dusky

Privacy Policy

Effective August 3, 2026 · Last updated August 3, 2026

1. Who We Are and Scope

This Privacy Policy explains how Dusky ("Dusky", "we", "us") collects, uses, shares, secures, retains, and deletes information when you use askdusky.com, our web application, our desktop applications, and related services (the "Service"). It applies to visitors, account holders, and anyone whose data we process because a user connected a mailbox. It should be read alongside our Terms of Service.

2. Summary

  • We access your mailbox only after you authorize it through Google OAuth, and only within the scopes you approve.
  • We use your email data solely to power features you use: reading, search, summaries, chat answers, drafts, sending, and automation reports.
  • We never sell your data, never serve third-party ads, and never use your email content to train general-purpose AI models.
  • You can disconnect any mailbox, clear your private memory, opt out of community learnings, export your data, and delete your account at any time.

3. Data We Collect

  • Account data: email address, hashed password (or federated identity from Google sign-in), user ID, display name, timezone, plan, terms-acceptance timestamp, and settings.
  • Connected mailbox data: see section 4.
  • OAuth credentials: access and refresh tokens for connected providers, and short-lived OAuth state values used to secure the connection flow.
  • User content: chat messages, prompts, automation definitions (including purpose, audience, tone, and output style), drafts you compose, run history, generated reports, feedback notes, and private memory entries.
  • Notification preferences: which channels (in-app, browser, desktop, email) you have enabled.
  • Usage and technical data: log records, IP address, timestamps, browser and device type, operating system, app version, referring pages, feature interactions, and error diagnostics.
  • Support data: messages you send us and their contents.
  • Billing data: if you purchase a paid plan, our payment processor handles card details; we receive only transaction metadata such as plan, status, last four digits, and country. We never store full card numbers.
  • Cookies: see section 10.

4. Gmail and Connected Mailbox Data

When you connect a mailbox, and only within the scopes you approve, we may access and process: message metadata (sender, recipients, subject, date, thread and message IDs, labels, read state), message snippets and full bodies, attachment metadata, sent-mail records, and the address and display name of the connected account. You may connect multiple mailboxes; each is stored separately and linked to your account.

We fetch this data on demand to render your inbox and sent views, to answer your chat questions, and to execute automations you configure, including scheduled runs while you are not signed in. Where we cache message content it is to display it to you, to produce a report you requested, or to avoid redundant provider requests, and it is protected by row-level access controls scoped to your user account. We do not read your mailbox for any purpose other than providing the Service to you.

You can revoke access at any time from Settings, or from your Google Account security page. Revocation stops future access and we delete the associated tokens.

5. Google API Services Limited Use Disclosure

Dusky's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide or improve user-facing features that are prominent in the Dusky interface.
  • We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or asset sale where users have been given prior notice.
  • We do not use Google user data for serving advertising of any kind.
  • We do not allow humans to read Google user data unless we have your affirmative consent for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
  • We do not use Google user data to develop, improve, or train generalized or non-personalized AI or ML models.

6. How We Use Data

  • Operate the Service: display your mailbox, search, summarize, prioritize, draft, and send messages you confirm.
  • Run automations you create, on demand and on schedule, and generate reports and PDF exports.
  • Authenticate you, maintain sessions, and secure your account, including the "remember this device" option.
  • Deliver notifications you have enabled and essential transactional and security messages.
  • Personalize output using your automation context and private memory.
  • Provide customer support and respond to your requests.
  • Monitor, debug, and improve reliability, performance, and security, and detect abuse and fraud.
  • Process payments and maintain financial records.
  • Comply with legal obligations and enforce our Terms.

We do not sell your personal data, do not share it for cross-context behavioral advertising, and do not serve third-party ads.

7. AI Processing and Model Providers

To generate summaries, chat answers, drafts, and reports, we send the relevant portion of your content — which may include message subjects, snippets, bodies, your prompts, and your saved context — to AI model providers acting as our subprocessors. These providers process the data only to return a response to us, under contractual terms that prohibit using it to train their models and require deletion or short-lived retention for abuse monitoring only. We minimize what we send: only the messages relevant to the request or automation are included.

Model output is probabilistic and may be inaccurate. Review it before relying on it.

8. Memory, Feedback, and Community Learnings

  • Automation context (purpose, audience, tone, output style) is stored with the automation and used only in your runs.
  • Private memory is stored to your account, readable only by you under row-level security, and used only to shape your own results. You can view, edit, pin, and delete entries at any time in Settings.
  • Feedback you give on a report (thumbs up/down and notes) is stored with your account and always saved to your private memory.
  • Community learnings are optional. Only if you enable the sharing toggle do we derive generalized, anonymized lessons from your feedback that may improve results for other users. These are stripped of identifiers and message content before entering the shared pool. Turning the toggle off stops all future contributions; previously contributed anonymized learnings can no longer be linked back to you and may persist.

9. Legal Bases for Processing (EEA/UK)

Where GDPR or UK GDPR applies, we rely on:

  • Contract — to create your account and deliver the Service you requested.
  • Consent — to connect third-party mailboxes, to enable browser/desktop notifications, and to share community learnings. You may withdraw consent at any time without affecting prior lawful processing.
  • Legitimate interests — to secure, debug, and improve the Service, to prevent abuse and fraud, and to communicate about the Service, balanced against your rights.
  • Legal obligation — to meet accounting, tax, and lawful-request requirements.

10. Cookies and Similar Technologies

We use strictly necessary cookies and equivalent local storage for authentication, session persistence, security, and remembering your theme and preferences. We use minimal first-party diagnostic logging to keep the Service reliable. We do not use advertising cookies, cross-site trackers, or third-party ad networks. Blocking essential cookies will prevent sign-in from working.

11. Notifications and Communications

Notification preferences are stored in your profile. Browser and desktop notifications require a permission you grant to your browser or operating system and can be revoked there at any time. Email notifications are sent through our email infrastructure provider. You may disable optional notifications in Settings; essential security and transactional messages continue while your account exists.

12. Sharing and Disclosure

We disclose personal data only in these circumstances:

  • Subprocessors that operate the Service on our behalf, under contract, with confidentiality and security obligations (see section 13).
  • At your direction — for example, sending an email you confirm, which discloses its contents to your recipients and their providers.
  • Legal and safety — when required by law, subpoena, or court order, or to protect the rights, property, or safety of Dusky, our users, or the public. Where legally permitted we will notify you first.
  • Corporate transactions — in a merger, acquisition, financing, or asset sale, subject to this Policy and with prior notice.
  • Aggregated or anonymized data that cannot reasonably identify you.

13. Subprocessors

Categories of subprocessors we rely on:

  • Cloud hosting and edge compute (application hosting and serverless execution).
  • Managed database, authentication, and file storage.
  • AI model providers (summaries, chat, drafting, report generation).
  • Email delivery infrastructure (transactional and notification email).
  • Error monitoring and application logging.
  • Payment processing, if you purchase a paid plan.

A current list of named subprocessors is available on request at support@myvoidline.com. We assess each subprocessor's security posture and impose data-protection terms before engagement, and we remain responsible for their processing on our behalf.

14. International Transfers

Your data may be processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), adequacy decisions, or another lawful transfer mechanism, together with supplementary technical measures such as encryption in transit. A copy of the relevant safeguards is available on request.

15. Retention

We retain data only as long as needed for the purposes described:

  • Account data — while your account is active, then deleted or anonymized after closure.
  • OAuth tokens — until you disconnect the mailbox or delete your account, then deleted promptly.
  • Cached message content — kept only as long as needed to render your views and complete runs, and removed when you disconnect the mailbox.
  • Chat, automations, runs, reports, memory, feedback — until you delete them or delete your account.
  • Security and diagnostic logs — typically up to 12 months.
  • Billing records — as long as required by tax and accounting law, typically 6–10 years.
  • Backups — encrypted backups expire on our normal rotation cycle after deletion.
  • Anonymized community learnings — may be retained indefinitely because they no longer identify you.

16. Security

We apply administrative, technical, and physical safeguards appropriate to the sensitivity of email data, including: encryption in transit (TLS) and encryption at rest for stored data; row-level security so each user's records are only accessible to that user; isolated storage of OAuth tokens; least-privilege access controls and authentication for our staff; input validation and sanitized error handling in our backend functions; protection against leaked-password reuse at sign-up; audit logging; dependency vulnerability scanning; and periodic security review of the application and its policies. No method of transmission or storage is completely secure, and you use the Service at your own risk. Protect your own account with a strong unique password and by not enabling "remember this device" on shared machines.

17. Your Rights

Subject to applicable law, you may:

  • access the personal data we hold about you and obtain a copy;
  • correct inaccurate or incomplete data;
  • delete your data or close your account;
  • export your data in a portable format;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • withdraw consent at any time, for example by disconnecting a mailbox, turning off community learnings, or revoking notification permissions;
  • lodge a complaint with your local supervisory authority.

Many of these are available directly in the app (Settings → accounts, memory, privacy, notifications). Otherwise contact support@myvoidline.com. We respond within the period required by law, normally within 30 days, and may ask you to verify your identity. We will not discriminate against you for exercising a right. You may use an authorized agent where the law permits.

18. US State Privacy Rights

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, or another US state with a comprehensive privacy law, you have rights to know, access, correct, delete, obtain a portable copy, and appeal a denial, plus the right to opt out of sale, targeted advertising, and certain profiling. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for targeted advertising, so no opt-out is required. Sensitive personal information (which may include the contents of your email) is used only to provide the Service and not for inferring characteristics; we do not use or disclose it beyond the purposes permitted under CPRA. To appeal a decision, reply to our response or write to support@myvoidline.com.

19. Automated Decision-Making

Dusky classifies and prioritizes messages and generates drafts automatically, but it does not make decisions producing legal or similarly significant effects about you without human involvement. Every outgoing email requires your explicit confirmation. You may contact us to request human review of any automated output that affects you.

20. Desktop Applications

Our macOS and Windows desktop applications process the same data as the web application and may store session data and preferences locally on your device. They may check for and download updates. Uninstalling the app does not delete your server-side account data; use in-app deletion or contact us.

21. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it promptly.

22. Do Not Track

We do not track users across third-party websites, so we do not respond differently to "Do Not Track" or Global Privacy Control signals; there is no cross-site tracking to disable.

23. Data Breach Notification

We maintain an incident response process. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where legally required, notify affected users directly with a description of the incident, likely consequences, and the steps taken.

24. Controller and Processor Roles

For your account data, Dusky is the controller. Where you use the Service to process personal data of third parties contained in your mailbox, you generally act as controller and Dusky acts as processor on your documented instructions expressed through your use of the Service. A data processing agreement incorporating GDPR Article 28 terms is available on request at support@myvoidline.com.

25. Changes to This Policy

We may update this Policy to reflect changes in the Service, law, or our practices. Material changes will be notified by email or in-product notice before they take effect, and the "last updated" date above will change. Continued use after the effective date means you accept the updated Policy.

26. Contact and Complaints

Privacy questions, requests, and complaints: support@myvoidline.com. If you are in the EEA or UK and are not satisfied with our response, you may complain to your local data protection supervisory authority.