Last updated: August 2, 2026
Security
A plain-language overview of how pithie protects account and Google user data. Details on Google data handling are in the Privacy Policy.
Encryption
Traffic to pithie APIs and apps uses TLS in transit. Application data, including OAuth tokens and synced mail content stored in our database, is encrypted at rest by our hosting infrastructure.
Access controls
Users authenticate through Clerk. API access to mail data requires a signed-in session for the owning account. Google OAuth tokens are stored server-side and used only by pithie systems to sync mail and apply label changes you initiate. Administrative and production access is limited to authorized personnel who need it to operate or secure the service. Personnel do not read Google user data except as described in the Privacy Policy.
Hosting
pithie production services (API, web app, and marketing site) are hosted on managed cloud infrastructure. Supporting services include a managed database, Redis cache, and Google Cloud Pub/Sub for Gmail sync and mail-processing jobs.
Data retention
Synced Google mail and OAuth credentials are retained while the Google account remains connected and the pithie account is active. Disconnecting Google or deleting your account removes that data from primary systems as described on the deletion page. Short-lived backups may persist briefly before expiring.
Incident response
If we become aware of a security incident affecting personal data, we investigate, contain the issue, and notify affected users and regulators when required by law. Report suspected security issues to security@gropple.co or support@gropple.co.
Your responsibilities
- Keep your sign-in method secure and sign out on shared devices
- Connect only Google accounts you are authorized to access
- Disconnect Google or delete your account when you no longer need pithie