Privacy Policy
Last updated: August 14, 2026
Metis Mail lets you connect Gmail, Microsoft Outlook, and Zoho Mail accounts and manage them in one place, with optional AI assistance and integrated phishing detection. This policy explains what data we collect, how we use it, who we share it with, and the choices you have. It applies to the Metis Mail web application and its associated APIs.
1. Who we are
Metis Mail (the "Service") is an email client operated by AstraQ Cyber Defence ("we", "us", "our"), Engineers Colony Mothi Umari, Jatherpeth, Akola, Maharashtra, India 444005. You can reach us at contact@astraqcyberdefence.com.
2. Information we collect
Account information
- Your name, email address, and a hashed password (or magic-link sign-in records) when you create a Metis Mail account.
- Two-factor authentication data (TOTP secret and hashed backup codes), required for every account.
- Workspace membership records (workspaces you create or join, your role, and invitations you send or accept).
Connected mailbox data
- OAuth access and refresh tokens for each mailbox you connect (Google, Microsoft, or Zoho), together with the mailbox email address and provider.
- Email data fetched from your provider on your behalf: message headers, bodies, attachments, labels, and thread information. Most of this is fetched on demand and displayed to you; a limited subset is cached (see Section 5).
- Records you create in the Service: rules and workflows, custom labels, snoozes, scheduled sends, mute lists, unsubscribe history, drafts, and AI conversation threads.
Technical information
- Standard server logs (IP address, browser type, timestamps, requested pages) used for security, rate limiting, and debugging.
We do not collect data for advertising, and we do not use tracking or advertising cookies. Cookies we set are strictly functional (session, active workspace, active mailbox, theme).
3. Google user data
When you connect a Gmail account, Metis Mail requests the following Google OAuth scopes:
- openid, userinfo.email, userinfo.profile — to identify the Google account you connected and display its email address and name inside the app.
- gmail.modify — to list and read your messages and threads; mark messages read or unread; star, archive, restore, move to trash, and label messages; create, update, and delete drafts; apply the inbox rules you configure; and retrieve message content for the AI features and phishing analysis you invoke.
- gmail.send — to send email from your account only when you (or an action you explicitly approved or scheduled) trigger it: composing, replying, forwarding, scheduled "send later", and sending unsubscribe requests you initiate. Metis Mail never sends email autonomously.
Limited Use disclosure. Metis Mail's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the user-facing features of Metis Mail described in this policy. We do not use it for any other purpose.
- We do not transfer Google user data to third parties except as necessary to provide or improve those user-facing features (see Section 6), to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent.
- We do not use or transfer Google user data for serving advertisements, and we do not sell it to anyone.
- We do not allow humans to read your Google user data unless (a) we have your affirmative agreement for a specific message, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
- We do not use Google user data, including Gmail content, to develop, improve, or train generalized artificial intelligence or machine-learning models.
4. How we use your data
- Core email features — displaying your folders, messages, and threads; search; sending, replying, and forwarding; drafts; attachments; labels; archive, trash, star, and read-state changes; rules and workflows you configure; snooze and scheduled send.
- AI features you invoke — automatic message classification into labels, smart reply suggestions, thread summaries, and the AI assistant, which can read and act on your mail only within the tools and approvals you grant it in the chat interface. Destructive or outbound actions (deleting email, sending email) require your explicit in-chat approval.
- Phishing detection — when you open a message, its content may be analyzed by our phishing-detection service to warn you about suspicious email.
- Service operation — authentication, two-factor verification, workspace and shared-mailbox management, rate limiting, abuse prevention, and debugging.
- Transactional email — sending you sign-in links, verification emails, password resets, and workspace invitations.
5. What we store and for how long
- OAuth tokens are stored in our database and used solely to call your provider's API on your behalf. They are deleted when you disconnect the mailbox or delete your account, and we ask the provider to revoke the grant where the provider supports it.
- Message cache — to avoid re-downloading the same content, we cache the bodies of messages you open or that the features you use require (for example thread summaries, smart replies, and phishing analysis), along with their analysis results, keyed to your account. We do not maintain a full copy of your mailbox.
- Derived records — labels assigned to messages, thread summaries, unsubscribe history, scheduled items, and rule run history are stored so the features work across sessions.
- AI assistant conversations are stored so you can revisit them, and can be deleted by you at any time.
All data is encrypted in transit (TLS) and encrypted at rest by our database provider. Access to production systems is restricted to authorized personnel of AstraQ Cyber Defence and protected by strong authentication.
When you disconnect a mailbox, we delete its OAuth tokens and cease all access to that mailbox. When you delete your Metis Mail account, or on a verified request to contact@astraqcyberdefence.com, we delete your account data, cached message content, and derived records within 30 days, except where retention is required by law. Server logs are retained for up to 90 days.
6. Sharing and third-party processors
We never sell your data. We share it only with the processors needed to run the Service:
- Your email providers (Google, Microsoft, Zoho) — every mailbox action you take is executed against your provider's API.
- Database hosting (Neon, PostgreSQL) — stores the data described in Section 5.
- AI model providers (via OpenRouter) — when you use an AI feature, the relevant message content is transmitted to the model provider solely to generate the response for that feature, and is not used by us or permitted to be used to train generalized AI models. AI features operate only on the messages the feature requires, not your whole mailbox.
- Phishing-detection service — operated by AstraQ Cyber Defence. Message content is analyzed to produce a risk assessment.
- Transactional email (Resend) — delivers sign-in, verification, and invitation emails. Your mailbox content is never shared with Resend.
If you enable the optional MCP or agent-to-agent integrations, external AI clients you authorize via OAuth can access your mail through the tools you permit. You control these grants and can revoke them at any time in settings.
If you are a member of a workspace, mailboxes an administrator marks as shared are visible to other members of that workspace.
We may disclose data where required by law, court order, or a governmental authority with jurisdiction, or where necessary to protect the rights, safety, or security of the Service or its users.
7. Your rights and choices
- Disconnect any mailbox at any time from Settings → Connected Accounts; this deletes its tokens and revokes our access.
- Revoke Metis Mail's access directly from your provider: Google Account → Security → Third-party access, or the equivalent Microsoft and Zoho settings.
- Request access to, correction of, or deletion of your personal data, or raise a complaint, by emailing contact@astraqcyberdefence.com.
- Under India's Digital Personal Data Protection Act, 2023, you have the right to access, correct, and erase your personal data, to nominate a representative, and to grievance redressal.
Grievance Officer: AstraQ Cyber Defence, Engineers Colony Mothi Umari, Jatherpeth, Akola, Maharashtra, India 444005, contact@astraqcyberdefence.com. We acknowledge grievances within 72 hours and aim to resolve them within 15 days.
8. Children
The Service is not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction, to use Metis Mail. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
9. International transfers
Our processors may store or process data in countries other than yours (including the United States and the European Union). Where that happens, we rely on the processor's contractual and technical safeguards, and data remains protected as described in this policy.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app or by email before they take effect, and the effective date above will be updated. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
11. Governing law and contact
This policy is governed by the laws of India, and any disputes are subject to the exclusive jurisdiction of the courts at Akola, Maharashtra, India. Questions about this policy: contact@astraqcyberdefence.com.