Skip to content

Privacy Policy for Spillway

Effective date: July 22, 2026
Status: Pre-alpha / invited testing

Spillway is the working name of an email organization application currently developed and, in some builds, displayed as EmailSorter (the “App”). The App is independently developed and operated by Josh Pasek. It is not a University of Michigan service and is not endorsed, operated, or supported by Google, Apple, Ollama, OpenAI, Anthropic, or any other third-party provider.

This policy explains how the App accesses, uses, stores, and shares information. Because the App is in pre-alpha testing, its features and this policy may change. Material changes will be reflected by a new effective date.

1. Summary

The App is designed to be local-first:

  • Mail and App-created organization data are primarily stored on the user’s own device.
  • Google OAuth tokens, API keys, and similar credentials are stored using Apple Keychain.
  • The operator does not run an App server that receives or stores users’ Gmail content.
  • The App does not sell personal information, use Gmail data for advertising, or operate its own behavioral advertising or analytics system.
  • Users may choose local AI through Ollama or explicitly configure a cloud AI provider. Cloud AI use sends selected email content to that provider.
  • Users control whether the App performs supported Gmail changes such as labeling, marking read or unread, starring, archiving, moving messages to Trash, managing drafts, or sending mail.

2. Information the App accesses

Google account and Gmail data

When a user connects a Google account, the App may access:

  • the account’s email address and basic account identity;
  • messages and threads, including senders, recipients, subject lines, headers, snippets, message bodies, dates, labels, and read/star/archive/Trash state;
  • attachments or attachment metadata when needed to display, analyze, download, draft, or send them;
  • Inbox, Sent, Draft, and related Gmail state needed for App features; and
  • provider identifiers needed to reconcile messages, threads, drafts, and user-directed actions.

The App requests Gmail permissions needed to read and organize mail and to perform user-controlled Gmail actions. The exact permissions appear on Google’s consent screen.

App-created data

The App creates local data such as:

  • categories and category hierarchy;
  • classifications, summaries, extracted requests, dates, opportunities, and other AI-derived information;
  • user corrections, filing decisions, workflow status, sender preferences, and Work Ledger items;
  • drafts, Outbox state, templates, and links to supporting messages;
  • settings, connection status, and limited operational metadata; and
  • local backups and recovery records when those features are used.

Credentials

OAuth tokens, AI-provider API keys, and client secrets are stored in Apple Keychain where supported. They are not intentionally included in ordinary data files, backups, diagnostics, or the source repository.

Information a user submits directly

If a user contacts the operator or submits beta feedback, the operator receives the information the user chooses to provide. Users should not submit email bodies, credentials, student/patient/client information, private links, or other sensitive content in feedback. Feedback may be stored using the communication or form provider used for the submission.

Website information

Visiting the App’s public web pages may cause the website host to receive ordinary request information such as IP address, browser type, requested page, and time of access. The App does not combine ordinary website logs with Gmail content. Any cookies or measurements present on the broader joshpasek.com website are governed by that site’s configuration and hosting providers.

3. How information is used

Google user data and App-created data are used only to provide or improve user-facing App functions, including:

  • displaying, searching, threading, and organizing mail;
  • classifying messages and extracting possible requests, commitments, dates, and opportunities;
  • learning from the user’s corrections on that user’s device;
  • performing actions the user initiates or enables;
  • creating, editing, scheduling, and sending drafts or messages;
  • supporting Calendar and Reminders actions the user reviews and confirms;
  • preventing duplication, recovering from interrupted operations, and protecting local data;
  • diagnosing errors using local, minimized diagnostics; and
  • responding to support or feedback that the user voluntarily submits.

The operator does not use Google user data to create advertising profiles, sell data, determine creditworthiness, or train a general-purpose AI model.

4. Local and cloud AI

Ollama or another configured local endpoint

When the user selects Ollama at a local address, inference requests are sent to the Ollama service configured by the user, normally on the same Mac. The operator does not receive those requests. A user who changes the endpoint to another computer or hosted service is directing data to that endpoint and is responsible for its security and policies.

Cloud AI providers

The user may explicitly configure OpenAI, Anthropic, or Google Gemini. When a cloud provider is enabled, the App sends selected message content and task instructions directly to that provider to perform the requested classification or extraction. The App shows a privacy acknowledgement before cloud AI is enabled.

The operator does not control a provider’s infrastructure or retention practices. The provider’s terms, privacy policy, account type, and data controls apply. Users should not enable cloud processing for information their employer, institution, client, or law does not permit them to send to that provider.

5. When information is shared

The App does not sell or rent personal information. Information leaves the device only in circumstances such as:

  • Google: to authenticate the user and read or modify Gmail as necessary for requested App functions;
  • User-selected AI providers: when the user enables cloud AI or configures a nonlocal inference endpoint;
  • Apple Calendar or Reminders: when the user asks the App to create or work with an item and grants the relevant system permission;
  • User-selected storage or sync locations: when the user enables a backup, export, or experimental folder-sync feature;
  • Outbound recipients and Gmail: when the user sends, schedules, or saves a draft;
  • Support/feedback services: when the user voluntarily submits information; or
  • Legal or safety needs: if disclosure is required by law or reasonably necessary to protect rights, safety, or the integrity of the service.

The App’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Human access to Gmail data by the operator is not part of ordinary App operation. The operator will access user-provided content only when the user deliberately supplies it for support, when necessary to address security or abuse, when required by law, or with the user’s explicit consent.

6. Storage and retention

Mail caches, App-created organization data, and settings are stored on the user’s device. Some files may contain sensitive message content in readable form. Users are responsible for protecting the device, operating-system account, and any copies or backups.

The App may create local recovery snapshots. Credentials are excluded. Cached message content is excluded from portable backups by default; if a user chooses to include it, the resulting backup may contain plaintext sensitive content.

Local data remains until it is removed through App controls, deleted by the user, removed with the App’s data container, or otherwise cleared by the operating system. Disconnecting Google access does not necessarily delete local backups or exported copies. Users should remove those separately.

Third-party providers retain data under their own policies. Deleting local App data does not delete source mail from Gmail unless the user separately performs a Gmail deletion action.

7. User choices and deletion

Users may:

  • decline or revoke Google access;
  • choose local AI, cloud AI, or no AI classification;
  • disable supported Gmail write-back controls;
  • remove connected accounts and local data using available App controls;
  • delete local backups and exported files; and
  • ask the operator to delete support or beta-feedback information associated with them, subject to legal or security retention needs.

Google access can be reviewed or revoked from the user’s Google Account security settings. Revoking access prevents new API access but does not itself remove local files or backups already created by the App.

8. Security

The App uses measures such as Apple Keychain for credentials, PKCE for supported OAuth flows, atomic local writes, validated recovery snapshots, and minimized diagnostics. No software or storage method is perfectly secure. The App remains pre-alpha software and should not be treated as institutionally approved or as satisfying FERPA, HIPAA, IRB, records-retention, or other legal requirements without an independent review.

9. Children

The App is intended for adults and is not directed to children under 13. The operator does not knowingly collect children’s personal information through an App-operated service.

10. International use

Users who access third-party services or cloud AI may cause information to be processed in countries other than their own. Those providers’ terms and privacy notices govern their processing.

11. Changes to this policy

This policy may be updated as the App changes. The updated policy will show a revised effective date. If a change materially expands how Gmail data is used or shared, users will be given appropriate notice or choice before the new use applies.

12. Contact

Questions, privacy requests, and deletion requests may be sent through the contact method published at joshpasek.com. Before public or expanded beta distribution, the OAuth consent screen should also list a monitored App-specific support address.