e-slop
  • Home
  • Terms
// legal

Privacy Policy

Effective June 3, 2026

The short version

E-slop reads your incoming emails on our servers, scores them for AI-generated content, and moves the ones that score above your threshold. We read the body text to score it, then discard it. We store only basic metadata about what was filtered. We don't sell data, share data with third parties, or use your email content for anything beyond filtering.

What we access

When you connect Gmail, E-slop requests the gmail.modify scope from Google. This allows us to receive notifications when new mail arrives, read incoming message content (subject line and body), apply a label, and move messages to a designated folder.

When you connect Outlook, E-slop requests Mail.ReadWrite and User.Read from Microsoft. These permissions cover the same operations: receiving notifications, reading incoming messages, applying a category tag, and moving messages to a designated folder.

We use these permissions only for the filtering operations described in this policy. We do not read your sent mail, your contacts, your calendar, or any other account data. We do not use your email content to train models or improve detection rules.

How email processing works

When a new email arrives, your provider sends a notification to our server. We fetch the subject line and body of that message, run it through our scoring engine, and make a decision. If the email scores above your sensitivity threshold, we move it and log the metadata described below. If it doesn't score above the threshold, no action is taken and no record is created.

The email body text is held in memory during scoring and then discarded. We do not write it to disk or store it in a database at any point.

What we store

For each filtered email, we store in our database: your user ID, the provider's message ID, the sender's email address, the subject line, the AI detection score, and the timestamp when it was filtered. We store this to compile your daily digest and track your monthly usage for billing.

We also store your OAuth access token and refresh token, encrypted at rest using AES-256-GCM. These tokens are used only to take action on your behalf when a filtering decision is made.

We store your sensitivity threshold setting and, if you've provided one, your whitelist of addresses and domains that skip filtering entirely.

Gmail and Google's data use requirements

E-slop's use of Gmail data is limited to operating the filtering service you connected. We do not use Gmail data for serving advertisements. We do not allow humans at E-slop to read your email content except in cases where you explicitly request support and provide a specific message for review. We do not share Gmail data with third parties except as described under "Service providers" below.

This policy and our use of Gmail data comply with Google's API Services User Data Policy, including the Limited Use requirements.

Service providers

Our server runs on Render. Our database runs on Render's managed PostgreSQL. Your filtered email metadata is stored there.

Billing is handled by Stripe. When you add a payment method, that information goes directly to Stripe. We receive from Stripe only confirmation of payment status and a customer ID. We never see your card number or banking details.

Digest emails are sent via Resend from digest@e-slop.com. The subject lines and sender addresses from your filtered emails are passed to Resend to compose the digest. Resend's privacy practices are at resend.com/privacy.

Data retention and deletion

While your account is active, we store your OAuth tokens, your whitelist, and metadata about each filtered email, namely the sender, subject, score, time, and the message body. We need these to filter your inbox and show you your history.

Use Delete account in Settings to remove all of it yourself. We delete your filtered email data, whitelist, and OAuth tokens from our database at once, and revoke E-slop's access to your inbox. The deletion is permanent. Stripe keeps its own record of any payment you made, governed by Stripe's policy.

Cookies

This site does not set tracking or analytics cookies. Stripe's checkout flow may set cookies as part of fraud prevention. Those are governed by Stripe's policy.

Children

E-slop is not directed at anyone under 13. We don't knowingly collect personal data from children under 13.

Changes to this policy

If we make changes that affect how we handle your data, we'll update this page with a new effective date and notify you via the daily digest email. We won't change practices in ways that reduce your rights without advance notice.

Contact

Questions about this policy: admin@e-slop.com

© 2026 E-slop
e-slop Privacy Terms