Privacy Policy
moldit.ai ("moldit", "we", "us") is a browser extension that overlays your Gmail inbox with AI-generated work states (e.g. "Needs Action," "Waiting for Reply"). This policy explains what data the extension and its backend service access, how that data is used, and what is never done with it.
1. What we access
When you connect your Gmail account, moldit requests the following Google OAuth scopes:
- gmail.readonly — to read message metadata (sender, subject, date, snippet) and, when you open a message, its full body, so it can be classified and displayed in the overlay.
- gmail.modify — to perform actions you trigger yourself, such as archiving, trashing, or marking a message read/unread.
- gmail.send — to send a reply on your behalf, only when you compose and send one from within moldit.
Every Gmail action is performed using your own OAuth access token, scoped to your account. moldit never accesses another user's mailbox, and never takes an action (archive, send, etc.) that you did not initiate.
2. How data flows
moldit's browser extension talks to our backend service, which in turn calls the Gmail API using your access token. Concretely:
Email metadata (sender, subject, date, snippet) is sent to our backend to build your inbox view and to classify messages into work states.
Full message body is sent to our backend only when you open a specific email's detail view, so it can be rendered and, if requested, summarized.
Classification of your inbox into work states is performed by sending message metadata (sender, subject, date, snippet, and thread context — not full message bodies) to a third-party AI provider (Google Gemini, with Groq as a fallback). These providers process the data to return a classification label and do not use it to train their models under our API agreements with them.
3. What we store
On our server: classification results (e.g. which work-state bucket a message belongs to) are cached temporarily in memory, keyed by your email address and the message ID, and automatically expire within about an hour. We do not maintain a database of your emails, and raw message content is not persisted after a request completes.
In your browser: moldit stores your view preferences (layout, theme), a short-lived local cache of your inbox view, and your custom sorting templates using the browser's local storage — this data stays on your device and is scoped to your account.
moldit does not run analytics or tracking scripts, and does not sell or share your data with advertisers.
4. Third parties
We share data only as needed to provide the service:
- Google Gmail API — to read and act on your inbox, using your own authorization.
- Google Gemini API and Groq API — to classify email metadata into work states.
- Render — our hosting provider, which runs the backend service that brokers these requests.
We do not sell your data, and we do not share it for advertising purposes.
5. Google API Services User Data Policy
moldit.ai's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Your controls
- You can revoke moldit's access to your Google account at any time via Google Account permissions.
- Uninstalling the extension removes all locally stored data (preferences, cached views, templates) from your browser.
- You can request deletion of any server-side data associated with your account by contacting us (below); since we only retain short-lived cached classification results, this is typically already gone within the hour.
7. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by updating the "Last updated" date above.
8. Contact
Questions about this policy or your data: granthbagadia2004@gmail.com