Gimble Privacy Policy

Effective August 26, 2026

This Privacy Policy describes how Gimble LLC (“Gimble,” “we,” “us,” or “our”) collects, uses, and shares information when you use the Gimble application (the “Service”). Gimble is a Delaware limited liability company with its principal place of business at 1571 S 2000 E, SLC, UT 84108.

By using the Service, you agree to the practices described in this Privacy Policy.

1. What Gimble Does

Gimble connects to your Gmail account, with your consent, to identify which companies hold an account associated with your email address. Using your email metadata, Gimble builds a categorized inventory of those accounts. On top of that inventory, optional features can extract specific details from certain messages, including loyalty program balances, insurance policy information, subscription pricing, travel bookings, and a dated record of orders.

Gimble’s core design principle is derivation, not storage of mail. Gimble reads email to produce structured facts about your accounts and commitments. Your email content is never stored by Gimble.

2. Gmail Permissions and Progressive Consent

Gimble requests Gmail permissions progressively, only when a feature requires them, rather than all at once at sign-up. Most users hold only the first permission below.

2.1 Permissions We Request

  • Email Metadata (gmail.metadata): Requested when you first connect your Gmail. Allows Gimble to read message headers (sender, date, subject line) to identify which companies hold an account for you. No message body is accessible under this permission.
  • Gmail Read-Only (gmail.readonly): Requested the first time you ask Gimble to organize your Life view, or to fill in a loyalty balance, subscription price or renewal date. Those details sit inside the message rather than in its subject line, so reading them needs more than metadata. This permission cannot change anything in your mailbox.
  • Gmail Settings (gmail.settings.basic): Requested the first time you mute a company. Allows Gimble to create a Gmail filter that routes that company’s future mail out of your inbox.
  • Gmail Labels (gmail.labels): Requested alongside the settings permission above. Allows Gimble to create the label the filter files mail under.
  • Gmail Modify (gmail.modify): Requested the first time you opt into a backlog sweep or an inbox clean-up. Allows Gimble to move already-received mail out of your inbox and back again if you undo it. Nothing narrower can do this: a Gmail filter only acts on mail as it arrives and cannot touch a message already sitting in your inbox. This permission is never used to send, compose, or delete mail.

2.2 Permissions We Never Request

Gimble never requests gmail.compose, gmail.send, or full mail access. We are being precise here rather than reassuring: gmail.modify, which Gimble requests only for archiving, does technically permit sending and drafting mail — Google’s own consent screen says “Read, compose, and send emails from your Gmail account.” Gimble never uses that capability. No part of the Service sends, drafts, or composes a message, and where it helps you write to an insurance broker it opens a compose window that you send yourself. Gimble also never deletes mail: the only change it makes to your mailbox is moving a message out of the inbox under a Gimble label, which you can undo.

2.3 How Muting and Cleanup Work

Muting and cleanup archive mail: messages are moved out of your inbox under a label and remain in your mailbox. Nothing is ever deleted or trashed.

3. Information We Read, Store, and Transmit

3.1 Information We Read

  • Always: message headers (sender, date, subject line).
  • For sampled messages (when you opt into the deeper scan): the subject line, preheader, and body, processed transiently in memory.
  • For insurance-related mail: the text content of PDF attachments from companies already identified as your insurer or broker.

3.2 Information We Store

Gimble stores only derived data fields, never raw email content. Email bodies, preheaders, and attachment text are never written to any database. The data model has no field capable of holding raw message content, and this guarantee is structural.

Subject lines are written to a temporary working table during a scan for classification purposes. They are never displayed to you and are automatically deleted when the scan completes.

The derived fields Gimble stores are:

  • Company identity and classification: the company name, its category and subcategory, confidence scores, classification verdicts, dormancy status, and public breach matches.
  • Loyalty program information: member numbers, tier status, expiry dates, and point or mile balances.
  • Insurance policy information: carrier, policy line, policy number, premium amounts, and a dated premium history. Where your insurer or broker sends a policy document, Gimble also stores what that document states about the policy: the cover limits, deductibles and premiums on its schedule, the term it runs for, the NAIC code, the address on the policy, and the year, make and model of a covered vehicle. Each carries the date of the document it was read from. Gimble never stores the vehicle identification number, the dates of birth, the past claims, or the mortgage or lienholder account number that the same document prints — no field in the data model exists for any of these.
  • Subscription information: what a service charges, how often, when it renews, a dated price history, and a payment channel label (e.g., “PayPal” or “card”). Payment channel labels are truncated before their first digit so that card numbers, including the last four digits, can never be stored.
  • Order history (approximately two years): per order, the merchant, date, total charged, whether it was cancelled or returned, and a link to the sender’s own page for it. Gimble never stores what was purchased: no item descriptions, SKUs, product categories, or similar details. No field in the data model exists for item-level order contents.
  • Travel bookings (approximately one year): per booking, the type of travel, date range, city, and cost. Gimble never stores booking references, record locators, e-ticket numbers, seats, fare classes, or the names of other travelers. No field in the data model exists for any of these.
  • Breach data: public breach metadata from Have I Been Pwned, matched by domain. No password or credential of yours is involved.

3.3 Information We Never Extract or Store

The following categories of information are never extracted from your email, and no field exists in Gimble’s data model to hold them:

  • Card numbers, including the last four digits
  • Loan and bank account numbers
  • Credit scores and statement balances
  • Booking references and record locators
  • Names of other people, including other drivers on a policy
  • Seats and fare classes
  • Item-level contents of any order

3.4 Information We Transmit to Our AI Sub-Processor

For sampled messages, the subject line, preheader, body, and attachment text are sent to Anthropic’s Claude API for classification and extraction. This content is deleted by Anthropic within thirty days and is never used to train Anthropic’s models, under Anthropic’s standard commercial API terms. Gimble itself persists none of it.

Your Google user data is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. Our AI sub-processor’s commercial terms prohibit Anthropic from using API inputs to train its models.

4. No Human Review of Email Content

No Gimble personnel read your Google user data, except:

  • With your explicit consent;
  • As necessary to investigate a security incident; or
  • As required by applicable law or legal process.

5. Google API Services User Data Policy

Gimble’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Service Providers and Sub-Processors

Gimble shares information with the following service providers to operate the Service:

ProviderInformation ReceivedPurpose
Google (Gmail API, Cloud Pub/Sub)Mailbox change notificationsSource of email data; push notifications that new mail has arrived
AnthropicSubject, preheader, body, and attachment text of sampled messagesAI classification and extraction
SupabaseAll stored derived data; Gmail tokens encrypted in VaultDatabase, authentication, and secret storage
VercelRequest dataApplication hosting
RailwayRequest dataBackground scan worker
ResendEmail addressWeekly digest delivery
PostHogUser ID and event properties (feature names, scopes granted, program keys); no email contentProduct analytics
Have I Been PwnedYour connected email addressPublic breach-corpus lookup
DuffelFor flight repricing: two airport codes, one or two dates, “one adult.” For hotel search: latitude/longitude, radius, two dates, room and guest countsRepricing booked flights and finding hotel rooms for dates bracketed by flights

7. Data Retention

Derived data persists in your account for as long as your Gmail connection is active. There is no automatic expiry. You control your data through the disconnect and delete actions described in Section 8.

Data that has been deleted through disconnect or account deletion may persist in encrypted backups for up to seven days, after which it is permanently removed.

Content transmitted to Anthropic for classification is deleted by Anthropic within thirty days under Anthropic’s standard commercial API terms.

8. Your Choices: Disconnect and Delete

8.1 Disconnect Gmail

You can disconnect your Gmail account at any time from within the Service. Disconnecting:

  • Revokes Gimble’s access to your Gmail at Google
  • Deletes your Gmail access tokens from our encrypted secret store
  • Deletes all data derived from your mailbox, including account inventory, insurance policies, loyalty memberships, subscriptions, orders, travel bookings, scan records, and email digests

Your Gimble user account remains active after disconnecting. Disconnecting stops scanning; it does not delete your Gimble account.

8.2 Delete Your Account

You can delete your Gimble account at any time from within the Service. Deleting your account performs the same data removal as disconnecting your Gmail, and additionally deletes your user record. Account deletion is completed immediately.

Both actions revoke your Google grant before deleting tokens and remove encrypted secrets before the database rows that reference them, so no live credential can be stranded.

9. Security

Gimble protects your data using the following measures:

  • OAuth access and refresh tokens are stored in Supabase Vault, an encrypted secret store, not in application database tables.
  • Row-level security is enforced at the database layer so that each user can access only their own data.
  • Email content is processed transiently and never persisted.
  • All connections use HTTPS/TLS encryption in transit.

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You may request that we delete the personal information we have collected about you, subject to certain exceptions.
  • Right to Correct: You may request that we correct inaccurate personal information we maintain about you.
  • Right to Opt-Out of Sale or Sharing: Gimble does not sell your personal information. Gimble does not share your personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at privacy@gimble.app. We will respond to verifiable requests within thirty days.

11. Children’s Privacy

The Service is not directed to individuals under the age of 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete that information promptly. If you believe we have collected information from a person under 18, please contact us at privacy@gimble.app.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting a notice within the Service. The “Effective Date” at the top of this policy indicates when it was last revised.

13. Governing Law

This Privacy Policy is governed by the laws of the State of Delaware, without regard to its conflict of laws principles.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

Gimble LLC
1571 S 2000 E
SLC, UT 84108
privacy@gimble.app