Privacy Policy
Last updated: June 9, 2026
SyncPilot AI ("SyncPilot," "we," "us," or "our") operates an AI-powered service that reads your Gmail inbox, summarizes new messages, and delivers those summaries to Signal. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
1. Information We Collect
When you use SyncPilot, we may collect the following:
- Account information: Your email address and Google account identifier provided when you sign in with Google.
- Gmail integration data: A reference to the Gmail connection you authorize through Composio and the timestamp of your last email sync. Composio manages the underlying Google OAuth tokens on your behalf, so we do not store your raw Gmail credentials. We request read-only access to Gmail (
gmail.readonly). - Signal configuration: Device name, sender phone number, and recipient phone number you provide to deliver summaries.
- Run metadata: Counts of emails found and summaries sent, run status, and timestamps. We do not store full email bodies in our database.
- Manual agent requests: Task descriptions and context you submit in the Agent Console are processed in real time and are not persisted in our database.
2. Email Content Processing
To provide summaries, SyncPilot temporarily accesses email subject lines, sender addresses, and message bodies from your Gmail account. This content is:
- Sent to Groq's AI models to generate summaries
- Delivered to your configured Signal recipient number
- Not stored as full message content in our PostgreSQL database
Email content exists only for the duration needed to complete each processing run.
3. How We Use Your Information
We use collected information to:
- Authenticate you and maintain your account
- Connect and manage your Gmail and Signal integrations
- Fetch new emails and generate AI summaries on a schedule
- Send summaries to your Signal number
- Display connection status and run history in your dashboard
- Respond to manual agent requests you initiate
- Improve reliability, security, and service operation
4. Third-Party Services
SyncPilot relies on third-party providers to operate. Data may be shared with:
- Google Sign-In — authentication and session management
- Google (Gmail API) — read-only access to your inbox via OAuth
- Composio — brokers the Gmail connection and securely manages the Google OAuth tokens used to fetch your messages
- Groq — AI summarization of email content and agent prompts
- Signal (via signal-cli-rest-api) — delivery of generated summaries
- PostgreSQL hosting provider — encrypted storage of account and integration data
Each provider processes data under its own privacy policy. We encourage you to review their terms before connecting integrations.
5. Data Retention
- Account and integration records are kept while your account is active or as needed to provide the service.
- Your Gmail connection is revoked through Composio when you disconnect Gmail in Settings.
- Signal configuration is deleted when you disconnect Signal in Settings.
- Agent run metadata (counts and status) is retained to show history in your dashboard.
- Email content processed for summarization is not retained after each run completes.
6. Security
We take reasonable measures to protect your data, including:
- Delegating Gmail token storage and refresh to Composio, so your raw Google credentials are never stored on our servers
- Requiring Google sign-in for access to protected routes and APIs
- Protecting scheduled processing endpoints with a secret bearer token
- Verifying the connection status returned by the OAuth flow before saving an integration
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
7. Your Choices and Rights
You can:
- Disconnect Gmail or Signal at any time from Settings
- Manage your account through your Google account controls
- Stop using the service by disconnecting integrations and signing out
Depending on your location, you may have additional rights to access, correct, or delete personal data. Contact us using the information below to make a request.
8. Cookies
SyncPilot uses session cookies provided by Auth.js to keep you signed in. We do not use third-party advertising or analytics tracking cookies.
9. Children's Privacy
SyncPilot is not intended for users under 13 years of age. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect the latest revision. Continued use of SyncPilot after changes constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions or requests, contact us through the SyncPilot GitHub repository.