Privacy policy
Last updated: 29 July 2026
Zewillow reads your work email to find promises — things you said you would do, and things other people said they would do for you. It keeps a short list of the ones still open, and shows you the exact sentence each one came from.
This page says exactly what we look at, what we keep, and how to get rid of it. It is written in plain English on purpose.
Who we are
Zewillow is a small independent product. It is built and run from California, United States, and it is responsible for the data described on this page. Write to hello@zewillow.com about anything here and a real person will answer.
What Zewillow never does
- It never sends email as you. It can write a draft, but you send it.
- It never deletes, moves, files, or marks anything read in your mailbox. Our access is read-only, because that is the only kind we ask for.
- It never joins your meetings. There is no bot.
- It never sells your data, and never shares it for advertising.
- It never uses your data to train AI models.
What we ask permission for
Microsoft Outlook
- User.Read — your name and email address, so we know whose account this is.
- Mail.Read — read-only access to your mail.
- offline_access — lets Zewillow keep reading in the background without asking you to sign in again every hour.
Google Gmail
- openid and userinfo.email — your email address.
- gmail.readonly — read-only access to your mail.
We do not ask for permission to send, delete, or change mail, because Zewillow does not do those things.
What we store
For each commitment we find and you keep:
- A short description of the promise.
- The exact sentence it came from — usually one line.
- The other person's name, as it appeared in the message.
- Any date or timing that was mentioned.
- Whether it is open, done, dismissed, or snoozed.
- Whether it came from email or from a transcript, and the identifier of the message it came from.
- If a later message appears to show the promise was kept, the one sentence that suggests so, until you confirm or decline it.
- When it was found.
And about you:
- Your email address and name, when you joined, and when you last used Zewillow.
- If you subscribe: a Stripe customer reference, your subscription status and its renewal date. We never see or store your card details — those go straight to Stripe and stay there.
- A random code for each browser you are signed in on. It expires after 30 days, or when you sign out.
- A connection token for each mailbox you connect. This is what lets Zewillow read your mail. It is removed the moment you disconnect or delete your account.
- A list of identifiers for messages already looked at, so the same message is not read twice. Identifiers only — no subjects, no content.
- If a digest we send you bounces, or is reported as spam, we record your address and the reason so we stop emailing you. Removed when you delete your account.
What we do not store
We do not keep your emails. While a scan is running, message text is held in memory only, and it is gone as soon as the scan finishes. The one piece of a message that survives is the short quote attached to a commitment you chose to keep — the sentence containing the promise.
Error logs
When something goes wrong, Zewillow writes the error to its server log so the fault can be found and fixed. An error message can occasionally carry a fragment of whatever was being handled at the time. Those logs sit with Render, are not read except when chasing a fault, and are discarded on Render's own short schedule.
Who else handles your data
Zewillow uses a small number of other companies to work at all. Each sees only what it needs to.
- Anthropic (United States) — the AI that reads a message and picks out promises. Message text is sent to Anthropic's API for that purpose. Anthropic does not use data sent through its API to train its models.
- Render (United States) — runs the app and holds the database.
- Stripe (United States) — takes payment. Your card details are entered on Stripe's own page and never pass through Zewillow. Stripe keeps its own billing records, which it is required to do and which we cannot delete on your behalf.
- Postmark (United States) — delivers your morning digest email. Your digest lists your open commitments and the sentence each one came from, so Postmark handles that text in order to deliver it. It goes only to your own address.
- Microsoft and Google — your own mail provider, read only, and only after you give permission.
We do not sell, rent, or trade your data with anybody.
Google user data
Zewillow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means Gmail data is used only to find commitments and show them to you. It is never used for advertising. It is never sold. It is passed on only to the service providers listed above, and only as far as running those features requires. No person at Zewillow reads your Gmail data, except where you specifically ask us to in order to fix a problem, where it is necessary for security, or where the law requires it.
How long we keep things
- Commitments — until you delete them, or delete your account.
- Message identifiers — until you delete your account.
- Sign-in codes — 30 days, or until you sign out.
- Mailbox connection tokens — until you disconnect, or delete your account.
- Error logs — held briefly by Render, then discarded.
- Database backups — encrypted, and they roll off within seven days.
Deleting everything
Sign in, open Account, and choose Delete my account. It removes, immediately and for good: every commitment including finished and dismissed ones, anything waiting in the review queue, every stored message identifier, your mailbox connection tokens, every sign-in code, and your account record itself.
Nothing is held back. The only remaining trace is inside encrypted database backups, which are overwritten within seven days.
If you would rather we did it, write to hello@zewillow.com and we will do it within 30 days.
Disconnecting without deleting
Open Account and choose Disconnect. That removes the connection token, so Zewillow stops reading your mail. Your saved commitments stay where they are.
You can also cut off access from your provider's own settings — Microsoft's My Account page, or Google's third-party app permissions page. Either works, and neither needs us.
Keeping it safe
- Everything travels over HTTPS.
- You sign in through Microsoft or Google. Zewillow never sees, receives, or stores your password.
- Sign-in cookies cannot be read by scripts in the page.
- Buttons in the digest email are signed, expire after 14 days, and can each do one thing to one item. Every one of them opens a page asking you to confirm, so a mail scanner following links cannot change anything.
No system is perfect. If you think something has gone wrong, please tell us at hello@zewillow.com.
Your rights
You can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Write to hello@zewillow.com. We do not charge for this and we do not treat you differently for asking.
Where your data lives
In the United States.
Children
Zewillow is for working adults. It is not intended for anyone under 18, and we do not knowingly collect anything from them.
Changes to this page
If we change it, the date at the top changes. If a change matters to you, we will email you before it takes effect.