Privacy policy
Flick (flicked.email and the Flick apps) is an email decision client. This page explains the technical capability you authorize, how Flick currently uses it, what content is processed, what persists, and what account deletion does not erase.
What we access
For Gmail, Flick requests the restricted gmail.modify OAuth scope. Google describes that grant as permission to read, compose, and send email, in addition to modifying labels. The grant is technically broader than Flick's current interface. The current Flick build does not expose or invoke Gmail Send. It reads sender, subject, snippets, thread content when required by a requested feature, and thread metadata to prepare a bounded decision batch. Approved replies are created as drafts for you to review and send.
Flick's private pilot is limited to Gmail accounts that the participant personally controls. Delegated, shared, team-managed, and alias-only identities are outside the pilot.
What we store
- Account & connection data — your account identifier, connected-mailbox metadata, and encrypted access credentials.
- Decision and delivery state — bounded batch identifiers, account/thread bindings, archive/keep/draft decisions, retries, provider results, and minimal metadata required to reconcile an action.
- Approved draft text — stored encrypted, scoped to your account, and retained only as required to create or reconcile the provider draft. It is not a permanent mailbox archive.
- Product analytics — first-party usage events (e.g. "deck loaded", "draft accepted") plus Google Analytics across flicked.email, our landing pages, the Flick web app, and the Flick iOS app, for aggregate traffic measurement. No ad networks, and no ad/IDFA tracking on iOS.
Flick does not maintain a general copy of your mailbox. Message content is processed request-scoped when needed to display a selected card or generate the draft you request. The selected thread content can transit Flick infrastructure and Anthropic for that request. Minimal action state and encrypted approved draft text can persist temporarily for delivery and reconciliation.
AI drafting
Reply drafts are generated server-side using Anthropic models. The selected thread content is sent for the draft request you initiate. Flick does not use mailbox content to train its own models and does not instruct Anthropic to train on it. Approved draft text can be stored encrypted until provider creation or reconciliation completes.
Google API Services — Limited Use disclosure
Flick's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Browser companion
Flick's browser companion is not being offered to new users during the contained private pilot. Existing installations use a companion session for the same Flick account:
- It never touches your mail provider's website. Its only permission is to talk to Flick's own service (app.flicked.email). No content scripts, no access to Gmail or any other site you browse.
- On your device it stores exactly four things in the extension's local storage: a revocable Flick session token, the email address of the connected account (so the panel can name it), and your badge and ritual-hour preferences. Nothing syncs to other devices.
- It stores no email on your device. Cards are fetched from Flick's API for display, live in the panel for the session, and die with it.
- Sign-in is a handoff, not a new login. Connecting the panel exchanges a one-time 60-second code on our domain for the extension's own session token — no passwords, no Google scopes requested by the extension.
- Revocation is yours, two ways: "disconnect this panel" in the panel menu ends just the extension's session (the web app stays signed in); "sign out everywhere" ends every Flick session including the web. Panel sessions also expire on their own after about a month.
- The once-a-day badge calls a counts-only endpoint (how many cards are waiting — never message content).
The extension introduces no new subprocessors; everything below applies unchanged.
Service providers (subprocessors)
- Folderly — Gmail connectivity currently uses Folderly infrastructure from the same team. The Google consent screen can therefore identify Folderly. Flick is seeking written confirmation for the exact Flick client identity and data flow; a prior verification of another product should not be read as approval of every Flick surface.
- Nylas — email connectivity for connected mailboxes.
- Google — OAuth and Gmail APIs for Google accounts.
- Google Analytics — aggregate traffic analytics across flicked.email, our landing pages, the Flick web app, and the Flick iOS app (IDFA-free on iOS).
- Anthropic — AI reply drafting.
- Vercel — application hosting.
- Railway — database hosting.
- Stripe — payment processing for web purchases (we never see your card number).
What we never do
- We never sell your data.
- We never show ads or share your data with ad networks.
- The current Flick build does not expose or invoke Gmail Send, even though
gmail.modifyis technically broad enough to authorize sending. - We never train AI models on your mail.
Deleting your data
Request deletion from Settings → Delete account or by email. Flick removes active application access, mailbox connections, and eligible application records according to its deletion process. Provider email already changed by an action remains at the mail provider unless you change it there. Payment processors, Apple, tax, fraud, refund, dispute, security, and legally required records may be retained under their own obligations and retention periods; deleting a Flick account does not itself cancel an external subscription. Contact support if you need cancellation or refund help.
Changes & contact
If this policy changes materially we'll update this page and the effective date. Questions or requests: hey@flicked.email.