Privacy
Privacy Policy
Last updated June 1, 2026
Sortcery is a free Gmail-sorting demo from Aprendio LLC. This page tells you exactly what we do with your data, in the same plain English we use everywhere else in the product.
1.What we collect
- Your Google account basics — name, email address, profile picture, and a Gmail access token. We get these from Google when you sign in.
- Email metadata, not bodies — for each message we sort, we read the sender, subject, snippet (the first ~140 characters Gmail returns), and label state. We do not store email bodies. The reading-pane preview is fetched on-demand and lives only in your browser.
- Your corrections — when you reclassify a message, we save the sender + subject + snippet + the category you picked so Sortcery learns your preferences.
- Your settings — label renames, sort rules, schedule, and the system prompt your auto-tune has converged on.
- Run history — a row per sort (when, how many emails, how many applied, error count) so the History view can show you what happened.
- The email address you give us for a conference code — separate from your Google account, used only to email you the offer code.
- Standard server logs — IP address, request path, timestamp. Kept for security and debugging, rotated regularly.
2.What we don't collect
- Email bodies — they stay in your browser.
- Your Google password — Google handles authentication; we never see it.
- Payment information — Sortcery is free during the trial window.
- Contact lists, calendars, drive files, or anything outside the Gmail scope you grant.
3.What we send to AI providers
Sortcery's whole job is to ask an AI model to classify each email. To do that, we send the model the sender, subject, and snippet, plus a handful of your prior corrections as in-context examples. We do not send email bodies.
Our current classifier is Anthropic's Claude Haiku 4.5 via OpenRouter. The tuner that periodically revises your rules uses Anthropic's Claude Sonnet 4.6, also via OpenRouter, with Anthropic's API as a fallback. When you send data to Sortcery, you're also sending it through these vendors, and their handling is governed by their terms:
If we change classifier providers, we'll update this section. If you'd rather route classifications through your own local AI instead, switch to MCP-direct mode in Settings — the email metadata then flows through your own Claude install and never touches our cloud.
4.Who else gets your data
We share only with the vendors below, and only the minimum each needs to do its job. Aprendio LLC does not sell your data.
- Google — authenticates you and gives us read/label access to your Gmail (Privacy).
- OpenRouter + Anthropic — receives email metadata for classification (see §3).
- Resend — sends the conference offer code email when you claim one (Privacy). Sortcery itself never sends mail; see §6.
- Our hosting — Sortcery runs on Aprendio LLC's own server infrastructure. Your data is not in third-party Supabase or any other managed database service.
5.Marketing communications
By signing in to Sortcery, you agree we may occasionally email you about other Aprendio services — done-for-you AI work, new tools, and the conference giveaways we run. Frequency is low (a few times a year, not weekly).
Every marketing email includes a one-click unsubscribe link that opts you out immediately. Unsubscribing has no effect on your Sortcery account or transactional emails (offer codes, account notifications).
6.The no-send guarantee
Sortcery's whole reason for using Gmail is to read messages and apply labels. It cannot send mail on your behalf — that's enforced in code, not just promised in policy. Every outbound call to the Gmail API is checked against an allowlist that refuses any send- or draft-shaped request before it leaves our server.
7.How long we keep your data
We retain your preferences, rules, corrections, and run history for as long as your account exists. You can wipe all of it at any time:
- Settings → Data → Export downloads a JSON copy of everything we have.
- Settings → Data → Reset everything deletes your preferences, rules, corrections, examples, and tokens.
- Email privacy@aprendio.ai for a full account deletion, and we'll also revoke our Google OAuth grant on your behalf.
Server logs roll over within 30 days. Backups are retained for up to 30 days before being overwritten.
8.Your rights
Depending on where you live, you may have legal rights including: knowing what we hold about you, getting a copy, correcting it, deleting it, and opting out of marketing. Use the Settings controls above, or email privacy@aprendio.ai and we'll handle it within 30 days.
You can also revoke Sortcery's access to your Gmail directly from your Google account permissions page at any time. That immediately stops all classification and label changes.
9.Cookies and sessions
We use a small set of session cookies to keep you signed in. We don't use third-party analytics, advertising, or tracking cookies. The only cookies Sortcery sets are the ones our auth system (Supabase GoTrue, self-hosted on Aprendio's infrastructure) needs to recognize you on the next page load.
10.Security
Connections are TLS 1.2/1.3 only. Your stored data lives on an Aprendio-controlled Postgres database behind row-level security policies that block one user from reading another's data. We rotate Google OAuth refresh tokens, scope-limit our Gmail access to gmail.modify (read + label, never send), and audit every Gmail API path through an allowlist.
11.Children
Sortcery isn't directed at anyone under 16, and we don't knowingly collect data from minors. If you believe a minor has signed up, email privacy@aprendio.ai and we'll delete the account.
12.Changes to this policy
We may revise this policy as Sortcery evolves. Material changes will be announced via in-app notice or email at least two weeks before they take effect. The "Last updated" date at the top of this page always reflects the current version.
13.Contact
Aprendio LLC is the data controller for Sortcery. Reach us at privacy@aprendio.ai. We respond to privacy requests within 30 days.