Security & privacy
Your inbox stays yours.
FoucsAI is maintained by the FoucsAI team. This page summarizes the controls we have in place today, written plainly. It's not a third-party certification — if you need one for procurement, get in touch.
Read-only OAuth
FoucsAI uses Google's official Gmail API. We request read scopes by default — we cannot send or delete email on your behalf.
In-memory processing
Threads are fetched, scored, and summarized in memory at request time. We don't keep a mirror of your inbox sitting on disk.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest for any cached metadata. OAuth tokens are stored encrypted with per-user keys.
No model training
Your email is never used to train a public model. Prompts and completions are processed only to serve your session.
Revoke any time
Disconnect from your Google account or inside FoucsAI — we delete your stored metadata within 24 hours of revocation.
Least-privilege infra
Production access is restricted, logged, and reviewed. Secrets live in a managed vault, never in code or repos.
The details
What we collect, and why.
When you connect Gmail, FoucsAI accesses thread metadata, sender, subject, snippet, and body text via the Gmail API. We read this on demand to score and summarize threads. We don't mirror your mailbox into our own database; cached metadata (e.g. priority score, last-summarized timestamp) is retained only as long as needed and deleted on disconnect.
We store your email address, name, profile photo (from Google), and account preferences such as VIP senders and keyword rules. This is the minimum needed to deliver the product.
Summaries and drafts are produced by large language models accessed via a server-side gateway. Prompts and completions are processed for your session only and are not used to train public foundation models. We log redacted metadata for reliability — never raw email content beyond the session.
We rely on Google (Gmail API + Auth), our cloud hosting provider, and an LLM gateway. Each is bound by a data processing agreement and accessed through least-privilege credentials. A current list is available on request.
Disconnect from inside FoucsAI or from your Google account at any time. We delete stored metadata within 24 hours of revocation. Email security@focusai.app to request earlier deletion or a data export.
Found something? Email security@focusai.app with reproduction steps. We acknowledge within two business days and credit responsible disclosures in our changelog.
FAQ
Security & privacy — FAQ
Common questions about how FoucsAI handles your data.
