Privacy Policy

Last updated: July 18, 2026

LowSignalMail ("we", "us", or "our") operates the LowSignalMail service, which lets you read, reply to, and compose Gmail messages entirely via SMS text message. This Privacy Policy explains what data we collect, how we use it, and your rights with respect to that data.

Google Workspace Data: LowSignalMail's use of information received from Google APIs, including Gmail, adheres to the Google API Services User Data Policy, including the Limited Use requirements.

1. Information We Collect

Phone number. We collect your mobile phone number when you create an account. It is used to identify your account, send you a one-time verification code during signup, deliver email notifications and content to you via SMS, and allow you to manage your account settings.

Gmail OAuth tokens. When you connect your Gmail account, Google grants us an OAuth refresh token and access token. These tokens are stored encrypted in our database and are used solely to access your Gmail inbox on your behalf — to fetch messages, send replies, mark messages as read, and receive real-time inbox notifications via Google Pub/Sub.

Email metadata used transiently. When a new email arrives or you request to read your inbox, we fetch the sender's address and subject line from the Gmail API to compose an SMS notification for you. This metadata is used in memory to build the SMS message and is never written to our database.

Email body content used transiently. When you request to read an email, we fetch the message body from the Gmail API and deliver a truncated plain-text version to you via SMS. The message body is used in memory to build the SMS and is never stored in our database.

SMS message logs. We log a record of each SMS sent or received (direction, approximate timestamp, conversation state, message type, and segment count for billing) but we do not store the text of any SMS that contains email content. The body field is set to null for all messages that would contain your email data.

Account preferences. If you configure notification preferences (sender whitelist/blacklist, schedule windows), those preferences are stored in your account record.

2. How We Use Your Information

We do not use your Gmail data or phone number for advertising, profiling, or any purpose beyond operating the service as described above.

3. How We Access Your Gmail Data

LowSignalMail requests the https://www.googleapis.com/auth/gmail.modify OAuth scope. This scope allows us to:

All Gmail data is accessed for the sole purpose of operating the SMS email interface. We do not share, sell, or transfer your Gmail data to any third party except as required to operate the service (e.g., the Twilio SMS delivery service for outbound SMS) or as required by law.

4. Data Sharing

Twilio. Outbound SMS messages are sent via Twilio's messaging API. SMS content that does not contain email data (e.g., prompts, navigation instructions) may be visible to Twilio as part of transmission. We never send raw email body content in SMS messages that would be unnecessarily long; content is truncated and delivered as a user-readable summary.

Google Cloud Platform. The application is hosted on Google App Engine and uses Google Cloud Secret Manager and Google Cloud Pub/Sub. These services process data in accordance with Google's terms.

MongoDB Atlas. Encrypted user account data and SMS logs are stored in MongoDB Atlas.

We do not sell your data. We do not share your data with advertising networks, data brokers, or information resellers.

5. Data Retention

Your account data (phone number, Gmail OAuth tokens, notification preferences) is retained for as long as you have an active account. SMS message logs are retained for operational and billing purposes.

One-time verification codes (OTPs) expire after 10 minutes and are automatically deleted from our database after expiration.

6. Your Rights and Choices

Revoke Gmail access. You can revoke LowSignalMail's access to your Gmail at any time in your Google Account permissions. Revoking access will stop the service from reading or sending email on your behalf.

Notification preferences. You can manage which email senders trigger SMS notifications and set quiet hours via the self-service settings portal at /settings.

Account deletion. To request deletion of your account and all associated data, contact us at the email address below. We will delete your account, revoke Gmail access, and remove your data from our systems within 30 days.

7. Security

We store OAuth tokens encrypted at rest. All data in transit is encrypted via HTTPS. Outbound SMS is delivered over Twilio's secure API. We take reasonable measures to protect your data against unauthorized access, loss, or disclosure.

If you become aware of a security issue involving your data, please contact us promptly at the address below.

8. Children's Privacy

LowSignalMail is not directed at children under the age of 13. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If you have an account, we will notify you by SMS of material changes before they take effect.

10. Contact

Questions about this Privacy Policy or requests to delete your data can be directed to:

LowSignalMail
Email: privacy@lowsignalmail.com