Privacy Policy
Last updated September 10, 2026
Knowles Mail Bridge (the application) is a private tool operated by Michael Knowles for his own use. This policy describes how it handles data.
Who it serves
Only the operator. Access is restricted to an explicit allow-list of Google accounts belonging to him. The application is not offered to other people and has no other users.
What data it accesses
With the operator's explicit Google authorization, the application accesses Gmail data in the authorized mailbox: message and thread contents, headers, attachments, labels, and drafts. It also reads the account's verified email address and basic profile information in order to identify which mailbox authorized a given connection.
What it stores
- Google refresh and access tokens, encrypted, in storage belonging to the operator's own Cloudflare account. These are what allow the application to reconnect without repeated sign-in.
- Nothing else. Message contents, attachments, and metadata are not stored, logged, or retained. Mail is decrypted in memory only for the duration of a single request and is gone when that request completes.
How data is used
Gmail data is used only to carry out the operator's own instructions in the moment he gives them: finding a message, reading a thread, composing a reply. It is not used for any other purpose.
What is never done
- Data is never sold, rented, or licensed.
- Data is never transferred to third parties, except that message content necessarily passes to the AI assistant the operator is using at the moment he asks it to act on that message.
- Data is never used to train, fine-tune, or improve any machine learning model.
- Data is never used for advertising, profiling, or analytics.
Google user data
The application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Tokens are kept only while a connection is in use. The operator can revoke the application's access to any account at any time at myaccount.google.com/connections, which immediately and permanently invalidates the stored token for that account. Because no mail content is retained, revoking access leaves nothing behind.
Security
Tokens are encrypted at rest in the operator's own Cloudflare storage. Each session is bound to the single account that authorized it, so a session for one mailbox cannot reach another. All traffic is over HTTPS.
Children
The application is not directed to children and is not available to anyone but its operator.
Changes
If this policy changes, the revised version will be posted at this address with an updated date.
Contact
Questions about this policy: mikeknowles79@gmail.com