Klein.Express

Privacy policy

Last updated 29 September 2026

Who this applies to

Klein.Express is a private operations tool used by its owner. It is not offered to the public, and nobody else can sign in: access is limited to an explicit allowlist of accounts.

Google sign-in

Signing in with Google gives us your email address, which is checked against the allowlist and recorded in an activity log of sign-ins. Nothing else from your Google account is used for sign-in.

Gmail

If the owner connects a Gmail account, Klein.Express requests access to read and organise it (gmail.modify, plus openid and email to identify the mailbox). Google's consent screen describes this permission as able to read, compose and send email. Klein.Express uses it to read mail, to organise it: label, archive and move mail to Trash, which Gmail lets you undo for 30 days, and to keep the drafts the owner writes in the owner's Gmail. Klein sends mail through Gmail only when the owner writes and sends it from the backoffice; assistants never send through Gmail. Klein.Express never deletes mail permanently.

  • Every message except spam, trash and drafts is copied into our database so it can be shown in the tool and queried by the owner's assistants. Messages deleted or moved to Trash in Gmail are removed from that copy.
  • The subject, snippet and body of every stored message are encrypted at rest (AES-256-GCM). Sender, recipients, date, labels and the Message-ID headers that link replies are stored unencrypted so the inbox can be listed and threads assembled.
  • A message the owner sends waits in Klein.Express for 10 seconds so it can be undone, and then Gmail sends it. While it waits, Klein.Express keeps which draft it is, and its recipients and subject encrypted at rest (AES-256-GCM); the draft itself stays in the owner's Gmail. A message the owner schedules for later waits the same way, for up to 90 days, until its time.
  • Files the owner attaches while writing, and the attachments of a message the owner forwards or reopens, are held in Klein.Express encrypted at rest (AES-256-GCM) until the message is sent or discarded, and for at most a day after they were last used. The draft in the owner's Gmail keeps its own copy.
  • The Google refresh token is encrypted at rest and held only by the server-side component that talks to Google.
  • Mail data is used only to display it to the owner and to let the owner's own automated assistants read and organise it: label, archive, star, mark read or unread, create and rename labels, and move mail to Trash when the owner approves it, either each time or through an approval policy the owner set. Mail content an assistant reads is processed by the AI model provider that runs the owner's assistant, only to carry out the owner's requests. Klein.Express does not sell it, use it for advertising, or use it to train models. The filters an assistant uses to query mail, such as sender addresses, are kept in the audit log.

Google Contacts

If the owner allows it when connecting Google, Klein.Express can read the owner's Google Contacts (contacts.readonly), only when the owner imports them from the Contacts page. It reads names, email addresses, phone numbers, birthdays, nicknames, company names and photos, and stores the imported contacts in Klein.Express, where the owner edits, labels and deletes them. For each Google contact it also keeps Google's contact id, so a later import skips people already brought in. Klein.Express never changes or deletes anything in Google Contacts.

Contact data is used to show and search the owner's contacts in Klein.Express and to let the owner's own assistants read and update Klein's copy, only through the tools the owner granted them. Contact details an assistant reads are processed by the AI model provider that runs the owner's assistant, only to carry out the owner's requests. Klein.Express does not sell it, use it for advertising, or use it to train models.

Google API Services User Data Policy

Klein.Express's use and transfer of information received from Google APIs, including Gmail and Google Contacts, adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Where data lives

Data is stored in a managed PostgreSQL database hosted by Railway. Outgoing email, when the owner approves one, is delivered through Resend.

Disconnecting and deletion

Disconnecting Google in the tool revokes Klein.Express's access to Gmail and Google Contacts at Google. You can also revoke it at any time from your Google account's third-party access page. To have stored data deleted, contact us at the address below.

Contact

← Klein.Express