Privacy Policy
Last updated: September 25, 2026 · This is a draft policy pending legal review.
InfiniHash LLC ("InfiniHash," "we," "us") operates Oryah Mail, a connector that lets Claude access mailboxes and calendars you authorize (Gmail, Google Workspace, Microsoft 365 / Outlook). This policy explains what we collect, why, and how it's protected.
1. What we collect
- Account data: name, email address, and authentication identifiers from Google, Microsoft, or your passkey provider.
- OAuth tokens: encrypted access and refresh tokens for each mailbox/calendar you connect.
- Mailbox and calendar content: accessed only to fulfill the specific request you or Claude make (e.g., a search, a send, a free/busy check) — not bulk-synced or indexed beyond what's needed to serve that request and short-term caching for performance.
- Usage and audit data: timestamps, action type, and mailbox involved, recorded in your audit log.
- Billing data: handled by our payment processor (Stripe); we do not store full card numbers.
2. Google API Services User Data Policy — Limited Use disclosure
Oryah Mail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide or improve the mail and calendar features you request within Oryah Mail.
- We do not use Google user data for serving advertisements.
- We do not use Google user data to train generalized AI or machine learning models.
- We do not sell Google user data, transfer it to third parties for their own purposes, or allow humans to read it except: with your explicit consent, for security purposes (e.g., investigating abuse), to comply with applicable law, or where the data has been aggregated and de-identified.
The same Limited Use principles apply to Microsoft account data accessed through Microsoft Graph.
3. How we use data
We use collected data to operate the connector (authenticate you, relay requests to your mailboxes, enforce the per-mailbox permissions and send-domain allowlists you set), maintain your audit log, provide support, process billing, and secure the service. We do not use mailbox or calendar content for advertising or to train AI/ML models, and we do not sell your data.
4. Data retention and deletion
- OAuth tokens are retained until you disconnect a mailbox or delete your account, at which point they are revoked and deleted within 30 days.
- Audit logs are retained for 12 months for security and support purposes, then deleted.
- Message and calendar content fetched to fulfill a request is not persisted beyond short-term caching (typically under 24 hours) unless you explicitly save it (e.g., a draft).
- You may request full account deletion at any time by emailing [email protected]; we will delete account data, tokens, and logs within 30 days, except where retention is required by law.
5. Subprocessors
We share limited data with subprocessors strictly to operate the service:
- Stripe — payment processing and billing.
- Cloudflare — network security, CDN, and DDoS protection.
- Google — Gmail, Google Workspace, and Calendar API access you authorize.
- Microsoft — Microsoft 365 / Outlook and Calendar (Graph API) access you authorize.
We do not sell data to subprocessors or any other third party.
6. Security
OAuth tokens are encrypted at rest and in transit. Access to production systems is restricted and logged. See our Security overview for more detail.
7. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to withdraw consent for connected mailboxes at any time by disconnecting them in account settings. To exercise these rights, contact [email protected].
8. Children's privacy
Oryah Mail is not directed to children under 16, and we do not knowingly collect data from them.
9. Changes to this policy
We may update this policy as the product evolves. Material changes will be posted here with an updated date.
10. Contact
InfiniHash LLC · [email protected]