Security & privacy

Your inbox stays yours.

FoucsAI is maintained by the FoucsAI team. This page summarizes the controls we have in place today, written plainly. It's not a third-party certification — if you need one for procurement, get in touch.

Read-only OAuth

FoucsAI uses Google's official Gmail API. We request read scopes by default — we cannot send or delete email on your behalf.

In-memory processing

Threads are fetched, scored, and summarized in memory at request time. We don't keep a mirror of your inbox sitting on disk.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest for any cached metadata. OAuth tokens are stored encrypted with per-user keys.

No model training

Your email is never used to train a public model. Prompts and completions are processed only to serve your session.

Revoke any time

Disconnect from your Google account or inside FoucsAI — we delete your stored metadata within 24 hours of revocation.

Least-privilege infra

Production access is restricted, logged, and reviewed. Secrets live in a managed vault, never in code or repos.

The details

What we collect, and why.

Gmail data

When you connect Gmail, FoucsAI accesses thread metadata, sender, subject, snippet, and body text via the Gmail API. We read this on demand to score and summarize threads. We don't mirror your mailbox into our own database; cached metadata (e.g. priority score, last-summarized timestamp) is retained only as long as needed and deleted on disconnect.

Account data

We store your email address, name, profile photo (from Google), and account preferences such as VIP senders and keyword rules. This is the minimum needed to deliver the product.

AI processing

Summaries and drafts are produced by large language models accessed via a server-side gateway. Prompts and completions are processed for your session only and are not used to train public foundation models. We log redacted metadata for reliability — never raw email content beyond the session.

Subprocessors

We rely on Google (Gmail API + Auth), our cloud hosting provider, and an LLM gateway. Each is bound by a data processing agreement and accessed through least-privilege credentials. A current list is available on request.

Retention & deletion

Disconnect from inside FoucsAI or from your Google account at any time. We delete stored metadata within 24 hours of revocation. Email security@focusai.app to request earlier deletion or a data export.

Vulnerability reporting

Found something? Email security@focusai.app with reproduction steps. We acknowledge within two business days and credit responsible disclosures in our changelog.

FAQ

Security & privacy — FAQ

Common questions about how FoucsAI handles your data.