Sodaroad
Privacy Policy
We built Sodaroad to be your inbox — a mail app that reads, renders, and sends your Gmail, and keeps an encrypted copy of your mail so it opens instantly. This policy explains what data we collect, how we use it, who else processes it, how long we keep it, and the choices you have. We've kept it as clear as we can while covering everything that matters.
1. Information We Collect
Account Information. When you sign up, we collect your name and email address through Google OAuth. We do not collect or store payment information.
Email Data. Sodaroad is an inbox backed by your Gmail. When you connect Gmail, Sodaroad imports your mail — all of it except spam, trash, and drafts, starting from your 10,000 most recent messages — and then follows changes as mail arrives, is read, or is deleted. For every message Sodaroad stores: the sender, recipients, subject, date, and Gmail labels are kept as plain metadata so your inbox list renders quickly; the message body, HTML, and preview text are encrypted with AES-256-GCM before they touch our database. Sodaroad also sets up a Gmail watch (a push subscription on your mailbox) so it can learn about new mail without polling; the notifications carry no message content. When you send mail from Sodaroad, it goes out through Gmail's API from your account.
Usage Data. We collect information about how you interact with Sodaroad, such as session activity. We use essential cookies for authentication and session management. We do not use analytics, advertising, or tracking cookies.
2. How We Use Your Information
To Provide the Service. We use your email data and account information to show your inbox, render your conversations, send the mail you compose, and keep your stored copy in sync with Gmail. This is the primary and essential use of your data.
To Personalize Your Experience. Sodaroad may use automated classification to organize mail for your account. Sodaroad does not train models on your email data. Your email data is not combined with other users' data to train generalized or non-personalized AI or machine learning models, and Google API data is not used to develop, improve, or train generalized, foundational, or frontier AI or ML models.
The Memory Feature (Decisions & Commitments). Sodaroad offers an optional feature that finds decisions and commitments in your conversations and keeps them as a private record for you. To do this, Sodaroad sends the text of a conversation — subject, sender, date, and message text, up to set limits — to an AI model provider we have verified does not use your content to train its models (Z.ai, Anthropic, or OpenAI — the candidate set named in the disclosure you consented to). What comes back — short claims about your own decisions and commitments — is encrypted like your mail. This feature is off until you explicitly turn it on at the memory consent page, which shows exactly what is sent before you consent. While it is off, nothing is sent and no memories are stored; only after you turn it on can Sodaroad process your stored conversations, under the disclosure you consented to, until you withdraw consent — nothing is ever processed under a grant you have not given. Your consent record stores the date of your grant and the version of the disclosure you agreed to, and each extracted memory records the model that produced it. You can withdraw consent there at any time; withdrawing stops new processing but does not delete what was already extracted. Sodaroad does not train models on your email data, and no provider in this feature does either.
Channel Rule Suggestions. The Channels page lets you describe a sorting rule in plain words (for example, "only email from my dad"). When you do, Sodaroad sends what you typed — your description, and nothing else — to an AI model (Z.ai's GLM, through OpenRouter, on Sodaroad's own account) to draft candidate rules. No content from your mail is sent: not messages, not subjects, not senders, not any other mailbox data — the model receives only the description text. The candidates come back as plain-language rules, each shown with a count of which of your stored conversations it would match today, and nothing is saved until you approve a rule through the standard rule editor — the same way a hand-typed rule is saved. The description itself is not stored; the only record kept is an audit-log entry noting that the call happened (your channel, the counts, and the model — never the description text).
To Communicate With You. We may use your email address to send service-related communications, such as account updates and responses to support requests. We do not send promotional emails to you on behalf of third parties.
3. What We Do Not Do with Your Data
We want to be explicit about what Sodaroad will never do with your information:
No Advertising. We do not use your email data or personal information for advertising purposes, including serving ads, retargeting, personalized advertising, or interest-based advertising.
No Data Sales. We do not sell, rent, license, or trade your personal information or email data to any third party, including advertisers, data brokers, or information resellers.
No Unauthorized Human Access. Sodaroad employees and contractors do not read your emails unless (a) you have given specific, affirmative consent to view a particular message (for example, as part of a support request you initiated), (b) it is necessary for security purposes such as investigating abuse or a security incident, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized such that it is no longer personally identifiable and is used only for internal operational purposes.
No Creditworthiness or Surveillance. Your data is never used to determine creditworthiness or for lending purposes, and is never provided to any entity for the purpose of conducting surveillance.
4. Sub-processors
Sodaroad relies on the following third-party service providers to operate. Each is contractually bound to use your data only as necessary to provide services on our behalf and in accordance with this policy. We do not transfer your Google user data to any party not listed below, except as necessary to comply with applicable law or as part of a merger or acquisition (with prior explicit notice and consent).
Google (privacy policy) — provides OAuth authentication, Gmail API access, and (when enabled) Pub/Sub mailbox-change notifications. Google is the source of all email data Sodaroad processes.
Supabase (privacy policy) — hosts our PostgreSQL database in US East. Stores your account, application-encrypted OAuth tokens, and the stored copy of your mail: metadata in plaintext and message bodies/previews encrypted at the application layer (AES-256-GCM, a key separate from Supabase's disk encryption). Also stores audit and rate-limit records.
Vercel (privacy policy) — is Sodaroad's intended web application host. Sodaroad has not yet launched its hosted service: today the Sodaroad web application runs on infrastructure under Sodaroad's direct control (a development machine in the United States), and Vercel processes no Sodaroad data. At Sodaroad's first deployment, Vercel will host the web application in US East and ingest structured logs; those logs will pass through an application-layer redaction pass that removes known PII keys (email addresses, OAuth tokens, OAuth state, cookies, Authorization headers) before write.
Google Sheets (privacy policy) — stores the public waitlist log (timestamp, email, ESP type only). Receives no Gmail-derived content.
AI Model Provider (the memory feature). When — and only when — you have explicitly turned on the memory feature at the memory consent page, Sodaroad sends the text of your conversations (subject, sender, date, and message text, up to the limits disclosed there) to one AI model provider: Z.ai (GLM), Anthropic, or OpenAI — each contractually or by published API terms barred from using your content to train their models, and each verified by us as such before any content is sent. The date of your grant and the version of the disclosure you consented to are recorded with your consent, and each extracted memory records the model and prompt version that produced it. No content is sent to any of them while the feature is off. You can withdraw consent at the memory consent page at any time; withdrawal stops new processing immediately.
OpenRouter (channel rule suggestions). OpenRouter routes Sodaroad's model calls for the channel rule suggestion feature described in §2: when you ask for a plain-words rule draft, your typed description (and nothing else — no mail content) is sent through OpenRouter to the model named there, on Sodaroad's own account. For this feature OpenRouter receives description text only, and nothing from it is stored.
5. Data Retention and Storage (the complete picture)
This section is the single, complete statement of what Sodaroad keeps and for how long; the rest of this policy links here rather than restating it.
Your stored mail. Sodaroad keeps the imported copy of your mail — all of it except spam, trash, and drafts, starting from your 10,000 most recent messages, plus the rest of any conversation you open in Sodaroad — until you delete it or delete your account. There is no fixed retention clock: the copy exists so your inbox works, and you are the only person who can remove it early. Message bodies, HTML, and previews are encrypted with AES-256-GCM under keys that live only in Sodaroad's encrypted environment; subjects, senders, recipients, dates, and Gmail label snapshots are stored as plaintext metadata. Your read/unread and archived state in Sodaroad is Sodaroad-local — it is not written back to Gmail. (An optional automatic-triage feature — off today — can archive bulk promotions in Gmail by removing Gmail's Inbox label; it is disclosed here and at connect before it is ever turned on.)
Deletion behavior. If you delete a message in Gmail, Sodaroad removes its stored copy the next time it syncs; until that sync runs, Sodaroad may still show the message from the stored copy. If you revoke Sodaroad's access at Google, Sodaroad stops reading your Gmail immediately, but revoking does NOT delete anything Sodaroad has already stored — your stored mail remains (and keeps rendering in Sodaroad) until you delete it from your account settings or delete your account.
OAuth tokens. Encrypted at the application layer (AES-256-GCM) and held only while your account is active. Deleted immediately on account deletion.
Audit log. Append-only and retained indefinitely as a forensic record of consent grants, exports, and deletions. Audit rows reference your user id and event counts but contain no message content; the record of your deletion request itself survives your deletion.
Rate-limit records. Short-lived rows keyed by your account id or IP address plus timestamps. Your account-keyed rows are removed immediately when you delete your data; the remaining rows are removed by a periodic stale-record cleanup.
Extracted memories. If you turn on the memory feature, the short claims it extracts (decisions and commitments from your conversations) are encrypted with AES-256-GCM under the same application-layer keys as message bodies and are kept until you delete them: all at once from the memory consent page, or together with everything else when you delete your account. They are included in your data export. Withdrawing memory consent stops new extraction but does not delete the memories you already have — deletion is the separate action described above.
Backups. Sodaroad's current Supabase Free Plan does not include provider-managed automated backups or point-in-time recovery. Account deletion removes records from the live production database immediately; because there are no managed backups, there is no backup-retention tail for those records.
6. Data Storage & Security
Your data is stored on US-based cloud infrastructure using industry-standard encryption in transit (TLS 1.2+) and at rest (AES-256 at the disk layer). OAuth refresh and access tokens, and all stored message bodies and previews, are additionally encrypted at the application layer with AES-256-GCM before they reach the database. We implement administrative, technical, and physical safeguards designed to protect your information from unauthorized access, alteration, disclosure, or destruction. These measures include role-based access controls, append-only audit logging, row-level security policies on every user-data table as a forensic backstop, and regular security reviews. No method of electronic storage is 100% secure, and we cannot guarantee absolute security. For our security-disclosure process and contact, see /security.
7. Your Rights & Choices
Self-serve export. You can download a JSON export of every record we hold about you — your account, linked email addresses, stored mail (with bodies decrypted into the file), mailbox state, classification decisions, and extracted memories (with their claim text decrypted into the file) — from the dashboard at any time. The export deliberately omits OAuth tokens. Rows that cannot be decrypted are exported with a placeholder and listed in a decryptWarnings section, so a single damaged record never blocks your export.
Self-serve deletion is immediate. When you trigger deletion from the dashboard, Sodaroad asks Google to revoke every linked OAuth token (best-effort — if you want certainty, check your Google Account permissions afterward), writes a final audit entry, and permanently removes, in one operation: your account, your stored mail (every thread and message), your extracted memories, your sync state, your classification decisions, your mailbox-watch state, and your account-keyed rate-limit records. There is no 90-day delay and no soft-delete period. The only record that survives is the append-only audit entry showing that your deletion was performed (see §5).
Email-based requests. If you cannot reach the dashboard, you may also request export, correction, or deletion by emailing hello@matome.ai.
Revoke Google access. You may revoke Sodaroad's access to your Google account at any time through your Google Account permissions. Revoking access immediately stops Sodaroad from accessing your email — and, as §5 states, it does not delete the stored copy; use the dashboard deletion, or the step-by-step guide at Managing and deleting your data, when you want the data gone.
Cookies. Most browsers allow you to manage cookie preferences through their settings. Sodaroad only uses essential cookies for authentication and session management; disabling them will prevent you from signing in.
8. California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, the purposes for which it is used, and whether it is sold or disclosed. You have the right to request deletion of your personal data and to opt out of the sale of your personal information. Sodaroad does not sell your personal information. To exercise your rights, contact us at hello@matome.ai. We will not discriminate against you for exercising any of your CCPA rights.
9. European Users (GDPR)
If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation, including the right to access, rectify, port, and erase your data, as well as the right to restrict or object to certain processing. Our legal bases for processing your data are: (a) your explicit consent, provided when you connect your email account and authorize Gmail API access; (b) performance of a contract, as processing is necessary to deliver the Service you have requested; and (c) our legitimate interest in maintaining the security and integrity of the Service. You may withdraw your consent at any time by revoking Sodaroad's access through your Google Account settings, by withdrawing memory-feature consent in the product at the memory consent page (the most precise withdrawal point Sodaroad offers — it stops memory processing immediately without affecting anything else), or by contacting us. To exercise any of these rights, contact us at hello@matome.ai.
10. Children's Privacy
Sodaroad is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with personal information, please contact us at hello@matome.ai.
11. Data Breach Notification
In the event of a data breach that affects your personal information, we will notify affected users by email and, where required by applicable law, notify the relevant supervisory authorities within the timeframes required by law. Our notification will describe the nature of the breach, the data affected, and the steps we are taking in response. Our security-disclosure contact and process are documented at /security.
12. Google API Services — Limited Use Disclosure
Sodaroad's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Sodaroad:
(a) Only uses access to Google user data to provide and improve user-facing features that are prominent in Sodaroad's user interface, namely reading, rendering, and sending your mail and keeping the stored copy described in §5 in sync.
(b) Does not transfer Google user data to third parties except as necessary to provide or improve user-facing features (with user consent), to comply with applicable law, or as part of a merger or acquisition (with explicit prior consent). Sodaroad does not transfer Google user data to any advertising platform, data broker, or information reseller.
(c) Does not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
(d) Does not allow humans to read Google user data unless the user has provided affirmative consent to view specific messages, it is necessary for security purposes, it is required by applicable law, or the data is aggregated and anonymized for internal operations.
(e) Does not use Google user data to develop, improve, or train non-personalized AI or machine learning models. Any machine learning applied to your email data is personalized to your account only and is not co-mingled with other users' data for generalized model training.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date below. If we make material changes — particularly changes to how we access, use, or share your Google user data, or the addition of a new sub-processor that receives Gmail-derived content — we will notify you by email before the changes take effect and will request your consent before accessing any types of data not previously disclosed. Your continued use of Sodaroad after any non-material changes constitutes acceptance of the revised policy.
14. Contact Us
If you have questions about this Privacy Policy, your data, or your rights, contact us at hello@matome.ai. For security-disclosure inquiries, see /security.
Last updated: August 2026