Nesty is a workspace that organizes your projects, mail, files, and collaborators in one place. This policy describes what data Nesty accesses, why, and what we will never do with it.
If you connect a Gmail account, Nesty asks Google for three permissions and no others: read-only access to your mail (gmail.readonly), permission to send mail as you (gmail.send), and the email address of the account you are connecting (userinfo.email).
We use gmail.readonly to read message headers and, where you separately consent inside the product, message content — solely to organize your mail into your projects, surface obligations and next steps, and produce the diagnostics you request. If you grant sending permission (gmail.send), Nesty sends a message from your address only when you explicitly initiate it — for example, sending an invitation or a document you choose to share — one message per action, never automated, never in the background. We use userinfo.email once, at the moment you connect, to learn which Google account you just authorized, so the connection can be labelled with that address and your mail attributed to the right mailbox; it discloses your email address and nothing else — no name, no profile, no contacts, no other account data.
Nesty never modifies or deletes your mail. When you connect a mailbox, Nesty may check it on a schedule in the background — including when you are not signed in — solely to keep your projects current with newly arrived mail. It is never read for any other purpose, and disconnecting the account ends this immediately.
Nesty's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except with your explicit permission, for security purposes, or as required by law.
Integrations such as Dropbox and GitHub are read-focused and connected only at your request. Each can be disconnected at any time from within the product, which ends Nesty's access.
Your account information, the projects and content you create, and the material you choose to ingest are stored with our infrastructure providers (including Convex for data, Clerk for authentication, Vercel for hosting, and Anthropic for AI processing of content you submit to AI features). We store derived organization (for example, which project a message belongs to) rather than mirroring your mailbox.
When you use AI features, the relevant content is sent to our AI provider (Anthropic) solely to produce the result you asked for. Under the commercial API terms Nesty operates on, this content is not used to train Anthropic's models — and Nesty never uses your content to train anything either. Your content is not sold, is not shared with any third party for their own purposes, and is not retained by the AI provider beyond the limited period their terms allow for abuse and safety monitoring. Your data lives in your Nesty workspace and nowhere else.
All data is encrypted in transit using TLS between your browser, Nesty, and every provider we use, and is encrypted at rest by our infrastructure providers. Google credentials are stored only as refresh tokens held in our database; they are never exposed to the browser, never written to application logs, and are used only server-side to obtain short-lived access tokens at the moment of a request you initiated.
Access is scoped to your account. Every request is authenticated before it reaches your data, every server-side operation resolves the identity of its caller and refuses to act without one, and every read and write is filtered by your account identifier so that one account cannot reach another's content. Automated background jobs verify that an account still exists before touching any data belonging to it.
Nesty is operated by a single person with no staff and no subcontractors. No employee reads your mail or your content; access happens only through the product's own scoped mechanisms, or with your explicit permission, for security purposes, or as required by law. Administrative credentials are held solely by the operator and stored outside the application.
Disconnecting a Gmail account revokes Nesty's grant with Google directly, so access ends at Google rather than merely stopping on our side, and the stored credential is destroyed. Deleting your account removes your data from every table in which it is stored, and we verify afterward that no records remain.
We do not sell your data. Content becomes visible to others only through sharing you initiate — share links you mint and members you invite — and you can revoke either at any time.
You may disconnect any integration at any time, and you may request deletion of your account and associated data by emailing dev@inh.tech; we will complete deletion within 30 days.
We will post any changes to this policy on this page. Questions: dev@inh.tech.