Back to Home

Privacy Policy

Last updated: September 4, 2026 · Version 1.0.0

Zero-Trust Data Guarantee

At gork.email, we build programmable email infrastructure for AI agents. We respect your privacy and process all data under strict zero-trust principles. We do not sell your personal information or Google user data to third parties, nor do we use private email payloads to train public AI models.

01. Information We Collect

When you use gork.email, we collect necessary account information and platform metrics to provide secure API services:

  • Authentication Data (Google OAuth SSO): When you authenticate via Google, we collect your name, primary email address, and Google profile photo URL. We use this exclusively to authenticate your account and provision your isolated organization.
  • API Credentials & Hash Hashes: API keys and secrets generated via the dashboard are stored using salted SHA-256 password hashes. Raw API keys are never stored in cleartext.
  • Email Transaction Payloads: Email messages, metadata, headers, and attachments processed through your configured inboxes and webhooks.
  • Usage & Telemetry: Log data including IP addresses, user agents, API endpoint invocation counts, and latency statistics for rate-limiting and security auditing.

02. How We Use Google User Data

gork.email integration with Google APIs (Google Sign-In / OAuth 2.0) adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements.

Limited Use Compliance
  • We only request access to basic profile (openid, email, profile) for authentication.
  • We do not transfer Google user data to third parties unless required by law or necessary to provide the service.
  • Google user data is never used for serving advertisements or for training generalized AI/ML models.

03. Multi-Tenancy & Data Isolation

gork.email enforces strict Row-Level Security (RLS) across Neon PostgreSQL databases. Every customer organization operates within an isolated tenant boundaries:

  • No cross-tenant data leakage is permitted. Queries resolve dynamically against the authenticated user's organization ID.
  • Attachments are securely encrypted at rest in Cloudflare R2 object storage.
  • Payload sizes are capped (15MB max) and checked for safety against malicious zip bombs and script injections.

04. Data Retention & Deletion

You maintain full ownership of your data on gork.email:

  • You can request complete account and data deletion at any time by contacting our support team or deleting your organization from the Developer Dashboard.
  • Upon account termination, all API keys, webhook configurations, inbox mapping, and raw email payloads are permanently purged from active databases within 30 days.

05. Contact Us

If you have any questions regarding this Privacy Policy or Google OAuth compliance, please reach out to us:

Email: support@gork.email
Security: security@gork.email
Website: https://gork.email