Legal
Privacy Policy
Last updated: September 8, 2026 · Applies to the Gork service and website.
Our approach to privacy
Gork (the "Service", "we", "us") builds programmable email infrastructure for AI agents. This policy explains what we collect, why we collect it, how long we keep it, who we share it with, and the choices you have. We do not sell your personal information or your Google user data, we do not serve ads, and we do not train machine-learning models on the contents of your email or the email you process through the Service.
01. Information We Collect
- Account information. When you sign in with Google, we receive from your identity provider only the profile fields needed to create your account: your name, primary email address, and avatar URL. If you register with email and password instead, we collect the name and email address you provide; passwords are stored as irreversible hashes, never in readable form.
- Organization and workspace data. Workspace names and membership roles you create, inbox display names and usernames you choose, verified domains, webhook endpoint URLs, suppression lists, and billing plan information.
- Message content. Email messages, headers, recipients, subject lines, bodies (plain text and HTML), and attachments that your inboxes send, receive, or store through the Service. This data is processed and stored on your behalf to provide the Service.
- Credentials. API keys are shown to you once at creation. We store only a salted SHA-256 hash of each key, never the key itself. Webhook signing secrets are stored so we can verify your webhook endpoints.
- Usage and technical data. IP addresses, user-agent strings, timestamps, endpoint invocations, error events, and latency metrics. We use this for rate limiting, abuse detection, debugging, and security auditing.
02. How We Use Information
- To operate the Service: provision inboxes, route and deliver email, maintain threads, dispatch webhooks, enforce quotas, and process billing.
- To secure the Service: detect abuse, spam, and bulk-sending patterns; verify webhook signatures; respond to bounces and complaints; and quarantine addresses after deletion to prevent account takeover.
- To support you: respond to support requests and send service or account notifications.
- To comply with law and protect our legal rights.
We do not use the content of messages processed through the Service to build profiles about you or your recipients, and we do not use it to train generalized AI or machine-learning models.
03. Google User Data
Our use of Google user data obtained through Google OAuth (used solely for authentication) complies with the Google API Services User Data Policy, including its Limited Use requirements:
- We request only the basic profile scopes needed to authenticate you (openid, email, profile).
- We do not transfer Google user data to third parties except to provide or secure the Service or as required by law.
- We do not use Google user data for advertising, and we do not allow humans to read it unless you ask us to or we are required to by law.
04. How We Share Information
We share data only with the service providers required to run the product, and only to the extent needed to provide it:
- Cloudflare, Inc. — our hosting provider. The Service runs on Cloudflare Workers, email routing, Queues, and Cloudflare R2 object storage (used for email attachments).
- Neon (Neon, Inc.) — our managed PostgreSQL provider, which stores structured application data in per-organization workspaces.
- Dodo Payments — our payments processor. Dodo collects and handles payment card details; we never receive or store card numbers.
- Google LLC — identity verification only (OAuth sign-in).
- Amazon Web Services (SES) — delivery of your outbound messages and receipt of inbound mail. SES is our sole email provider: sending, receiving, and bounce and complaint notifications all flow through it. No other sending provider touches your mail.
We may also disclose information where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Gork, our users, or the public.
05. Data Retention & Deletion
- Message data. Messages and attachments are retained until you delete them or delete your organization, subject to the retention windows below.
- Deleted inboxes. When an inbox is deleted, its address enters a 90-day security quarantine to prevent account takeover. You may reactivate the inbox during this window. After 90 days the address is released.
- Deleting your organization. You can delete your organization from the dashboard at any time. We purge organization data — inboxes, messages, keys, webhook configurations, and domains — within 30 days of deletion, except where we are required to keep records for legal, tax, or fraud-prevention purposes (for example, billing records).
- Logs. Operational and security logs are retained for a limited period (generally no more than 30 days) unless an active security investigation requires longer.
06. Security
We apply security measures across the platform, including:
- All traffic is encrypted in transit (TLS); data at rest is encrypted by our infrastructure providers.
- Every query is scoped to your authenticated organization at the application layer, so one workspace can never read another’s mail, keys, or billing data.
- API keys are stored as salted SHA-256 hashes; raw keys are shown once and never stored in cleartext.
- Webhook deliveries are signed with HMAC-SHA256 (X-Gork-Signature) so you can verify they came from us.
- Inbound email is sanitized before delivery: HTML is defused, scripts and hidden payloads are stripped, attachment types and sizes are bounded (15 MB per message), and decompression bombs are guarded against.
- We run outbound anti-abuse controls: sending approval for free workspaces, per-tier daily caps, and a broadcast-pattern tripwire that pauses sending pending review.
No security program is perfect. If you believe you have found a vulnerability, contact us at security@gork.email.
07. International Transfers
Gork is a global service. Data may be processed in the United States and in other regions where we or our subprocessors operate. When we transfer personal data across borders, we rely on appropriate safeguards (including, where applicable, standard contractual clauses adopted by the European Commission or equivalent mechanisms), and we take reasonable steps to ensure your data is protected to the standard described in this policy.
08. Your Rights & Choices
- Access and correction. You can view and update your account, workspace, and key settings from the dashboard.
- Export. Message data can be retrieved through the REST API at any time.
- Deletion. You can delete inboxes, keys, webhooks, and your entire organization from the dashboard, or request deletion by emailing support@gork.email.
- Do Not Sell. We do not sell personal information, so there is nothing to opt out of. We also do not use tracking cookies for advertising.
- GDPR / CCPA rights. Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. To exercise any of these rights, email support@gork.email and we will respond within the time frame required by law.
09. Children
The Service is a developer infrastructure product and is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at support@gork.email.
10. Cookies & Local Storage
The dashboard uses a session cookie and local storage to keep you signed in and remember preferences (such as theme). We do not use third-party advertising or cross-site tracking cookies. If you block cookies, parts of the dashboard that require authentication may not work.
11. Changes to This Policy
We may update this policy as the Service evolves. Material changes will be announced on this page with an updated "Last updated" date, and we will notify you through the dashboard or by email when required. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
Questions about this policy, your data, or Google OAuth compliance? Reach us at: