Last updated: September 20, 2026
Aesir Labs, LLC d/b/a ForthWrite (“we,” “our,” or “us”) provides ForthWrite, an AI-powered email drafting tool. This policy explains how we collect, use, and protect your information when you use our Chrome extension, Outlook Add-in, web application at forthwrite.ai, and the Claude connector described below.
We collect the following categories of information:
in:inbox is:unread) at most once every 60 seconds so it knows which new conversations to draft for. We do not read Gmail labels, attachments, archived mail, or any folder other than the inbox. On the routine drafting path, thread content is held in memory only for the duration of the draft request. When voice-matching capture is on, the inbound message you replied to is later stored as part of that reply pair, as described under sent-email snippets below.calendar.freebusy. We never read event titles, guests, descriptions, locations, or attachments. A short summary of open windows is computed on your device and sent with a draft request so a scheduling reply can offer times you are actually free. We do not store that summary on our servers after the draft is returned. The feature is on by default; you can turn it off at any time from the extension options page.calendar.events.owned, with exactly the details you were shown, and ask Google to email those guests the invitation. We never create, change, or delete any other event on your calendar, and we never act without that per-event confirmation. Sending an invitation does not let us read your existing events: the free/busy summary described above remains the only calendar data we read. Guests are drawn from the people already on the email thread, plus anyone named in the drafting note you wrote for that reply (matched against your own ForthWrite contacts) and anyone whose address you type in yourself. You can uncheck any of them before sending./me/calendar/getSchedule call. Microsoft offers no free/busy-only permission, so this requires Calendars.ReadWrite, which is broader than what we do with it; what we actually call is limited to this free/busy check and the single event creation described below. Where that call returns an event subject or location alongside a busy block, we discard it at the point of reading, before anything else in the extension can see it: it never reaches a draft, our servers, or an AI provider. We never call calendarView, and we never read, change, or delete an event that already exists. Which calendar is read follows the mailbox you are drafting in, so Gmail threads use Google Calendar and Outlook threads use your Outlook calendar; if you have connected both, you can pin one under Calendar in the extension options page. The feature is on by default and can be turned off in the same place.POST /me/events, carrying exactly the details you were shown. Microsoft emails the guests on that event automatically; that is the only notification behaviour available to us and we cannot suppress it, so an invitation you confirm always notifies the guests you saw. We never create, change, or delete any other event on your calendar, and we never act without that per-event confirmation.users.settings.sendAs.listonce to enumerate the alias addresses configured on that account so the right “From” identity can be attached to drafts. We store only the alias email address and display name, never the alias signature HTML./dashboard/inboxreads thread metadata from your connected Gmail and Outlook accounts to show a unified triage view, and lets you generate a voice-matched reply for any thread. Saving a reply to your Gmail Drafts folder or Outlook Drafts folder uses your account's existing draft-creation permission. Production Inbox Hub requests send permission when you connect a mailbox. New mailboxes start with sending on; you can turn a mailbox off on the Connections page. Sending a reply still requires you to click Send and confirm the recipient and content; a short undo window follows before the message is actually sent through your provider. We never send automatically, in bulk, or without that explicit per-message confirmation, and thread content read for this feature is not persisted beyond what is needed to render the triage view and generate the draft you asked for, except when capture later stores that inbound message as part of a reply pair.https://www.forthwrite.ai/mcp to request a draft or a contact lookup. We receive the prompt material Claude sends (the thread or instruction, and any contact identifier), generate a draft using your voice profile, or return a minimized contact summary, and send that text back to Claude. We do not send mail, open a mailbox, or hand Claude your inbox. The conversation you have with Claude, including any draft text we return, is processed by Anthropic under Anthropic's terms. You can revoke the grant at any time from Connections or from Claude's connector settings. Setup is documented at https://www.forthwrite.ai/claude.If you submit your mobile phone number through our consulting contact form, Aesir Labs, LLC d/b/a ForthWrite may send you appointment confirmations and reminders at that number (“Consulting SMS Program”). The full SMS terms are on this page and at /sms-consent. Marketing texts about the consulting offer you asked for require a separate, optional, unchecked box on that form. The marketing box is not required to submit the rest of the form or to book a consultation by any other means. A phone number collected on any other ForthWrite page is not SMS consent.
We do not share, sell, or otherwise provide your mobile phone number or messaging consent information to any third parties or affiliates for marketing or promotional purposes. Your mobile number and SMS opt-in status are used solely to operate the Consulting SMS Program described above.
The public opt-in form is https://form.typeform.com/to/Eu7ihAB0. For the full call-to-action, every opt-in method we use, and a screenshot, see our SMS Consent page.
When you provide your own API key (BYOK), keys saved through the web app are stored encrypted at rest using AES-256-GCM envelope encryption with per-user data-encryption keys wrapped by a master key held only on our servers. The key is decrypted only long enough to send your draft request to the AI provider you selected (OpenAI, Anthropic, Google, xAI, etc.). Some legacy extension-only keys may still live only in Chrome's local storage until you migrate them to the web app. On the hosted path, draft requests are routed through our backend proxy: Free and grandfathered Standard default to OpenAI; Pro and Teams default to Anthropic. The email thread we read to write a draft is not stored after the response, except when capture later stores that inbound message as part of a reply pair. The draft text we generate is not retained for general use, with three narrow exceptions: for a new account we keep a copy of its first 10 drafts for up to 60 days so we can check whether early drafts were any good; a draft you never send may be kept for up to 180 days as a quality signal; and when you regenerate or refine a draft before sending, the earlier rejected draft and any instruction you used to replace it are kept with that training sample under the same retention window as your sent-email snippets. None of these is used to train shared or third-party models, and none is ever combined with another user's data.
Account and subscription data is stored in a secure Supabase (PostgreSQL) database with row-level security enabled. Payment information is handled entirely by Stripe and never touches our servers. All data is transmitted over HTTPS.
Sent-email snippets captured for voice matching are stored in the same Supabase database and scoped to your own account, with one exception described in Section 6a. Those snippets hold real message text: the inbound message you replied to, the draft ForthWrite wrote, and the version you sent. OAuth tokens for connected Gmail and Outlook accounts and BYOK credentials saved in the web app are encrypted at rest using AES-256-GCM envelope encryption with per-user data-encryption keys; the master key is held only on our application servers and is never written to the database.
If we confirm unauthorized access to your data, we notify affected users within 72 hours. Regulator thresholds are defined in our incident playbook.
If you are on a ForthWrite Teams plan, the owner and any admin of your team can open a review record covering every accepted member of that team. For messages ForthWrite drafted, the review record shows the inbound message you replied to, the first draft, any revisions you asked for along with the instruction you typed, the version you sent, which model produced the draft, and the date and time you sent it. They can filter it by member and by date, and export it as a CSV file.
This is real message content rather than a count. A team owner or admin can read the text of client emails you drafted and sent through ForthWrite. Team members cannot see each other's records, and nobody outside your team can see any of it.
The purpose is to let a firm show how a message was written: what the machine proposed, and what the person changed before sending. Until this feature shipped on 14 September 2026, these snippets were kept only to match your writing voice. On individual plans that is still the only thing they are used for.
ForthWrite is not a mail archive. The review record covers only messages you drafted with ForthWrite. It does not hold your mailbox, and it has no visibility into work done in other tools. On an individual plan you can turn off voice-matching capture from the extension options page, which stops new rows from being written. On a Teams plan, capture is required on seats by default; a team owner or admin can turn that requirement off, and the seat holder cannot. Team drafting analytics elsewhere in the dashboard remain counts only and contain no message content.
Account and subscription data is retained while your account is active. Draft usage counters reset weekly.
Sent-email snippets captured for voice matching are retained for as long as you keep voice-matching capture enabled, so we can keep your writing-style profile current. Plans keep snippets for a rolling window tied to your plan (Free and grandfathered Standard: 1 year; Pro and Teams: 18 months, which is 540 days) so recently captured data is never lost during normal use. If you are on the Free plan, or your subscription lapses or is canceled, we do not immediately delete your existing snippets: they age out under the same rolling 1-year window, giving you a grace period to resubscribe without losing your writing-style profile. On an individual plan you can disable capture from the extension options page. On a Teams plan, a team owner or admin can turn the capture requirement off; the seat holder cannot. While that requirement is on, a seat cannot delete captured snippets from the dashboard. An individual account can still delete its own snippets from Settings or by emailing us. Your account, subscription, and writing-style profile remain intact unless you also request full account deletion.
Voice dictation audio is never retained. It exists only in memory for the duration of the transcription request and is discarded immediately after the text is returned to your compose box.
Claude connector access tokens expire after one hour. Refresh tokens rotate on each use. Revoking the grant from Connections, or deleting your account, burns the token family. We keep a short audit of tool calls (which tool, success or failure, no draft body) so we can debug a broken connector.
On an individual plan, or as a team owner or admin, you can request deletion of your account and all associated data (including snippets, the writing-style profile, OAuth tokens, and any embeddings) from Dashboard → Settings → Danger zone → Request deletion, or by emailing us at support@forthwrite.ai. A Teams seat cannot start that request from Settings. The seat can ask a team owner or admin to release them; that does not start a ForthWrite wipe. We complete account deletion within 30 days of a confirmed request from someone who can make it. Some records required by law (for example Stripe tax invoices) may be retained after deletion.
You have the right to access, correct, or delete your personal data. You can export your data from Settings in the dashboard, or by contacting us at support@forthwrite.ai. Account deletion from Settings is available on an individual plan and to a team owner or admin. A Teams seat asks their owner or admin instead. Account deletion is completed within 30 days of a confirmed request.
You can also disable calendar availability at any time from the extension options page, and disconnect any linked Gmail or Outlook inbox from the Settings tab in your dashboard. Disconnecting an inbox deletes that row and the stored OAuth tokens for that account. On an individual plan you can disable voice-matching capture from the extension options page. On a Teams plan, a team owner or admin can turn the capture requirement off; the seat holder cannot.
ForthWrite's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
The specific Google OAuth scopes ForthWrite requests, and the user-facing feature each scope powers:
gmail.readonly: reading the open Gmail thread to build draft context; polling the inbox-thread list (read-only, in:inbox is:unread) so the extension knows which new conversations to draft for; reading sent-mail snippets when you opt into voice capture or one-shot historical backfill; and (web) reading thread metadata for the Inbox Hub's triage view.gmail.compose: creating, updating, and deleting only the drafts ForthWrite itself authored, whether from the Chrome extension or the web dashboard's Inbox Hub. We never modify or delete drafts you wrote by hand.gmail.send (web only): sending a reply from the Inbox Hub for a mailbox that has sending on (new connections start with sending on; you can turn a mailbox off on the Connections page), only after you click Send and confirm the recipient and content, and only after a short undo window elapses. We never send automatically, in bulk, or without that explicit per-message confirmation.gmail.settings.basic (web only): enumerating your send-as aliases via users.settings.sendAs.list so the right “From” identity is attached when drafting. No other settings are read or written.userinfo.email: identifying the authenticated Google account so the extension can match it to your ForthWrite subscription.calendar.freebusy (Chrome extension only): reading busy and free blocks on your primary Google Calendar so scheduling drafts can offer times you are actually free. This scope returns no event details: no titles, guests, descriptions, or locations.calendar.events.owned (Chrome extension only): creating a calendar invitation when you send or confirm one on a scheduling thread, and asking Google to email the guests listed on it. We use this scope only to write the single event you approved. We do not use it to read, list, change, or delete any other event on your calendar, and there is no code path that creates an event without your explicit per-event confirmation.We also request Microsoft Graph permissions for Outlook accounts you connect. Mail.Read and Mail.ReadWrite power the Inbox Hub's triage view and draft saving. The Chrome extension always requests Mail.Send. Inbox Hub also requests it in production. Sending from Hub still requires a mailbox with sending on, a confirm step, and a short undo window.
The Chrome extension additionally requests Calendars.ReadWrite. Microsoft has no free/busy-only permission and no create-only permission, so this single permission is the narrowest one that covers both calendar things we do. It grants more than we use, so here is exactly what we use it for:
/me/calendar/getSchedule: reading busy and free blocks on your Outlook calendar so scheduling drafts can offer times you are actually free. Where this call returns an event subject or location, we discard it at the point of reading; nothing downstream in the extension can access it.POST /me/events: creating a calendar invitation when you send or confirm one on a scheduling thread. Microsoft emails the guests on it automatically.We do not call calendarView, we do not list your events, and we never read, change, or delete an event that already exists. The calendar permission is requested only by the Chrome extension; it is not requested by the ForthWrite web app, by the Outlook Add-in, or when you sign in with Microsoft.
We may update this policy from time to time. We will notify you of material changes via email or a notice on the website.
For privacy-related questions, contact us at support@forthwrite.ai.