support@serif.email.
Children
Serif is not directed to children under 13 (or the age of consent where you live), and does not knowingly collect their data.
Changes
Updates to this policy are posted here with a new effective date. If a change materially affects how your mail is handled, you will be told in the app before it takes effect.
Contact
Serif · operated by Jesse J. Anderson · support@serif.email