Legal
Privacy policy
Effective
Who operates Sortae
Sortae (“Sortae,” “we,” “us”) operates the Sortae service. Questions and privacy requests can be sent to privacy@sortae.com. General support is available at support@sortae.com.
Data we receive
If you join the waitlist, we receive your normalized email address, the signup source, the policy consent version, and timestamps. For abuse prevention, we create short-lived keyed fingerprints from the trustworthy network address and a normalized browser user-agent. We do not store the raw network address or user-agent.
If an invited user chooses to connect Google, Sortae requests profile identity plus read-only Gmail and Google Calendar scopes. Gmail access is limited to reading messages and metadata. Calendar access is limited to the connected account’s primary calendar. Sortae cannot send, edit, or delete Gmail messages or Calendar events.
Bounded imports and normalized content
The initial Gmail import fetches at most 100 full messages. Rolling Gmail storage is limited to 500 messages from the preceding 30 days per connection. Primary Calendar imports cover 30 days in the past through 180 days in the future and store at most 1,000 events.
Sortae stores normalized message or event content, provider record identifiers, sender or organizer details, timestamps, derived summaries, routing reasons, and your actions. Normalization extracts readable text needed to provide the attention views; it does not change data in Google.
How we use and share data
We use this data only to provide, secure, troubleshoot, and improve the features you request. Sortae does not sell personal data, serve behavioral advertising, or use Google user data to train generalized AI or machine-learning models.
Sortae runs on Google Cloud Run, stores deployment secrets in Google Secret Manager, stores application data in Supabase, and uses Cloudflare Turnstile to protect public waitlist submissions. These providers process limited data for hosting, storage, security, and abuse prevention under their service terms. We may also disclose data when legally required or to protect users and the service.
Google API Limited Use
Sortae's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
Security, retention, and deletion
Google refresh tokens are encrypted with AES-256-GCM before storage; plaintext tokens are used only server-side while making a requested provider call. We use access controls and tenant isolation, but no online service can guarantee absolute security.
Operational logs are designed to omit waitlist emails, raw network addresses, user-agents, provider payloads, tokens, and message content. Short-lived waitlist abuse records are retained for up to 24 hours. Application records remain while the account is active or as needed for security and legal obligations. Encrypted backups and provider logs may retain deleted data for a limited recovery or compliance period before aging out.
Your controls
Invited users can access their workspace, export their Sortae account data, disconnect Google, and permanently delete their account from Account & data. Disconnecting removes the connection, encrypted credential, imported source records, derived items, and sync state. Account export does not include unauthenticated waitlist records.
To access, correct, or delete a waitlist entry before creating an account, email privacy@sortae.com from the address you submitted. We will verify control of the address before acting. Depending on where you live, you may have additional privacy rights and appeal rights.
Changes and contact
We may update this policy as Sortae changes. Material updates will be identified by a new effective date and, when appropriate, an in-product notice. See our Terms of Service for service terms.