Privacy Policy
Effective May 18, 2026
Summary
blade.net helps you find people in your Gmail who you've actually corresponded with and send them a personalized message. We read email headers (not bodies), store a ranked contact list, and only send mail when you compose a campaign and click Send. We do not sell, share, or use your data for advertising. You can revoke access and delete your data at any time.
Information we collect
- Google account profile.Your name, email address, profile picture, and unique Google user ID. Provided by Google's standard OpenID Connect on sign-in.
- Gmail message headers. The
From,To,Cc,Bcc,List-Unsubscribe,Precedence, and internal date for messages in your mailbox going back as far as the lookback window you select. We do notread, store, or transmit message bodies or attachments of messages you've received. - On-demand contact history. When you open the recent-messages panel for a specific contact, we ask Gmail for the
Subjectheader and Gmail's ~150-charactersnippetfor up to the 20 most recent messages with that contact, render them in your browser, and do not save them to our database. - Link clicks (opt-in per campaign).If you check “Track link clicks” when composing a campaign, we replace every URL in the message with a
blade.net/l/…short link. When a recipient clicks, we record an aggregate counter (count, first-click time, last-click time) keyed to that recipient's queue row, then 302-redirect to the original URL. We do not store individual click events, IP addresses, or user-agent strings. Tracking is off by default and disclosed in the composer; uncheck the box to send untracked. - Bounce monitoring. After a campaign sends, we periodically read your inbox for delivery-failure notifications (mailer-daemon messages) and mark the corresponding recipients as bounced. Only the address that bounced and a short DSN snippet are stored, both attached to the queue row for that recipient.
- OAuth tokens. The access token and refresh token issued by Google so we can read your mailbox and (with your explicit grant) send mail on your behalf. Tokens are encrypted at rest using AES-256-GCM with a key derived from a secret only the server knows.
- Derived contact list.One row per email address you've corresponded with, including: their email, their display name (parsed from the
Fromheader), counts of how many emails you've sent and received, first and last contact dates, and whether the address looks like an automated sender. - Send history.When you run a campaign, we record the recipient, subject, your campaign template, the per-recipient unsubscribe token, send timestamp, success/failure status, and Gmail's returned message ID.
- Job state. Status, progress, and error messages for the background tasks that mine your mailbox and send your campaigns.
How we use your information
- To authenticate you via Google.
- To build and display your ranked contact list.
- To send mail merge campaigns to recipients you explicitly select, using your Gmail account, throttled to stay under Google's per-day sending limits.
- To honour unsubscribe requests from your recipients.
- To debug failures (server-side logs include hashed recipient identifiers and error messages — full email addresses are not logged outside our database).
We do not use your data for advertising, profile building, training machine-learning models, or any purpose unrelated to delivering the blade.net service.
How your data is stored
- Database. A managed Postgres database hosted by Neon in the AWS us-east-1 region.
- Background jobs.Mining and sending tasks run on Trigger.dev's managed worker infrastructure.
- App hosting. The web app runs on Vercel.
How we protect your data
We use industry-standard security procedures and encryption to protect the confidentiality and integrity of your data, including Gmail data received via Google APIs. The controls below apply specifically to sensitive and restricted-scope data (Google OAuth tokens, Gmail message headers, and any content read on demand).
- Encryption in transit. All connections between your browser, blade.net, Google APIs, Neon (our database), and Trigger.dev (our background workers) use TLS 1.2+ (HTTPS). Traffic on the public internet is never sent in cleartext.
- Application-layer encryption at rest for OAuth tokens. Your Google
access_token,refresh_token, andid_tokenare encrypted with AES-256-GCM (authenticated encryption) before being written to the database. The encryption key is derived via HKDF from a server-only secret that is never present in the database, in logs, or in source control. Tokens are decrypted only in server memory when a request needs them. - Storage-level encryption at rest. Our Postgres database (Neon) encrypts all stored data at rest on the underlying disk using AES-256, and all point-in-time backups inherit the same encryption.
- Strict access controls.Every API request and database query is scoped to the authenticated user's
userId. One user's data cannot be accessed by another user of blade.net. Session cookies are markedSecure,HttpOnly, andSameSite=Lax, and every state-changing endpoint additionally enforces a same-origin check to prevent CSRF. - Least-privilege OAuth scopes. We request only the two Gmail scopes we actually use (
gmail.readonlyfor header-only mining and on-demand conversation previews, andgmail.sendfor sending your campaigns) and we never call an API outside those scopes. You can revoke this access at any time via myaccount.google.com/connections. - Message content minimization. Mining reads header metadata only (
format=metadata) — no message bodies. The recent-conversation panel additionally reads theSubjectheader and Gmail's ~150-charactersnippet, but only for the specific contact you click on, only in your browser, and never persisted server-side. - Rate limiting and anti-automation. Sensitive endpoints (campaign creation, mining kick-off, the waitlist form) are rate-limited to prevent abuse.
- Trusted subprocessors under contract.Data handled on our behalf by Neon (database), Trigger.dev (background workers), and Vercel (web hosting) is governed by those providers' data-processing terms, which include SOC 2 controls and encryption at rest and in transit.
- Incident response. Suspected security incidents are triaged by the operator on call. If we determine that user data has been unlawfully accessed or exposed, we will notify affected users by email as soon as reasonably practicable. Vulnerability reports may be sent to security@blade.net.
No system is perfectly secure, and we cannot guarantee absolute security. If you believe your account or data may have been compromised, contact us immediately at the addresses above.
Google API Services User Data Policy
blade.net's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We only use Gmail data to provide and improve the contact-mining and outreach features you explicitly opted into.
- We do not transfer Gmail data to third parties except as needed to provide or improve those features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
- We do not use Gmail data for advertising purposes.
- We do not allow humans to read Gmail data unless we have your affirmative consent for specific messages, are required to do so for security purposes, to comply with applicable law, or as part of internal operations (e.g., debugging or abuse detection) with data aggregated and anonymized where feasible.
Third parties
- Google.Used for sign-in and as the source + destination of your mail. Subject to Google's own privacy policy.
- Neon. Hosts our Postgres database (AWS us-east-1).
- Trigger.dev. Runs background jobs. Receives minimal metadata (user IDs, job IDs, hashed recipient identifiers, error messages) — not raw mailbox content.
- Vercel. Hosts the web application. May log standard request metadata (IP address, user agent, timing).
We share data with these providers only as required to operate the service. We do not sell your personal information.
Your rights
- Revoke access. Open myaccount.google.com/connections, find blade.net, and click Remove access. This immediately prevents blade.net from reading or sending mail.
- Delete your data. Email us at hello@blade.net with your Google account email. We will delete your user record, contacts, mined message headers, send history, and encrypted tokens within 7 days.
- Export your data. The contacts page has an Export CSV button. For everything else, email the address above.
Retention
We keep your data as long as your account is active. If you stop using blade.net but don't request deletion, your data remains in the database so you can return without re-mining. If you delete your account or revoke access, we remove your user record and all associated rows.
Children
blade.net is not directed to anyone under 13. If you become aware a child has provided data to us, contact us and we will remove it.
Changes
We may update this policy. Material changes will be announced via email to your registered Gmail address before they take effect.
Contact
Questions or requests: hello@blade.net