Privacy Policy
Last updated July 15, 2026
This policy explains what information Senttri ("Senttri," "we," "us") collects when you use our unified-inbox service, why we collect it, and what control you have over it. It's written to describe what the product actually does, not boilerplate — if something here stops matching reality, treat the product as wrong and tell us.
Information we collect
Account information. Your name, email address, and password (stored as a salted hash — we never store or have access to your plaintext password), plus organization and team-membership details if you use Senttri with others.
Connected email account data. When you connect Gmail, Outlook/Microsoft 365, Yahoo, or iCloud, we store the messages in those accounts — including full subject lines, sender/recipient addresses, and full message body content (not just headers or previews) — so we can display, search, and categorize your mail. Attachment files are stored separately in encrypted cloud storage, keyed to your organization.
Authentication credentials.For Gmail and Outlook, we use OAuth — we receive a revocable access token, never your Google or Microsoft password. For Yahoo and iCloud, which don't support OAuth for mail access, we ask for an app-specific password (a credential you generate that is not your main account password); this is encrypted before storage and used only to sync mail via IMAP.
Open-tracking data.If you send a message with "Track opens" enabled, we log when the recipient's email client loads the message, along with the recipient's IP address and user-agent string, so we can show you an "opened" indicator. This is data about your recipient, not just you — see "Sending tracked email" below.
Billing information.Subscription payments are handled entirely by Stripe. Senttri never receives or stores your card number — we store only a Stripe customer/subscription reference so we know what plan you're on.
Usage and log data. Standard technical logs (IP address, browser type, timestamps, error traces) generated by using the app, retained for security and debugging.
How we use AI to categorize your mail
Senttri sorts incoming mail into Needs Reply, Action Items, FYI, and Newsletters using an AI classifier. To do this, we send the message's subject line, a short preview snippet, and up to the first 500 characters of the message body to our AI processing partner (currently Anthropic, for the Claude API) for classification. We do not send full message bodies, attachments, or your other account data for this purpose.
Our AI processing partner does not use data submitted through its commercial API to train its models, and we do not use the content of your email to train any AI model ourselves. If our AI processor becomes unavailable or a request fails, Senttri falls back to a simple local keyword-based classifier that never leaves our own servers.
Google API Services User Data Policy
Senttri's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We request Gmail access only to read, display, send, and label/categorize mail on your behalf inside Senttri — never for advertising, and never to sell your data to anyone.
How we store and protect data
- All traffic between your browser and Senttri is encrypted in transit (TLS).
- Our database and file storage run on Supabase infrastructure, which encrypts data at rest.
- OAuth tokens and IMAP app-passwords receive an additional layer of encryption (AES-256-GCM) at our application layer before they're ever written to the database — so even direct database access doesn't expose a usable credential.
- Access to your organization's data is enforced at the database level (row-level security), scoped to your organization's members — not just checked in application code.
See our Security page for more detail.
Data retention and deletion
Disconnecting an email account deletes its messages, attachments, and open-tracking data from Senttri, including the underlying attachment files in storage — not just the connection itself. Deleting your organization deletes all associated data. Some information may be retained briefly in backups or logs for security and legal-compliance purposes before it is purged on our normal retention schedule.
Who we share data with
We don't sell your data. We share data only with the service providers needed to run Senttri, each bound by their own privacy/data-processing terms:
- Supabase — database, authentication, and file storage.
- Anthropic — AI mail classification (see above).
- Stripe — payment processing.
- Google / Microsoft — OAuth connections to Gmail and Outlook/Microsoft 365, as you authorize.
- hCaptcha (Intuition Machines) — bot/abuse protection on sign-up and login.
- Vercel — application hosting.
Your choices
- Disconnect any connected email account at any time from Settings.
- Turn off "Track opens" per message in Compose, or leave it unchecked by default.
- Request a copy of, or deletion of, your data by contacting us (below).
- Delete your account and organization at any time from Settings.
Children's privacy
Senttri is a business productivity tool and is not directed to, or knowingly used by, children under 16.
Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page and, where appropriate, notify account admins directly.
Contact us
Questions about this policy or requests about your data: privacy@senttri.com.