Skip to content
underlayerYour workspace

YOUR DATA. YOUR CONTROL.

Privacy

Understand what you share, what we store, and who can access it.

About this draft

Development disclosures. This is not a final privacy policy. Operator and contact details, provider retention and policy review must be completed before public release.

What you connect and share

Signing in identifies your Underlayer account. Connecting Gmail is a separate step: you choose reading access, draft and sending access, or both. Agents start with no Gmail permissions. Underlayer checks each new request against your current permissions and label rules.

Allowed requests send information such as search queries, message IDs, recipients or draft text to Gmail. Underlayer returns permitted results to your agent, which can include addresses, headers, bodies, labels and draft details. Gmail credentials stay on the server. Underlayer offers reading, draft and sending actions. Sending is off by default and requires a separate permission in Underlayer. It sends only an existing draft created by the same agent, to the draft’s current recipients. Google’s draft scope includes sending; granting that scope alone does not enable an agent to send.

What Underlayer stores

The hosted application stores your account identifier and creation date, agent and Gmail connections, granted Google scopes, permissions, label rules and draft ownership IDs. Gmail credentials and temporary connection data are encrypted. The application database does not store email bodies, search results or an activity history. Email content passes through the server while a request runs. Drafts and sent messages stay in Gmail; sending replaces a draft with a sent message.

Auth0 and Google handle sign-in. Vercel hosts Underlayer, and MongoDB Atlas stores application data. A session cookie keeps you signed in; a temporary cookie protects the Gmail connection process. These providers have their own operational records and retention settings. Provider logs and backup retention are still being reviewed; this is not a zero-retention service.

Connected agents handle their own copies

Connecting ChatGPT transfers permitted Gmail results to OpenAI so it can answer your request. Conversation, memory, feedback and training handling depends on the applicable terms and settings. Underlayer cannot erase copies already received by ChatGPT. Review OpenAI’s connected-app guidance and data controls, including the feedback exception after opting out of training.

You can stop access and delete Underlayer data.