Sodaroad
Managing and deleting your data
This guide explains what Sodaroad stores, how to get it out, and how to delete it. It is the how-to companion to the Privacy Policy (§5 covers retention in full).
What Sodaroad stores
Sodaroad keeps a copy of your mail so your inbox opens instantly: all of your mail except spam, trash, and drafts, starting from your 10,000 most recent messages, plus the rest of any conversation you open. Message bodies and previews are encrypted with AES-256-GCM before they reach our database; subjects, senders, recipients, dates, and label snapshots are stored as plain metadata. Sodaroad also stores your Google sign-in identity, OAuth tokens (encrypted), sync state, and an append-only audit log of account events. Sodaroad keeps your read/unread and archived state in Sodaroad rather than writing it back to Gmail. (An optional automatic-triage feature — off today — can archive bulk promotions in Gmail by removing Gmail's Inbox label; it will be disclosed here and at connect before it is ever turned on.)
Your memories (decisions & commitments)
Sodaroad has an optional memory feature: it finds the decisions and commitments in your conversations — the launch date you settled, the draft you promised to send — and keeps them as a private record for you. To do this, Sodaroad sends the text of a conversation to an AI model provider we've verified does not train its models on your content (Z.ai, Anthropic, or OpenAI — the candidate set named in the disclosure you consented to; your consent record stores the date and disclosure version of your grant, and each memory records the model that produced it). The feature is off until you explicitly turn it on at the memory consent page, which shows exactly what is sent, first.
What Sodaroad keeps from this feature is encrypted like your mail (AES-256-GCM) and is included in your data export, with the conversation each memory came from. You can see your extracted memories — each with its source conversation linked — on the memory page. You control them in two separate ways — the distinction matters:
Withdrawing consent stops processing; it does not delete anything. Turning the feature off at the memory consent page stops Sodaroad from processing new conversations immediately. The memories you already have stay — still in your export, still deletable — until you delete them. (This mirrors revoking Gmail access, which stops access without deleting stored mail.)
Deleting memories is the data path. On the memory page, each memory can be corrected if the extraction got it wrong, dismissed so it stays hidden, deleted on its own, or re-checked by re-reading its conversation. The memory consent page has a distinct delete all my memories action — separate from turning the feature off — that permanently deletes every extracted memory. Deleting your account (below) removes them too, together with everything else.
Export your data
From the dashboard, choose Export your data. You get a JSON file with your account, linked email addresses, your stored mail (with bodies decrypted into the file), mailbox state, classification decisions, and extracted memories (with their claim text decrypted into the file). OAuth tokens are never included. If a stored message can't be decrypted (a damaged record), it appears with a placeholder and is listed in the file's decryptWarnings section — one bad record never blocks your export.
Delete your data
From the dashboard, choose Delete account. Deletion runs immediately — there is no delay and no soft-delete period. Sodaroad first asks Google to revoke your OAuth tokens (best-effort — if you want certainty, check your Google Account permissions afterward), then permanently removes, in one operation:
Your account and sign-in identity; the entire stored copy of your mail — every thread and every message; your extracted memories; your OAuth tokens; your linked email addresses; your sync and mailbox-watch state; your classification decisions; and your rate-limit records.
Two things deliberately survive: the append-only audit entry recording that your deletion was performed (it contains your user id, the event, and counts — no message content), and any IP-address rate-limit rows, which a periodic stale-record cleanup removes. That is the complete list.
Revoking access is not deleting data
Revoking Sodaroad's access from your Google Account permissions page stops Sodaroad from reading your Gmail immediately. It does not delete anything Sodaroad has already stored — your stored mail remains and keeps rendering in Sodaroad until you delete it using the steps above. If your goal is "Sodaroad has nothing of mine", revoke access and delete your data from the dashboard.
Deleting mail in Gmail
When you delete a message in Gmail, Sodaroad removes its stored copy the next time it syncs. Until that sync runs, Sodaroad may still show the message from the stored copy.
Last updated: August 2026