Skip to content

Privacy Policy

Last updated: August 7, 2026

Placeholder text — pending legal review. This is a temporary, interim policy written for Bevel AI's pre-launch, tester-stage website. It has not been reviewed by a lawyer. It will be replaced with a counsel-reviewed policy before any public beta or general release. Bracketed text marks details (such as the legal entity name) that are still being finalized.

1. Who operates this site, and its current legal status

Bevel AI is, at this stage, a pre-launch, early-stage software project built and operated by an individual developer. No company has been incorporated yet. Until a corporate entity is formed, "we," "us," "our," and "the Operator" in this policy refer to that individual, doing business under the name "Bevel AI" (legal entity name: to be determined). This website is currently an informational and tester-recruitment site — see /download, which confirms there are no public installers yet.

If and when a company is incorporated to operate Bevel AI, this policy will be updated to name that entity, and your rights under this policy will transfer to it as the successor operator, consistent with the section on changes to this policy below.

2. Scope of this policy

This policy covers two separate things, because they behave very differently:

  • This marketing website (the pages you are browsing now, at this domain).
  • The Bevel AI desktop application, if and when you install it as an early tester — a local-first, single-user desktop program with no hosted backend today.

There is currently no Bevel AI cloud account, no hosted sync service, and no server that stores your messages on our behalf. If that changes, it will be covered by a dedicated, separately published policy before it launches, as described in Section 10.

3. Information this website collects

  • Standard web server logs at our hosting/CDN provider (IP address, browser type, requested page, timestamp), kept only as long as the provider's default operational logging retains them.
  • Two font files loaded from Google Fonts (fonts.googleapis.com and fonts.gstatic.com) so the site renders with its chosen typefaces. Loading these files discloses your IP address and browser information to Google, the same as loading a font from any other third-party server.
  • Hero and feature images and video loaded from external media hosts, used only to serve that visual content. Loading them discloses your IP address to those hosts the same way any embedded image or video would.

This website deliberately does not do the following:

  • No accounts, sign-ups, or logins on this website.
  • No analytics or telemetry scripts (no Google Analytics, no Meta Pixel, no PostHog, no session recording).
  • No advertising cookies, retargeting pixels, or cross-site tracking of any kind.

4. The early-access waitlist field

This site includes an email-only waitlist field (on the homepage and /download). Today, no backend is connected to it — what you type stays in your browser and is not transmitted, received, or stored anywhere, and submitting it currently returns an honest "not connected yet" message rather than a real confirmation. Before a real signup service is wired up, this policy will be updated first to disclose exactly what's collected, why, who processes it, and how to unsubscribe — that disclosure has to exist before the field goes live, not after.

5. Information the desktop app stores locally

If you install the app as an early tester, the following is stored only on your own device:

  • Your messages and attachments, in a database on your device protected with AES-128-XTS full-database encryption.
  • A local search index, built and stored on your device.
  • Your app settings and connected-account metadata.
  • Account tokens and encryption keys, held in your operating system's credential store (Windows Credential Manager, macOS Keychain, or a Linux Secret Service keyring).

6. Information that never leaves your device

  • Message content. Reading, searching, and organizing happen entirely on your computer.
  • Your encryption keys and account tokens.
  • Your search queries and reading habits.

The only network traffic the app generates is directly between your device and the messaging providers you connect, through their official APIs. We do not sit in the middle of that connection, and we do not receive a copy.

7. Connected providers, and the Google API Limited Use disclosure

The app connects to messaging providers you choose to authorize (currently Gmail and Microsoft Outlook/Graph), using each provider's official OAuth flow and official API. Your use of each connected account remains subject to that provider's own terms and privacy policy. We only request the minimum access scopes needed for the features visible in the app.

Bevel AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: data from your Gmail account is used only to provide and improve the user-facing inbox features you can see in the app, is never used to serve advertising, is never sold, and is never used to train generalized AI or machine-learning models. The same standard applies to data accessed via Microsoft Graph.

8. What we don't do

  • No advertising, and no sale or sharing of personal data for cross-context behavioral advertising. Ever.
  • No scraping or unofficial access to messaging providers — only official, authorized provider APIs.
  • No use of your message content to train any AI or machine-learning model, by us or by anyone we work with.
  • No sharing of your message content with third parties except the messaging providers you explicitly connect, through their own official APIs, and only to the extent needed to sync your own account.

9. Data retention

Website server logs are retained only as long as our hosting/CDN provider's default operational window. App data lives entirely on your device, for as long as you keep the app installed; uninstalling the app and deleting its local database removes it. If you contact us directly (for example, by email), we keep that correspondence only as long as needed to respond and to maintain a basic record of tester communications.

10. A future, optional hosted service

We may offer a managed sync service later, for people who want their local inboxes kept in step across devices. If it ships, it will be strictly optional, off by default, encrypted wherever the architecture allows, and covered by its own dedicated privacy terms — published and presented for your review before you could ever opt in. The local-first product will keep working without it.

11. Your rights

Depending on where you live, you may have some or all of the following rights over personal information we hold about you (which, given the local-first design above, is generally limited to whatever you've directly sent us, such as a support email):

  • Access — ask what personal information, if any, we hold about you.
  • Correction — ask us to correct inaccurate information.
  • Deletion — ask us to delete personal information we hold about you.
  • Portability — ask for a copy of information you provided to us, in a portable format.
  • Objection / opt-out — object to a specific processing activity, where applicable.

As a pre-launch project, we don't yet have automated tooling for these requests — but we will honor them manually, on request, to the email address in Section 16.

12. Children's privacy

This website and the app are not directed to, and are not intended for use by, children under 13 (or the minimum age required by your local law to consent to data processing without parental consent). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

13. International use

This website may be hosted or served from infrastructure located in a different country than yours, which can mean the limited website data described in Section 3 is processed there. Because the app itself stores your message data only on your own device, there is no cross-border transfer of your message content by us to worry about.

14. Security

The app's local database is protected with AES-128-XTS full-database encryption, and account tokens and encryption keys are held in your operating system's credential store rather than in plaintext files. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security — see the disclaimers in our Terms of Service. Full technical detail lives on the Security page.

15. Changes to this policy

We may update this policy as the product changes — most importantly, as it moves from "tester website" toward a real public release, and if/when a company is incorporated to operate it. We'll update the "Last updated" date above when we do. If a change is material, we'll make reasonable efforts to flag it prominently on this site before it takes effect. If you disagree with an update, your remedy is to stop using the website and the app.

16. Contact

Questions about this policy, or a request under Section 11, can be sent to [privacy contact address to be published — placeholder]. Until a dedicated address is live, treat this page as our current, good-faith statement of practice rather than a fully finalized legal document.