Attli is a personal Gmail assistant operated by Maciej Jaworski in Poland. It reads incoming email from inboxes you connect, filters routine noise, summarizes useful updates, and highlights messages that need attention. This policy covers the Attli website at attli.app and the connected Gmail, AI, and notification features.
1. Information we access and collect
Google sign-in. When you sign in with Google, we receive and store your Google account identifier, name, and email address to create and identify your Attli account. Signing in and connecting an inbox are separate steps.
Connected Gmail inboxes. After you authorize an inbox, Attli accesses message and thread identifiers, sender and subject information, timestamps, labels, message snippets and body text, and relevant earlier messages in the same conversation. Sender-related headers, including Reply-To, Return-Path, and authentication results, can be used to assess possible phishing. This data may include information about people who correspond with you.
Authorization and preferences. We store encrypted Gmail access and refresh tokens so Attli can check mail while you are away. We also store your custom instructions, memories you add or Attli derives from messages, notification settings, and your chosen digest time and timezone.
Optional Telegram connection. If you pair Telegram, we store identifiers needed to connect your Telegram account and chat with Attli, together with notification delivery status and errors.
Operational information. We store processing timestamps, connection errors, and model usage records, including model name, request identifier, token counts, and cost. Requests to the website also pass through infrastructure that processes connection information such as IP addresses and request paths.
2. How Attli uses your data
Attli uses Gmail data to classify incoming messages, explain its decisions, produce dashboard summaries, identify items that need your attention, and mark messages as read. Relevant thread history helps interpret an ongoing exchange. Custom instructions and saved memories personalize these decisions. Routine updates may also be combined into a daily digest.
When you enable Telegram, Attli sends the selected notifications and digests to your paired chat. It may also notify you when an inbox needs to be reconnected. Operational and usage records help run the service, diagnose failures, prevent duplicate processing, and track AI usage.
Attli does not sell Google user data or use it for advertising. Attli uses AI to generate decisions and summaries; Attli does not train or fine-tune AI models on your Gmail messages. Saved memory is information used in future requests, not model training.
3. Google permissions and their limits
Google sign-in uses identity permissions to identify your account. Connecting Gmail requests https://www.googleapis.com/auth/gmail.modify. Google does not provide a scope limited to both reading message bodies and marking messages as read, so this broader permission is needed for Attli’s current features.
Although the Google permission permits more operations, Attli implements reading messages and removing the unread label. Attli does not send email, move email to trash, or delete messages. You can revoke Google access at any time.
4. Data shared with service providers
Google provides sign-in and Gmail API access. Attli sends authorization credentials and message identifiers to Google when reading messages or marking them as read.
OpenRouter and the selected AI model provider process relevant email text, sender information, conversation context, your instructions, and saved memories to return a classification and summary. Daily digest requests contain previously generated update titles and summaries. Requests include an internal Attli user identifier for usage tracking; Gmail authorization tokens are not sent to the AI provider. Model routing, provider processing locations, and retention depend on the selected provider and applicable settings and terms. See OpenRouter’s privacy policy.
Telegram receives notification text, email links, and the destination chat identifier when you connect it. Notifications can contain personal information derived from email. Messages already delivered to Telegram remain subject to Telegram’s storage and deletion controls. See Telegram’s privacy policy.
Hosting and network services support the app and database. Cloudflare handles public web traffic, including connection information, as part of delivering and protecting the website. See Cloudflare’s privacy policy.
These services may process information outside Poland and the European Economic Area. Connecting Gmail enables the AI processing described here; Telegram sharing occurs only if you connect Telegram. Disconnect an inbox to stop future processing of that inbox.
5. Storage, retention, and security
Gmail OAuth tokens are encrypted at rest. The public website and external Google, OpenRouter, and Telegram API connections use HTTPS. Attli stores account information, inbox identifiers, processing metadata, sender and subject information, classifications and explanations, dashboard summaries, memories, notification records, and usage records in its database.
Raw email bodies and thread bodies are processed for classification but are not retained as raw bodies in Attli’s database. Summaries, explanations, and memories can still contain personal information drawn from those emails. This database policy does not mean that third-party AI services have zero retention; their processing is described above.
Account data and stored history are retained while your Attli account exists unless you remove the relevant data or request deletion. Attli does not currently apply an automatic age-based expiry to feed history or saved memories. Operational records are used for service administration and troubleshooting.
6. Disconnecting, revoking access, and deleting data
You can disconnect an inbox in Attli to remove its saved authorization token and stop future checks. You can also revoke access through your Google Account’s third-party connections. Revoking Google access does not automatically delete the Attli account, saved memories, or summaries already produced.
You can inspect, edit, and delete memories in the dashboard, and disconnect Telegram to stop future notifications. Disconnecting an inbox does not necessarily remove previously generated feed items or memories. Disconnecting Telegram does not delete messages already delivered to your chat.
To request access to, correction of, or deletion of your Attli account and associated stored data, contact us using the address below. We may need to verify account ownership before handling a request. Deleting Attli data does not delete original messages in Gmail.
7. Google API Services User Data Policy
Attli’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used to provide the user-facing features described in this policy.
8. Changes and contact
We update this policy when Attli’s data practices change and identify the latest revision above. For privacy questions or data requests, contact Maciej Jaworski at hello@attli.app.