Last updated: August 4, 2026
Postail ("Postail," "we," "us") is an Outlook add-in that drafts email replies, summarizes threads, adjusts tone, and detects bid deadlines using Claude, an AI model from Anthropic. Postail is operated by Tyler Gorman. This policy explains what data Postail accesses, where it goes, and what we store.
For its on-demand features (draft, summarize, bid check), Postail only reads the email message you are actively viewing when you click a Postail button. Specifically it reads:
Postail never modifies or sends the original message. Replies are composed through Outlook's own native reply window — you always review and send them yourself.
You can forward an email to a Postail address, such as bids@tgorman.com, to
have a deadline tracked. This requires no account and grants Postail no access to your
mailbox — it sees only the individual emails you forward, and nothing else in your account.
There is no sign-in, no permission, and therefore nothing to revoke.
What is stored: your email address, the subject line, and the details extracted from the message (general contractor, project name, scope, and deadline), plus the status you set by replying. The body of the forwarded email is not stored. It is read to extract those fields and then discarded.
Where the text goes: the forwarded message text is sent to Anthropic's Claude API to extract the deadline, under Anthropic's commercial API terms, which do not permit training on that data. It is not sent anywhere else.
What Postail sends: emails to you, at the address you forwarded from, and nowhere else. Postail does not contact general contractors, colleagues, or anyone whose address appears in a forwarded message.
Deleting your data: reply DELETE to any Postail email. Everything associated with your address is erased immediately — the tracked bids, the extracted details, and the address itself. No confirmation step and no waiting period. Reply STOP instead if you only want the reminders to end.
Because a forwarded email may contain another organisation's information, only forward what you are entitled to share with a third-party service.
If — and only if — you click "Connect mailbox" and approve Microsoft's consent screen, Postail additionally connects to your mailbox through Microsoft's own sign-in (Microsoft Graph) so it can work while the panel is closed. This powers automatic reminders: emails you sent that never received a reply, and approaching bid deadlines. With this connection Postail can:
Mail.Read)Mail.Send, used once reminder features are
enabled on your account)What we store for this feature: your email address, an encrypted sign-in token issued by Microsoft (encrypted at rest with a key held only in our backend; we never see or store your password), and sync timestamps. Message content read during a scheduled check is processed transiently and is not stored.
You can turn this off at any time with the Disconnect button in Postail's settings, which deletes the stored token immediately. You can also revoke Postail's access from your Microsoft account's app permissions page at any time — revocation on Microsoft's side takes effect on our next scheduled check.
When you use a Postail feature, the message content above is sent from the Outlook add-in to our backend (a Cloudflare Workers service), which forwards it to Anthropic's Claude API to generate the reply, summary, tone rewrite, or bid details. The two services that process your data are:
| Service | Role | What it receives |
|---|---|---|
| Cloudflare, Inc. (Workers) | Backend relay and request logging | Message subject/body/sender, in transit and in the audit log below |
| Anthropic PBC (Claude API) | Generates the AI output | Message subject/body/sender, sent per-request to produce a reply/summary |
No. Postail sends data to Anthropic under Anthropic's commercial API terms. Under those terms, Anthropic does not use inputs or outputs from commercial API traffic to train its models by default — see Anthropic's Privacy Center. We do not use your email content for any purpose other than generating the specific output you requested.
We keep a lightweight action log so we can diagnose issues and detect misuse of the service. Each entry records:
We do not store the message body, the AI-generated draft text, or any recipient list. This log is retained for as long as your license is active and is used solely for abuse detection, rate limiting, and support troubleshooting.
To request deletion of your action-log data, contact us at the address below. We will remove matching log entries within a reasonable time.
Postail is a business productivity tool and is not directed at, or intended for use by, children under 13.
We may update this policy as Postail changes. Material changes will be reflected by updating the "Last updated" date above.
Questions about this policy or a data deletion request: tgorman93@gmail.com