Privacy Policy

Last updated: August 2, 2026

This policy explains what information ENA processes, how it is used, and the choices you have over your data.

What ENA is

ENA is an email management workspace. It helps you organize the messages, contacts, documents, deadlines and follow-ups from a mailbox you choose to connect, so that important items are easier to find and act on.

Information you provide

  • Account details you enter when you sign up, such as your name, email address and password credentials handled by our authentication provider.
  • Content you create inside ENA, such as notes, tags, pinned items, follow-up dates and preferences.
  • Messages you send to us, for example a support request or product feedback.

Account information ENA may collect

  • Your account identifier, email address and display name.
  • Authentication events such as sign-in timestamps, used to keep your account secure.
  • Basic technical information such as browser, device type and app version, used for troubleshooting.

Google account and Gmail access

If you choose to sign in with Google, we receive basic profile information from Google in order to create and identify your ENA account. If you separately choose to connect a Gmail mailbox, ENA requests mailbox authorization from Google so that it can read and organize messages in ENA.

Signing in with Google and authorizing your Gmail mailbox are two separate permissions. Signing in with Google does not give ENA access to your mailbox. Mailbox access only begins after you complete the separate Gmail authorization step, and you can revoke it at any time.

Google User Data

ENA only accesses Google user data after you have granted permission through Google's own authorization process. That data is used solely to provide ENA's email management features to you — for example organizing messages into threads and categories, surfacing attachments and documents, extracting dates and follow-ups, and enabling search within your workspace.

ENA's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google user data for advertising, and we do not allow humans to read your data except where you explicitly ask us to (for example to resolve a support issue), where required for security purposes, or where required by law.

How ENA Uses Email Data

ENA does not access your Gmail mailbox automatically. ENA accesses Gmail data only after you select “Connect Gmail,” review Google's authorization screen, and grant the requested permissions.

ENA uses Gmail data only to provide visible, user-facing ENA features for the user who connected the mailbox. Depending on the features enabled and the permissions granted, these features may include:

  • Organizing messages and conversations.
  • Identifying important messages.
  • Identifying messages that may require a reply or other action.
  • Displaying email attachments and files.
  • Identifying bills, invoices, receipts, subscriptions, deliveries, contacts, dates and follow-ups contained in emails.
  • Generating personalized inbox summaries.
  • Allowing you to search your own mailbox information.
  • Allowing you to view and interact with your own messages and mailbox data through ENA.
  • Providing personalized email-management suggestions and insights.

ENA does not use Gmail data for unrelated purposes, advertising, credit decisions, data brokerage, surveillance, or features that have not been clearly disclosed to you.

Gmail data ENA accesses

ENA requests two Google permissions today: userinfo.email (your Google account email address) and gmail.readonly (read-only access to your Gmail messages). ENA cannot send, modify, label or delete mail in your mailbox.

Under those permissions, ENA's current implementation reads and imports:

  • The connected Google account's email address.
  • Gmail message identifiers and conversation/thread identifiers.
  • Sender name and sender email address, and Cc recipients.
  • Email subject lines.
  • The message date and timestamp.
  • Gmail labels and mailbox status (for example whether a message is unread or in the inbox).
  • The short Gmail-provided message preview (snippet), which ENA truncates to 280 characters and uses to categorize the message and to detect amounts, bills, receipts, subscriptions, deliveries and follow-up dates.
  • Attachment presence and basic attachment details (file name, file type and size) where Gmail returns them with the message metadata.

ENA requests messages from Gmail in metadata format. It does not download or store full email bodies, full HTML message content, or attachment file contents. Information ENA derives from the above — categories, priority, amounts, summaries, contacts, documents, calendar items, follow-ups and notes — is created by ENA and stored with your workspace.

Where Gmail data is stored

  • Imported Gmail metadata and everything ENA derives from it are stored in ENA's own application database.
  • That database is a managed PostgreSQL database hosted on Lovable Cloud (which runs on Supabase infrastructure). The ENA web application is hosted on Lovable's hosting platform.
  • Full email bodies are not stored. ENA only ever receives message metadata and the Gmail snippet; anything beyond that is never requested.
  • Attachment contents are not stored. ENA does not download attachment files.
  • Extracted information, summaries, classifications, amounts, contacts, follow-ups and notes derived from your email are stored in that same database, owned by your account.
  • Google OAuth access and refresh tokens are not stored by ENA. They are held by Lovable's encrypted connector gateway, which performs Gmail API calls on ENA's behalf. ENA stores only a per-user connection handle for that gateway, encrypted with AES-256-GCM before it is written to the database, and never exposed to the browser.
  • Every table holding your data enforces row-level security scoped to your account, so one account cannot read another account's records. Traffic is encrypted in transit (HTTPS/TLS), and access to production systems is limited to authorized personnel who need it.

No online service can guarantee absolute security, and you are responsible for keeping your own account credentials confidential.

How long Gmail data is retained

  • Imported Gmail metadata and snippets are retained until you delete them in ENA, remove imported email data, or delete your ENA account. ENA does not run a time-based purge of imported mail.
  • Attachment contents are never stored, so there is nothing to retain; attachment names and types follow the same lifetime as the message they belong to.
  • Summaries, categories, extracted amounts, contacts, follow-ups and notes are retained for the same period as the records they were derived from.
  • OAuth credentials are held by Lovable's connector gateway and are revoked when you disconnect Gmail or delete your ENA account. The encrypted connection handle stored by ENA is deleted at that moment.
  • Disconnecting Gmail stops future access but does not by itself delete data already imported; that data remains until you remove it or delete your account.
  • Deleted records are removed from ENA's active systems immediately, but routine encrypted infrastructure backups may still contain copies until those backups age out on the hosting provider's normal cycle.

Implementation detail pending review before publication: the exact maximum backup-retention window for the managed database has not yet been confirmed and stated here. This must be filled in with the hosting provider's actual backup-deletion period before this policy is published.

We may retain limited information for longer where it is necessary to comply with legal obligations, or to investigate and prevent fraud, abuse and security incidents.

Service providers

ENA relies on a small number of providers to operate. They may process Gmail-derived information only as necessary to provide their contracted services to ENA, under ENA's instructions.

  • Hosting: Lovable — serves the ENA web application and runs ENA's server-side code, which processes Gmail responses in memory.
  • Database: Lovable Cloud, running on Supabase managed PostgreSQL — stores imported Gmail metadata, derived information and your workspace records.
  • Authentication: the same managed platform provides account sign-in, including optional Google sign-in, and processes your email address and authentication events.
  • OAuth connection and token storage: Lovable's connector gateway — completes Google authorization, stores and refreshes your Google tokens, and proxies read-only Gmail API requests.
  • Google APIs: the source of the Gmail data you authorize ENA to read.
  • Support and feedback delivery: Formspree — receives only the name, email address and message content you submit through ENA's support and feedback forms, plus any file you choose to attach.
  • Error monitoring: Lovable's platform error reporting — receives technical error details from the app. ENA does not send email bodies or attachment contents to it.

ENA does not currently send Gmail content or derived information to any third-party artificial-intelligence provider: today's categorization, summaries and extraction run in ENA's own server code using rule-based logic. If ENA later enables an external AI provider for these features, that provider will be named here before the feature ships.

Human access to Gmail data

ENA personnel do not routinely read users' Gmail messages or attachments. Support staff cannot freely browse your mailbox.

Authorized personnel may access specific Gmail data only in limited circumstances:

  • When you give explicit permission for support personnel to review specific messages, files or related information.
  • When access is necessary to investigate a technical problem, a security incident, suspected abuse or fraud.
  • When access is legally required.
  • When information has been aggregated and anonymized for legitimate internal operations.

Any permitted access is limited to authorized personnel who need the information for the stated purpose, and only for as long as that purpose requires.

AI and Machine-Learning Use of Google User Data

ENA does not use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.

ENA may process an individual user's Gmail information with artificial intelligence to provide personalized features directly to that user, such as email summaries, message organization, action-item identification, date and follow-up extraction, attachment discovery, and personalized mailbox search and insights. Where an external AI provider is used for this, it processes the information only on ENA's behalf, under ENA's instructions, and only as needed to return the requested result — never to train its own models. As described under “Service providers,” ENA's current implementation performs this processing in its own server code and does not send Gmail information to an external AI provider.

One user's Gmail information is not used to train a model for other users, and is not used to improve generalized or non-personalized AI or machine-learning models.

  • Google Workspace data is not used to train models that serve other users or to create generalized AI or machine-learning products.
  • ENA does not sell Google Workspace data and does not provide it to third parties for advertising purposes.
  • Any service provider processing Google Workspace data on ENA's behalf may only process it under ENA's instructions and only as necessary to provide the requested service.

Limited Use compliance

ENA's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

ENA uses Google Workspace data only to provide or improve appropriate, visible, user-facing ENA features for the user who authorized access.

How information is used

  • To provide, operate and improve ENA's features.
  • To authenticate you and keep your workspace private to your account.
  • To respond to your support requests.
  • To detect, investigate and prevent abuse, fraud and security incidents.
  • To meet legal obligations.

ENA does not sell your personal information

We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing purposes.

Disconnecting Gmail and deleting data

What happens when Gmail is disconnected

  • ENA asks Lovable's connector gateway to remove the stored authorization for your mailbox, so ENA can no longer make Gmail API requests for it.
  • The encrypted connection handle ENA stored for you is deleted, and the mailbox is marked disconnected.
  • Future synchronization and importing from that mailbox stops immediately.
  • Disconnecting does not delete Gmail information that was already imported or generated before disconnection.
  • Disconnecting does not delete your ENA account.

To remove data already imported, use “Remove imported email data” in ENA's settings after disconnecting. That deletes the imported Gmail messages and derived records owned by your account from ENA's active systems. Full instructions are on the Data Deletion page. You can also revoke ENA's access from your Google Account security settings.

What happens when an ENA account is deleted

  • Your access to the ENA account is permanently removed and your session is invalidated.
  • Connected Gmail accounts are disconnected and ENA's authorization to make future Gmail API requests is revoked.
  • Deletion of Gmail data associated with the account begins, along with summaries, extracted information, follow-ups, attachment references, contacts, notes, preferences and other account data stored by ENA.
  • Records are removed from ENA's active systems as part of the deletion request, not on a delayed schedule.
  • Copies may remain in routine encrypted infrastructure backups until those backups age out.
  • Limited information may be retained where required for security, fraud prevention, legal compliance or resolving disputes.

Implementation detail pending review before publication: the maximum time for deleted information to disappear from infrastructure backups must be confirmed with the hosting provider and stated here before this policy is published.

Your rights and choices

  • Access, correct or update the information in your ENA account.
  • Disconnect a connected mailbox at any time.
  • Request deletion of imported email data or of your entire account.
  • Ask questions about how your information is handled.

Depending on where you live, you may have additional rights under local data protection law. We may need to verify your identity before acting on a request.

Children

ENA is not intended for use by anyone under 16 years of age.

Changes to this policy

We may update this policy as ENA evolves. When we do, we will change the "last updated" date at the top of this page.

Contact us

Questions about privacy can be sent through our Support page, which reaches the ENA team directly.