Last updated 14 July 2026
Privacy Policy
This Privacy Policy explains how SolidState Digital (“we”, “us”, or “our”) collects, uses, and shares information when you use Command (the “Service”).
1. Who we are
Command is operated by SolidState Digital. For privacy questions or requests, contact us at [email protected].
2. What we collect
Depending on how you use Command, we may process:
- Account information — name, email address, and profile details provided by Google or Microsoft when you sign in with OAuth.
- Mailbox data — email content, metadata (senders, subjects, dates, labels), and related thread information synced so Command can triage, label, search, and display your inbox.
- Attachment metadata — filenames, types, and links to messages. Attachment files are streamed on demand from Gmail or Outlook and are not stored as server-side blobs.
- AI-derived artifacts — label suggestions, contact notes, extracted todos, reply drafts, and synthesis reports generated to provide product features.
- Settings and preferences — sync scope, digest preferences, unsubscribe behaviour, and similar product configuration.
- Usage and technical data — limited analytics and operational logs needed to run and secure the Service (for example page analytics and error signals).
3. How we use your data
We use personal data to:
- Authenticate you and maintain your session
- Sync and organise your inbox (Hotline, Feed, labels, Action queue)
- Power Tools such as Attachments, Todo List, and Synthesis Reports
- Generate reply drafts, contact notes, and related AI assistance
- Run automation such as reject/unsubscribe flows and daily digests
- Operate, secure, rate-limit, and improve the reliability of the Service
- Respond to support and privacy requests
4. No-train policy
Emails and attachments are never used to train any AI models. We operate with a strict no-train policy, enforced across all model providers we use (through provider selection and applicable API terms).
Command may personalise features inside your account — for example label recommendations based on labels you apply or remove. That in-app learning stays within your account experience and is not used to train third-party foundation models.
5. Email providers
To connect your inbox we use OAuth with:
- Google — Google sign-in, Gmail API access, and optional Google Cloud Pub/Sub for live push sync
- Microsoft — Microsoft Entra ID sign-in, Microsoft Graph for Outlook mail, and optional webhooks for live sync
We store OAuth tokens needed to access your mailbox on your behalf. We never ask for or store your email password. You can revoke Command’s access at any time from your Google or Microsoft account settings, or by contacting us to delete your Command account.
6. Platforms and subprocessors
We use trusted service providers to operate Command. They process data only as needed to provide their services to us:
- Vercel — application hosting, edge delivery, scheduled crons, and Vercel Analytics
- PostgreSQL — primary database (hosted with providers such as Supabase or Neon)
- Auth.js (NextAuth) — authentication and session management
- OpenRouter — AI API gateway; underlying model providers are reached through OpenRouter under our no-train policy
- Upstash — Redis for rate limiting and QStash for background jobs
- Resend — transactional email (for example welcome messages and daily digests)
- Google and Microsoft — as described above for identity and mailbox access
7. Sharing
We do not sell your personal data. We share data only with the subprocessors listed above as needed to run the Service, or when required by law.
If you create a shared Synthesis Report link, anyone with that unguessable URL can view the report until you revoke it. Shared links are under your control.
8. Retention and deletion
We retain account and synced data while your account is active and as needed to provide the Service. You can request deletion of your account and associated data by emailing [email protected]. Disconnecting OAuth from Google or Microsoft stops further provider access; contact us if you also want Command-side data removed.
9. Security
We use industry-standard measures appropriate to a cloud SaaS product, including OAuth (no passwords stored), access controls, rate limiting, and signed endpoints for background jobs and scheduled tasks. No method of transmission or storage is completely secure; we work to protect your data and improve safeguards over time.
10. Cookies and similar technologies
We use session cookies and similar technologies required for authentication and to keep you signed in. We also use Vercel Analytics to understand aggregate usage of the Service. These technologies help the product work and are not used to train AI models on your email.
11. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data we hold about you, and to object to or restrict certain processing. To exercise these rights where applicable, contact [email protected]. We will respond in line with applicable law.
12. Children
Command is not directed at children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
13. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Continued use of the Service after an update means you acknowledge the revised policy.
14. Contact
SolidState Digital
Email: [email protected]