REVIEW-PENDING — this is an engineering starting draft, not legal advice. It is pending human legal review and sign-off before publication.
Privacy Policy
How Data Destroy accesses, uses, stores, and shares information — including data received through Google APIs.
Limited Use
Data Destroy’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only access the narrow, restricted scope described below, and we use that information solely to provide the feature you asked for.
How Google user data is accessed
Data Destroy requests the gmail.metadata scope only. This grants access to message headers and metadata — sender, recipient, subject, and dates. It does never grant access to message bodies, content, or attachments, and full-text search of your mailbox is not possible under this scope. Signing in with Google is a separate, narrower identity (OIDC) grant used only to authenticate you.
How the data is used
We use this metadata solely to detect which companies hold your data and to send and track data-deletion requests on your behalf. We do not use it for advertising, and we do not sell it.
How the data is stored
Your data is encrypted at rest using per-user envelope encryption: each account has its own wrapped data-encryption key. Access tokens, signed mandates, and inbound replies are encrypted under that key.
How the data is shared
We do not sell or share your data with third parties. Data leaves Data Destroy only as the deletion requests you authorize, sent to the specific companies you have named.
Deletion and purge
You can disconnect and purge your account at any time. Purge performs a crypto-shred: your per-user wrapped key is cleared, rendering all stored data — tokens, mandates, and inbound replies — permanently unreadable.
No third-party trackers
This site and the app load only same-origin resources. We use no third-party scripts, analytics, or externally hosted fonts.