Privacy Policy
FOIAflow drafts, sends and tracks public records requests. This policy describes what the product stores, who else processes it, and what we can and cannot see.
The short version
The Gmail connection is send only. We cannot read your mailbox, and no part of the product tries to. We store the requests you write, the agencies you send them to, a record of what was sent, and the replies that come back to our own reply address. We do not sell your data and we do not share it for advertising.
Gmail access is send only
When you connect Gmail, FOIAflow asks Google for exactly one mail permission, the one Google names gmail.send. That permission lets an application hand Google a finished message for delivery. It does not permit reading, listing, searching, downloading, labeling or deleting anything in your mailbox. This is not a policy we impose on ourselves. It is the boundary Google enforces: the credential we hold is refused for every read operation, so there is no version of this product that quietly starts reading your mail without you granting a new permission first.
If you are a journalist deciding whether to connect a working account, that is the fact that matters. Your sources, your unrelated correspondence and every message you did not send through FOIAflow are invisible to us.
Google returns a refresh token so the app can send on your behalf later. We encrypt it with AES-256-GCM before it is stored, and the key lives in server environment configuration, not in the database beside the ciphertext and never in your browser. It is used only on the server, only to obtain a short-lived token, and only when a send is taking place.
Disconnecting Gmail
You can disconnect from the Gmail settings in the app. Disconnecting asks Google to revoke the token and deletes the stored connection, so the app can no longer send as you. You can also revoke access yourself from your Google Account permissions page, which works whether or not you sign in to FOIAflow again. Revoking at Google is the authoritative action; our delete is what removes the record on our side.
Google user data and Limited Use
FOIAflow’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What Google gives us is narrow. Connecting Gmail returns the address of the account you connected and a token that lets the app send messages as you. Nothing in that grant returns the contents of your mailbox, because the only mail permission we request is gmail.send.
We use what we receive solely to provide the sending feature described above, which is visible in the product and runs only when you start it. We do not transfer it to others except where doing so is necessary to provide that feature, where the law requires it, or in connection with a merger or acquisition. We do not use it for advertising, to build advertising profiles, or to determine creditworthiness. No person here reads it, except where you have asked us to, where security or the law requires it, or where it has been aggregated and de-identified for internal operations.
How agency replies reach us
A request sent through FOIAflow goes out from your Gmail address and carries a reply address that belongs to us, unique to that one request. When the agency replies, the message arrives at our inbound mail provider, is matched back to the request it belongs to, and is stored with that request so the correspondence and the filing stay together.
That is the only mail we ever receive, and it is mail addressed to our own domain. If an agency writes to your address directly instead of using the reply address, that message goes to your mailbox and we never see it.
What the product stores
- Your account: the email address you sign up with and the organization it belongs to.
- Requests you draft and file, including the letter text, the jurisdiction, the agency and its routing details, filing dates and the response deadlines calculated from them.
- A record of each send: the recipient, the sending address, the reply address, the subject, the exact body transmitted, the identifier Gmail returned, who sent it and when.
- Agency replies matched to the request that produced them.
- Documents you upload and the analyses generated from them.
The send record is written by the server after Google accepts the message, and the application cannot alter it afterward. It exists so there is a durable account of what left the building, which is the thing you are most likely to need if an agency later disputes what it received.
Who else processes it
- Supabase, for the database, authentication and file storage.
- Resend, for transactional email and for receiving agency replies.
- Google, only if you connect Gmail, and only to send the messages you send.
- Anthropic, which processes document text and request context when you run an analysis, trace an entity, or look up an agency records contact.
- Vercel, which hosts the application.
Each processes this data as our service provider, under its own terms. We are not in a position to make promises on their behalf about what they do internally, so we do not make any here.
Documents you upload
Uploaded files are stored in Supabase Storage under your organization. When you run an analysis, the document and the earlier analyses in the same investigation are sent to Anthropic’s API and the result is written back to your account. Files are not sent anywhere else, and nothing is published or made public by the product.
What we do not do
We do not sell your data. We do not share it for advertising. There is no advertising network and no third-party analytics or tracking script in this application. We do not read your mailbox.
People using this product are frequently working on material that is confidential until the day it is published, and sometimes on material that is sensitive well beyond that. Everything in an account is treated as confidential.
Security
Traffic runs over HTTPS. Data is scoped to your organization at the database level, so one account’s records are not readable by another. The Gmail refresh token is encrypted at rest with a key held outside the database. No system is perfectly secure, and we are not going to tell you otherwise.
Keeping and deleting data
We keep your data for as long as your account exists. You can delete a request from the app at any time. The record of a request that was already transmitted is kept even so, because deleting our copy would not unsend the message and would leave you without the record of what was filed.
Write to us at the address below to delete your account and we will remove your data. We would rather commit to doing that on request than publish a retention schedule we have not yet built the tooling to enforce.
Legal process
We may be required to disclose data in response to valid legal process. Where we are permitted to tell you, we will. Some orders carry provisions that forbid it, so we will not promise notice in every case. A promise that cannot always be kept is worth less than an accurate description of the limit.
Changes
If this policy changes, the date at the top of this page changes with it.
Contact
Questions about this policy go to contact@foiaflow.co.