Serif Privacy policy

Privacy policy

Effective 30 August 2026 · Serif is operated by Jesse J. Anderson · support@serif.email

Serif is an email client. With your permission it connects to your Gmail mailbox, shows you your mail, and writes your actions back to Gmail. This policy says what Serif accesses, what it stores, what it does with it, and how it leaves, for both the app and this website. Serif is in private development; this policy is published ahead of launch so that it governs the first mailbox ever connected.

The short version: Serif keeps a copy of your mail only while your mailbox is connected, uses it only to show it to you, never deletes anything from Gmail, and never shows it to advertisers, data brokers, AI training pipelines, or people.

What Serif accesses

When you connect a Gmail mailbox, you grant Serif access through Google’s consent screen, limited to these scopes:

Serif asks for nothing broader, and it asks separately for each mailbox you choose to connect.

What Serif stores

What Serif does with it—and never does

Your mail is used for exactly one thing: showing it to you, inside Serif’s own features. Concretely, and as policy:

Serif’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Who else touches the data

Serif runs on service providers who process data on its behalf: Vercel (application hosting), Supabase (database hosting, encrypted at rest), and Plausible (cookieless website analytics, aggregate visit counts only — it never sees your mail). They are not licensed to use your data for anything of their own. Beyond that, Serif discloses data only if the law compels it. There are no other recipients: no advertisers, no data brokers.

How long Serif keeps it

For as long as the mailbox is connected, and no longer.

Security

Data moves over TLS and rests on encrypted disks. Mailbox credentials are additionally encrypted at the application layer, with the key held outside the database, so neither a leaked backup nor a leaked connection string exposes them. If a breach ever affects your data, you will be told what happened and what it touched.

Cookies and analytics

The Serif app sets one cookie: a session cookie that keeps you signed in. This website sets no cookies. Its visit counts come from Plausible, a cookieless analytics service that keeps no personal data and no identifiers, only aggregate counts. Fonts are served from this domain rather than a third party.

Your choices

Children

Serif is not directed to children under 13 (or the age of consent where you live), and does not knowingly collect their data.

Changes

Updates to this policy are posted here with a new effective date. If a change materially affects how your mail is handled, you will be told in the app before it takes effect.

Contact

Serif · operated by Jesse J. Anderson · support@serif.email