Privacy Policy

Last updated: September 20, 2026

1. Overview

Aesir Labs, LLC d/b/a ForthWrite (“we,” “our,” or “us”) provides ForthWrite, an AI-powered email drafting tool. This policy explains how we collect, use, and protect your information when you use our Chrome extension, Outlook Add-in, web application at forthwrite.ai, and the Claude connector described below.

2. Information We Collect

We collect the following categories of information:

  • Account information: Email address and authentication data when you sign up.
  • Subscription data: Plan type, billing interval, and payment processor IDs (handled by Stripe).
  • Usage data: Draft generation counts for tier rate limiting, and product-analytics events (page views, clicks, sign-in, and payment events) sent to PostHog and HeyCatch. Neither receives email content or drafts.
  • Gmail content read by the Chrome extension: When the extension is installed and signed in to a Google account, it reads (a) the thread you are currently viewing so it can generate a contextually relevant draft, and (b) the inbox-thread list (using the read-only filter in:inbox is:unread) at most once every 60 seconds so it knows which new conversations to draft for. We do not read Gmail labels, attachments, archived mail, or any folder other than the inbox. On the routine drafting path, thread content is held in memory only for the duration of the draft request. When voice-matching capture is on, the inbound message you replied to is later stored as part of that reply pair, as described under sent-email snippets below.
  • Google Calendar free/busy (Chrome extension): When the extension is signed in to a Google account, it reads only whether you are busy or free on your primary calendar, using calendar.freebusy. We never read event titles, guests, descriptions, locations, or attachments. A short summary of open windows is computed on your device and sent with a draft request so a scheduling reply can offer times you are actually free. We do not store that summary on our servers after the draft is returned. The feature is on by default; you can turn it off at any time from the extension options page.
  • Google Calendar events you send (Chrome extension): When a scheduling thread has settled on a time, the extension offers you a prefilled invitation showing the event title, the date and time, and every guest who would be emailed. Nothing is created until you act on that offer. When the details are already correct you can send it with a single click; More options instead opens the full card, where you can edit the title, date, time, description, and guest list before pressing Confirm. If we cannot fill in a date, a time, or at least one guest, or we are not confident the thread actually settled on a time, the one-click option is withheld and the card opens for review instead. On send or Confirm, we create that one event on your primary calendar using calendar.events.owned, with exactly the details you were shown, and ask Google to email those guests the invitation. We never create, change, or delete any other event on your calendar, and we never act without that per-event confirmation. Sending an invitation does not let us read your existing events: the free/busy summary described above remains the only calendar data we read. Guests are drawn from the people already on the email thread, plus anyone named in the drafting note you wrote for that reply (matched against your own ForthWrite contacts) and anyone whose address you type in yourself. You can uncheck any of them before sending.
  • Outlook calendar free/busy (Chrome extension): When the extension is connected to a Microsoft account, drafting inside Outlook reads only whether you are busy or free, using the Microsoft Graph /me/calendar/getSchedule call. Microsoft offers no free/busy-only permission, so this requires Calendars.ReadWrite, which is broader than what we do with it; what we actually call is limited to this free/busy check and the single event creation described below. Where that call returns an event subject or location alongside a busy block, we discard it at the point of reading, before anything else in the extension can see it: it never reaches a draft, our servers, or an AI provider. We never call calendarView, and we never read, change, or delete an event that already exists. Which calendar is read follows the mailbox you are drafting in, so Gmail threads use Google Calendar and Outlook threads use your Outlook calendar; if you have connected both, you can pin one under Calendar in the extension options page. The feature is on by default and can be turned off in the same place.
  • Outlook calendar events you send (Chrome extension): The invitation flow is identical to the Google one described above: the same prefilled card, the same withheld one-click option when we cannot fill in a date, a time, or at least one guest, and the same requirement that you send or confirm before anything is created. On send or Confirm, we create that one event on your Outlook calendar with a single POST /me/events, carrying exactly the details you were shown. Microsoft emails the guests on that event automatically; that is the only notification behaviour available to us and we cannot suppress it, so an invitation you confirm always notifies the guests you saw. We never create, change, or delete any other event on your calendar, and we never act without that per-event confirmation.
  • Email content during draft generation: When you generate a draft, the relevant thread content is sent to your configured AI provider (BYOK) or, on the hosted path, through our backend proxy. Free and grandfathered Standard default to OpenAI. Pro and Teams default to Anthropic. We do not retain the thread content after the response is returned, except when capture later stores that inbound message as part of a reply pair.
  • Microphone audio for voice dictation (Pro and above): If you use the dictation button in the Chrome extension, your microphone audio is recorded locally, sent to our servers, and forwarded to OpenAI's Whisper API to produce a text transcript. The audio is used only to generate that transcript, is held in memory for the duration of the request, and is not stored by ForthWrite. Only the resulting text is returned to your compose box. Free-tier users see an upgrade prompt instead of a microphone permission request.
  • Gmail send-as aliases: When you connect a Google account on the web app, we call users.settings.sendAs.listonce to enumerate the alias addresses configured on that account so the right “From” identity can be attached to drafts. We store only the alias email address and display name, never the alias signature HTML.
  • Sent-email snippets for voice matching (all tiers): Snippets of emails you send (the body of your reply, the surrounding thread, and metadata like timestamps and platform) are stored in our database so we can learn your writing voice. Voice capture is on by default for all signed-in users. On an individual plan you can turn it off from the extension options page. On a Teams plan, capture is required on seats by default; a team owner or admin can turn that requirement off, and the seat holder cannot. On all tiers, this powers a private writing-style profile injected into the model. On Pro and above, it also drives the coaching and improvement dashboard. On Pro and Teams, snippets are additionally embedded so the model can retrieve your past similar emails at draft time.
  • PlusVibe / Pipl.ai integration: If you use ForthWriteinside PlusVibe or Pipl.ai (cold-email and sales-engagement platforms), the extension reads the thread, lead, and email-list data those platforms load in your browser tab, along with the corresponding network requests to pipl.ai/plusvibe.ai domains, so it can generate a contextually relevant draft the same way it does for Gmail. This data (thread and lead identifiers, request metadata, and email content) is cached locally in the extension's own browser storage on your device, capped to the most recent 100 requests, and is not sent to our servers except when you generate a draft, at which point it is handled the same way as the email content described above.
  • LinkedIn messaging integration (opt-in):LinkedIn support is off by default and only activates after you explicitly grant the extension access to linkedin.com from its options page. Once granted, the extension reads the currently open LinkedIn messaging conversation (the same visible-thread-only scope as Gmail) so it can generate a contextually relevant draft, and inserts the generated reply into LinkedIn's own message box for you to review and send. We do not read your LinkedIn connections, feed, profile data beyond what appears in the open conversation, or any conversation other than the one you have open. This data is handled the same way as the email content described above: held in memory only for the duration of the draft request and never persisted to our servers except when you generate a draft. You can revoke this access at any time from the extension options page or from Chrome's own site-permissions settings.
  • Historical email backfill (Pro and above, opt-in): If you choose to import historical emails from the Training Dashboard, we read up to the last twelve months of your sent mail via Gmail or Microsoft OAuth and store the same snippet-level information described above. We do not read inbox or non-sent folders, and the import is one-shot. We do not poll your mailbox in the background.
  • Inbox Hub drafting and sending (dashboard, connected accounts): The Inbox Hub at /dashboard/inboxreads thread metadata from your connected Gmail and Outlook accounts to show a unified triage view, and lets you generate a voice-matched reply for any thread. Saving a reply to your Gmail Drafts folder or Outlook Drafts folder uses your account's existing draft-creation permission. Production Inbox Hub requests send permission when you connect a mailbox. New mailboxes start with sending on; you can turn a mailbox off on the Connections page. Sending a reply still requires you to click Send and confirm the recipient and content; a short undo window follows before the message is actually sent through your provider. We never send automatically, in bulk, or without that explicit per-message confirmation, and thread content read for this feature is not persisted beyond what is needed to render the triage view and generate the draft you asked for, except when capture later stores that inbound message as part of a reply pair.
  • OAuth tokens for connected inboxes:When you connect a Gmail or Outlook account on the web, we store the access and refresh tokens issued by the provider, encrypted at rest using AES-256-GCM with per-user data-encryption keys wrapped by a master key held only on our servers. Tokens are used solely to support the features you have asked for: historical email backfill, the Inbox Hub's thread feed, drafting, and, for mailboxes that have sending on, sending replies to threads you review and confirm in the Inbox Hub. Disconnecting an inbox deletes that row and the tokens with it.
  • Outlook Add-in: When you install the ForthWrite Outlook Add-in and click “Connect,” we create a linked-mailbox record storing your Outlook mailbox email address and a 7-day signed authentication token. This record is shown on your Security dashboardand can be revoked at any time. When you click “Generate Draft,” the current email thread (headers and body) is read via Office.js and sent to our proxy in the same way as the Chrome extension. Thread content is not stored after the draft is returned. If you send a reply after generating a draft, the add-in's Smart Alerts handler captures the generated draft and your final sent body so we can learn how you edited the AI output (the same training-capture flow as the Chrome extension). Capture only fires when a draft was generated for the same thread in the same session.
  • Mobile phone number (consulting inquiries only): If you request a consulting engagement through our qualification form (linked from the consulting practice page), we collect the mobile phone number you provide so we can send Consulting SMS Program messages as described in Section 3 below. Entering that number on the contact form is consent for appointment confirmations and reminders. Marketing texts still require the optional box on that form. We do not collect phone numbers anywhere else in the Service. Booking paths that do not use the qualification form do not collect a mobile number for SMS.
  • Claude connector (MCP): If you connect ForthWrite from Claude, we issue a short-lived OAuth access token and a rotating refresh token bound to the ForthWrite account you signed in as. Claude then calls our hosted connector at https://www.forthwrite.ai/mcp to request a draft or a contact lookup. We receive the prompt material Claude sends (the thread or instruction, and any contact identifier), generate a draft using your voice profile, or return a minimized contact summary, and send that text back to Claude. We do not send mail, open a mailbox, or hand Claude your inbox. The conversation you have with Claude, including any draft text we return, is processed by Anthropic under Anthropic's terms. You can revoke the grant at any time from Connections or from Claude's connector settings. Setup is documented at https://www.forthwrite.ai/claude.

3. SMS / Text Messaging Communications

If you submit your mobile phone number through our consulting contact form, Aesir Labs, LLC d/b/a ForthWrite may send you appointment confirmations and reminders at that number (“Consulting SMS Program”). The full SMS terms are on this page and at /sms-consent. Marketing texts about the consulting offer you asked for require a separate, optional, unchecked box on that form. The marketing box is not required to submit the rest of the form or to book a consultation by any other means. A phone number collected on any other ForthWrite page is not SMS consent.

  • Message frequency varies based on your scheduled appointment and any follow-up about the consulting offer you asked for.
  • Message and data rates may apply.
  • Reply STOP at any time to opt out of further text messages, or reply HELP for assistance.
  • We use LeadConnector (HighLevel) to deliver these text messages. LeadConnector may use carrier partners, including Twilio, to send the messages.

We do not share, sell, or otherwise provide your mobile phone number or messaging consent information to any third parties or affiliates for marketing or promotional purposes. Your mobile number and SMS opt-in status are used solely to operate the Consulting SMS Program described above.

The public opt-in form is https://form.typeform.com/to/Eu7ihAB0. For the full call-to-action, every opt-in method we use, and a screenshot, see our SMS Consent page.

4. How We Use Your Information

  • To provide and maintain the ForthWrite service.
  • To manage your subscription and billing.
  • To enforce rate limits on the free tier.
  • To communicate important service updates.
  • To improve the product based on aggregate, anonymous usage patterns.
  • To learn your writing voice by summarizing your sent-email snippets into a private writing-style profile and, on Pro and Teams, by embedding those snippets so the model can retrieve your most relevant past replies at draft time. Your snippets are never used to train shared or third-party models, and are never combined with another user's data.
  • To honor a Claude connector grant: issue and rotate OAuth tokens, generate the draft or contact summary Claude requested, and let you revoke that grant from Connections.
  • To propose times you are actually free when a reply is about scheduling, using only the free/busy summary described above, read from whichever calendar matches the mailbox you are drafting in.
  • To create a single calendar event on that same calendar, and ask Google or Microsoft to email the guests you selected, when you send an invitation from a scheduling thread.

5. API Keys and AI Providers

When you provide your own API key (BYOK), keys saved through the web app are stored encrypted at rest using AES-256-GCM envelope encryption with per-user data-encryption keys wrapped by a master key held only on our servers. The key is decrypted only long enough to send your draft request to the AI provider you selected (OpenAI, Anthropic, Google, xAI, etc.). Some legacy extension-only keys may still live only in Chrome's local storage until you migrate them to the web app. On the hosted path, draft requests are routed through our backend proxy: Free and grandfathered Standard default to OpenAI; Pro and Teams default to Anthropic. The email thread we read to write a draft is not stored after the response, except when capture later stores that inbound message as part of a reply pair. The draft text we generate is not retained for general use, with three narrow exceptions: for a new account we keep a copy of its first 10 drafts for up to 60 days so we can check whether early drafts were any good; a draft you never send may be kept for up to 180 days as a quality signal; and when you regenerate or refine a draft before sending, the earlier rejected draft and any instruction you used to replace it are kept with that training sample under the same retention window as your sent-email snippets. None of these is used to train shared or third-party models, and none is ever combined with another user's data.

6. Data Storage and Security

Account and subscription data is stored in a secure Supabase (PostgreSQL) database with row-level security enabled. Payment information is handled entirely by Stripe and never touches our servers. All data is transmitted over HTTPS.

Sent-email snippets captured for voice matching are stored in the same Supabase database and scoped to your own account, with one exception described in Section 6a. Those snippets hold real message text: the inbound message you replied to, the draft ForthWrite wrote, and the version you sent. OAuth tokens for connected Gmail and Outlook accounts and BYOK credentials saved in the web app are encrypted at rest using AES-256-GCM envelope encryption with per-user data-encryption keys; the master key is held only on our application servers and is never written to the database.

If we confirm unauthorized access to your data, we notify affected users within 72 hours. Regulator thresholds are defined in our incident playbook.

6a. What a team owner or admin can see

If you are on a ForthWrite Teams plan, the owner and any admin of your team can open a review record covering every accepted member of that team. For messages ForthWrite drafted, the review record shows the inbound message you replied to, the first draft, any revisions you asked for along with the instruction you typed, the version you sent, which model produced the draft, and the date and time you sent it. They can filter it by member and by date, and export it as a CSV file.

This is real message content rather than a count. A team owner or admin can read the text of client emails you drafted and sent through ForthWrite. Team members cannot see each other's records, and nobody outside your team can see any of it.

The purpose is to let a firm show how a message was written: what the machine proposed, and what the person changed before sending. Until this feature shipped on 14 September 2026, these snippets were kept only to match your writing voice. On individual plans that is still the only thing they are used for.

ForthWrite is not a mail archive. The review record covers only messages you drafted with ForthWrite. It does not hold your mailbox, and it has no visibility into work done in other tools. On an individual plan you can turn off voice-matching capture from the extension options page, which stops new rows from being written. On a Teams plan, capture is required on seats by default; a team owner or admin can turn that requirement off, and the seat holder cannot. Team drafting analytics elsewhere in the dashboard remain counts only and contain no message content.

7. Third-Party Services

  • Stripe: Payment processing. Subject to Stripe's Privacy Policy.
  • Supabase: Database and authentication hosting.
  • Sentry: Error tracking (no email content is sent to Sentry).
  • PostHog: Product analytics (page views, clicks, sign-in, and payment events). When you disconnect a connected inbox, we also send the mailbox address on that disconnect event so we can tell which mailbox was removed. PostHog does not receive email content or drafts.
  • Upstash: Rate-limit storage. Keys may be an email address or an IP address. No message content.
  • AI Providers: OpenAI, Anthropic, Google, xAI, and others. Subject to their respective privacy policies. Voice dictation audio is sent specifically to OpenAI's Whisper API for transcription. When you use the Claude connector, Anthropic also receives the draft text or contact summary we return, as part of your Claude conversation.
  • LeadConnector (HighLevel): SMS delivery for the Consulting SMS Program described in Section 3. LeadConnector receives the mobile number and message content needed to deliver those texts. Subject to HighLevel's Privacy Policy.
  • Twilio, Inc.: Carrier partner that may send Consulting SMS Program messages on LeadConnector's behalf. Twilio receives only the mobile number and message content needed to deliver those texts; it is not used for any other feature of the Service. Subject to Twilio's Privacy Policy.

8. Cookies and Tracking

We use cookies and similar tracking technologies on forthwrite.ai. Essential cookies keep you signed in. Analytics and advertising cookies, pixels, and other tracking tools (including PostHog, HeyCatch, and Google advertising tags on marketing pages) measure how the site is used: page views, clicks, sign-in, and payment events. Cookie and tracking data does not include your email content or drafts.

You can refuse or delete cookies through your browser settings. Blocking essential cookies may prevent you from staying signed in. For cookie and tracking info about a specific vendor, see that vendor's privacy policy in Section 7.

9. Data Retention

Account and subscription data is retained while your account is active. Draft usage counters reset weekly.

Sent-email snippets captured for voice matching are retained for as long as you keep voice-matching capture enabled, so we can keep your writing-style profile current. Plans keep snippets for a rolling window tied to your plan (Free and grandfathered Standard: 1 year; Pro and Teams: 18 months, which is 540 days) so recently captured data is never lost during normal use. If you are on the Free plan, or your subscription lapses or is canceled, we do not immediately delete your existing snippets: they age out under the same rolling 1-year window, giving you a grace period to resubscribe without losing your writing-style profile. On an individual plan you can disable capture from the extension options page. On a Teams plan, a team owner or admin can turn the capture requirement off; the seat holder cannot. While that requirement is on, a seat cannot delete captured snippets from the dashboard. An individual account can still delete its own snippets from Settings or by emailing us. Your account, subscription, and writing-style profile remain intact unless you also request full account deletion.

Voice dictation audio is never retained. It exists only in memory for the duration of the transcription request and is discarded immediately after the text is returned to your compose box.

Claude connector access tokens expire after one hour. Refresh tokens rotate on each use. Revoking the grant from Connections, or deleting your account, burns the token family. We keep a short audit of tool calls (which tool, success or failure, no draft body) so we can debug a broken connector.

On an individual plan, or as a team owner or admin, you can request deletion of your account and all associated data (including snippets, the writing-style profile, OAuth tokens, and any embeddings) from Dashboard → Settings → Danger zone → Request deletion, or by emailing us at support@forthwrite.ai. A Teams seat cannot start that request from Settings. The seat can ask a team owner or admin to release them; that does not start a ForthWrite wipe. We complete account deletion within 30 days of a confirmed request from someone who can make it. Some records required by law (for example Stripe tax invoices) may be retained after deletion.

10. Your Rights

You have the right to access, correct, or delete your personal data. You can export your data from Settings in the dashboard, or by contacting us at support@forthwrite.ai. Account deletion from Settings is available on an individual plan and to a team owner or admin. A Teams seat asks their owner or admin instead. Account deletion is completed within 30 days of a confirmed request.

You can also disable calendar availability at any time from the extension options page, and disconnect any linked Gmail or Outlook inbox from the Settings tab in your dashboard. Disconnecting an inbox deletes that row and the stored OAuth tokens for that account. On an individual plan you can disable voice-matching capture from the extension options page. On a Teams plan, a team owner or admin can turn the capture requirement off; the seat holder cannot.

11. Google API Services User Data Policy

ForthWrite's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We do not use Gmail data for serving advertisements.
  • We do not allow humans to read your Gmail data, except (a) with your explicit consent for specific messages, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data is aggregated and used for internal operations in accordance with applicable privacy laws.
  • We do not transfer Gmail data to others except as necessary to provide or improve user-facing features that are prominent in the application's user interface, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with appropriate notice to users.
  • We do not use Gmail data to develop, improve, or train generalized or non-personalized AI or machine-learning models. The voice-matching writing-style profile and Pro retrieval embeddings described above are user-scoped, used only to draft email for that same user, and never combined with another user's data or shared with any third party.
  • The same Limited Use restrictions apply to Google Calendar data we receive from you or write on your behalf. Free/busy data is used only to draft scheduling replies for the same user. Event details you approve on an invitation are used only to create that one event and notify its guests. Neither is ever used to advertise, to develop or train generalized or non-personalized AI or machine-learning models, or combined with another user's data.

The specific Google OAuth scopes ForthWrite requests, and the user-facing feature each scope powers:

  • gmail.readonly: reading the open Gmail thread to build draft context; polling the inbox-thread list (read-only, in:inbox is:unread) so the extension knows which new conversations to draft for; reading sent-mail snippets when you opt into voice capture or one-shot historical backfill; and (web) reading thread metadata for the Inbox Hub's triage view.
  • gmail.compose: creating, updating, and deleting only the drafts ForthWrite itself authored, whether from the Chrome extension or the web dashboard's Inbox Hub. We never modify or delete drafts you wrote by hand.
  • gmail.send (web only): sending a reply from the Inbox Hub for a mailbox that has sending on (new connections start with sending on; you can turn a mailbox off on the Connections page), only after you click Send and confirm the recipient and content, and only after a short undo window elapses. We never send automatically, in bulk, or without that explicit per-message confirmation.
  • gmail.settings.basic (web only): enumerating your send-as aliases via users.settings.sendAs.list so the right “From” identity is attached when drafting. No other settings are read or written.
  • userinfo.email: identifying the authenticated Google account so the extension can match it to your ForthWrite subscription.
  • calendar.freebusy (Chrome extension only): reading busy and free blocks on your primary Google Calendar so scheduling drafts can offer times you are actually free. This scope returns no event details: no titles, guests, descriptions, or locations.
  • calendar.events.owned (Chrome extension only): creating a calendar invitation when you send or confirm one on a scheduling thread, and asking Google to email the guests listed on it. We use this scope only to write the single event you approved. We do not use it to read, list, change, or delete any other event on your calendar, and there is no code path that creates an event without your explicit per-event confirmation.

We also request Microsoft Graph permissions for Outlook accounts you connect. Mail.Read and Mail.ReadWrite power the Inbox Hub's triage view and draft saving. The Chrome extension always requests Mail.Send. Inbox Hub also requests it in production. Sending from Hub still requires a mailbox with sending on, a confirm step, and a short undo window.

The Chrome extension additionally requests Calendars.ReadWrite. Microsoft has no free/busy-only permission and no create-only permission, so this single permission is the narrowest one that covers both calendar things we do. It grants more than we use, so here is exactly what we use it for:

  • /me/calendar/getSchedule: reading busy and free blocks on your Outlook calendar so scheduling drafts can offer times you are actually free. Where this call returns an event subject or location, we discard it at the point of reading; nothing downstream in the extension can access it.
  • POST /me/events: creating a calendar invitation when you send or confirm one on a scheduling thread. Microsoft emails the guests on it automatically.

We do not call calendarView, we do not list your events, and we never read, change, or delete an event that already exists. The calendar permission is requested only by the Chrome extension; it is not requested by the ForthWrite web app, by the Outlook Add-in, or when you sign in with Microsoft.

12. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or a notice on the website.

13. Contact

For privacy-related questions, contact us at support@forthwrite.ai.