Privacy Policy

Last updated 26 July 2026

Shopping Manager helps you see what you already own and what you spend. To do that it can, with your permission, read purchase-related messages in your email. This page explains exactly what it reads, what it keeps, and what it never keeps.

Who we are

Shopping Manager is operated by [TODO: legal entity name]. You can reach us at [TODO: contact email].

Google user data we access

If you choose to connect a Gmail account, we request the https://www.googleapis.com/auth/gmail.readonly scope. This is a restricted scope and it is read-only: we can never send, modify, or delete anything in your mailbox.

We use it for one purpose only:

  • To find messages that are order confirmations, shipping and delivery notices, cancellations, and return or refund confirmations, and to extract the purchase details from them.

To limit what we look at, we do not download your mailbox. We ask Google for messages matching a narrow search — purchase-related subject lines and sender patterns, within the time window you choose when connecting (30 days to 2 years, 180 days by default).

What we store

From messages that turn out to be purchases, we keep the structured facts:

  • Merchant, order number, order date, and currency
  • Line items: product name, variant, quantity, and price
  • Subtotal, tax, shipping, discount, and total
  • Shipment status, tracking numbers, and delivery dates
  • Return and refund status and refunded amounts
  • The message identifier, its subject line, and the sender address, so we can show you where an order came from and correct it if we read it wrong

What we never store

  • The body of any email. Message content is held in memory only while a message is being read, and is never written to our database, our logs, or our error reports.
  • Anything about your unrelated mail. Most messages we look at turn out not to be purchases. For those we record only the message identifier and the date, so we know to skip the message next time. We do not keep the subject line or the sender. This is enforced by a constraint in our database, not by convention.
  • Attachments, contacts, or calendar data.

Automated processing

To read a purchase email we may send the message text to a large language model provider, which returns the structured order details. We send only what is needed to read that one message, we do not send your identity along with it, and we disable provider-side retention where the provider supports it. The provider does not use this content to train models.

How your data is protected

  • The tokens that let us read your mailbox are encrypted before they are stored, with a key held separately from the database.
  • All traffic is encrypted in transit.
  • Every record is tied to your account and isolated at the database level, so one user’s data cannot be read by another. We test this automatically on every change.
  • Access to production systems is limited to what is needed to operate the service.

Sharing

We do not sell your data, and we do not share it for advertising. We use a small number of service providers to run the service — hosting, database, background job processing, and the language model provider described above — and they may process data only on our instructions.

Your choices

  • You never have to connect an inbox. The app works with orders you add by hand.
  • Disconnect at any time, from Settings. Doing so revokes our access token with Google immediately and deletes the data we imported from that account.
  • You can also revoke our access directly at myaccount.google.com/permissions.
  • Delete your account, from Settings. This revokes any Google tokens, removes every record we hold about you, and cannot be undone.

Retention

We keep your purchase records until you delete them or delete your account. Message identifiers for messages we skipped are kept so that re-syncing does not re-examine them, and are deleted when you disconnect the account they belong to.

Limited Use

Shopping Manager’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Changes

If we change how we handle your data we will update this page and the date at the top.

Terms of Service