Privacy
Magpie reads your email to help you keep track of life. It cannot send, forward, compose, or delete mail from your account.
Sign-in and Gmail access are separate choices. First, Google confirms your invited account. When you connect Gmail, Google asks for read-only access and confirms that the mailbox belongs to the same account.
Your data
What we hold
While your account exists, Magpie holds the following.
- Your account and session information, and a sealed Gmail credential. The web interface cannot open that credential.
- Mailbox details, meaning senders, recipients, subjects, dates, labels, and attachment metadata.
- Information derived from your mail, including events, interests, profile details, briefs, and the evidence linking them to messages.
- Your answers about your life and your chat history, saved separately from that evidence.
- Invitations, sign-in attempts, and operational records, held to manage access, protect accounts, and account for service costs.
This browser keeps unsaved onboarding answers so you can return to them. Saved answers are removed from the local draft after the server accepts them. Starting a new sign-in or ending your session clears private drafts on this device. An abandoned draft can remain until you return or clear site data.
Your mail
How mail is read
- The hosted service saves no message bodies and keeps no mailbox body cache.
- When a body is needed for analysis, it is fetched from Gmail, processed in memory, and released.
- Chat can open one message you point it at. It reads that message once, and keeps nothing from it.
- Before model processing, Magpie removes recognized personal identifiers and screens sensitive content.
These safeguards reduce what is shared. They are not a promise that every identifying detail can be recognized.
Your Gmail access is used to read the account you connected. Removing access in Google stops future reads, while previously saved analysis remains until deletion.
Who else sees it
Services involved
- Google provides sign-in and Gmail access.
- The hosted app uses Neon for account and product records, and owner-operated server infrastructure for mailbox analysis. Operators have access for support, debugging, and testing.
- OpenRouter and the model providers it routes to process screened mail text, derived information, and questions you send in chat. Hosted model requests require zero-data-retention and data-collection-denial controls.
- What you tell Magpie in chat stays in the same Neon database as the rest of your account. Your answered turns, the facts you chose to keep, and the sources you saved to Knowledge are indexed there so a later question can find them. The index holds a numeric representation and a checksum, never a second copy of the words. OpenRouter computes that representation on the same zero-data-retention terms as every other model request.
- When web research is enabled, Tavily receives bounded search queries, and no Gmail credentials or message bodies. Retrieved results are treated as unverified web information and kept separate from your profile and memory.
- When audio briefs are enabled, ElevenLabs receives screened brief text to create audio.
- To show the weather, Magpie sends the name of the city you are in, and nothing else, to Open-Meteo, a free forecast service.
- Resend delivers invitations and operational alerts for the service.
These descriptions explain each service's role. An optional service is not activated merely by connecting Gmail.
Your choices
How to leave
- You can remove Magpie's access in your Google Account. That stops future reads and leaves saved analysis in place.
- Signing out ends your session on this device. It does not remove your account or revoke Google's access grant.
- To request deletion, contact the person who issued your invite.
Deletion is carried out by the owner and is not an instant self-service action. A request does not mean deletion has finished. The owner must also check any retained provider records and backups.