Last updated: August 4, 2026
Postail ("Postail," "we," "us") is an Outlook add-in that drafts email replies, summarizes threads, adjusts tone, and detects bid deadlines using Claude, an AI model from Anthropic. Postail is operated by Tyler Gorman. This policy explains what data Postail accesses, where it goes, and what we store.
For its on-demand features (draft, summarize, bid check), Postail only reads the email message you are actively viewing when you click a Postail button. Specifically it reads:
Postail never modifies or sends the original message. Replies are composed through Outlook's own native reply window — you always review and send them yourself.
You can forward an email to a Postail address, such as bids@postail.app, to
have a deadline tracked. This requires no account and grants Postail no access to your
mailbox — it sees only the individual emails you forward, and nothing else in your account.
There is no sign-in, no permission, and therefore nothing to revoke.
What is stored: your email address, the subject line, and the details extracted from the message (general contractor, project name, scope, and deadline), plus the status you set by replying. The body of the forwarded email is not stored. It is read to extract those fields and then discarded.
Where the text goes: the forwarded message text is sent to Anthropic's Claude API to extract the deadline, under Anthropic's commercial API terms, which do not permit training on that data. It is not sent anywhere else.
What Postail sends: emails to you, at the address you forwarded from, and nowhere else. Postail does not contact general contractors, colleagues, or anyone whose address appears in a forwarded message.
Deleting your data: reply DELETE to any Postail email. Postail replies with a list of exactly what would be erased and deletes nothing yet; reply DELETE CONFIRM and everything associated with your address goes immediately — the tracked bids, the extracted details, the address itself, your timezone, and any hub sign-in. There is no waiting period and no backup is kept, so it cannot be undone.
The confirming step exists because erasure is the one thing here that cannot be reversed, and a single word typed at the wrong email should not be able to destroy a bid board. If you do nothing, the request expires within an hour and nothing is removed. Any other reply cancels it. Reply STOP instead if you only want the reminders to end.
Because a forwarded email may contain another organisation's information, only forward what you are entitled to share with a third-party service.
If — and only if — you click "Connect mailbox" and approve Microsoft's consent screen, Postail additionally connects to your mailbox through Microsoft's own sign-in (Microsoft Graph) so it can work while the panel is closed. This powers automatic reminders: emails you sent that never received a reply, and approaching bid deadlines. With this connection Postail can:
Mail.Read)Mail.Send, used once reminder features are
enabled on your account)What we store for this feature: your email address, an encrypted sign-in token issued by Microsoft (encrypted at rest with a key held only in our backend; we never see or store your password), and sync timestamps. Message content read during a scheduled check is processed transiently and is not stored.
You can turn this off at any time with the Disconnect button in Postail's settings, which deletes the stored token immediately. You can also revoke Postail's access from your Microsoft account's app permissions page at any time — revocation on Microsoft's side takes effect on our next scheduled check.
When you use a Postail feature, the message content above is sent from the Outlook add-in to our backend (a Cloudflare Workers service), which forwards it to Anthropic's Claude API to generate the reply, summary, tone rewrite, or bid details. The two services that process your data are:
| Service | Role | What it receives |
|---|---|---|
| Cloudflare, Inc. (Workers) | Backend relay and request logging | Message subject/body/sender, in transit and in the audit log below |
| Anthropic PBC (Claude API) | Generates the AI output | Message subject/body/sender, sent per-request to produce a reply/summary |
No. Postail sends data to Anthropic under Anthropic's commercial API terms. Under those terms, Anthropic does not use inputs or outputs from commercial API traffic to train its models by default — see Anthropic's Privacy Center. We do not use your email content for any purpose other than generating the specific output you requested.
We keep a lightweight action log so we can diagnose issues and detect misuse of the service. Each entry records:
We do not store the message body, the AI-generated draft text, or any recipient list. Entries are automatically deleted after 90 days and are used solely for abuse detection, rate limiting, and support troubleshooting.
If you use the forwarding address: reply DELETE to any Postail email to see exactly what is stored, then DELETE CONFIRM to erase it. Everything tied to your address goes — your tracked bids, the extracted details, the address itself, your timezone, any hub sign-in, and the internal counters keyed to it. No waiting period, and nothing is retained afterwards.
If you use the Outlook add-in: the action log described above deletes itself after 90 days. To have your entries removed sooner, email the address below and they will be deleted.
If you connected your mailbox: use Disconnect in Postail's settings. The stored sign-in token is deleted immediately. You can also revoke Postail's access from your Microsoft account's app permissions page.
Postail is a business productivity tool and is not directed at, or intended for use by, children under 13.
We may update this policy as Postail changes. Material changes will be reflected by updating the "Last updated" date above.
Questions about this policy or a data deletion request: support@postail.app