Privacy Policy
This page is an unreviewed draft. It has not been read by a qualified attorney and the bracketed values are not filled in. It must not be treated as the published policy, and no family should be invited on the strength of it.
Contents
In short
All My Kid's Emails reads the school-related email in the inbox you connect, summarises it, organises it by child, and emails you a daily digest. We use read-only access. We never change anything in your mailbox. We keep the message content we process for thirty days and then delete it. We do not sell your data or use it for advertising.
The rest of this page is the detail behind that summary.
1. Who we are
All My Kid's Emails is operated by [LEGAL ENTITY NAME], [ADDRESS]. For any privacy question, or to ask us to delete your data, contact [PRIVACY CONTACT EMAIL].
This is an invite-only pilot. It is free, it involves a small number of families, and it runs for approximately four weeks.
2. What we collect
Information you give us
- Your email address, used to sign in and to deliver your digest
- Your children's preferred names, grades, and schools or programs
- Optional details you choose to add, such as teacher names, class names, or activities
- Which email domains or senders you confirm as school sources
- Your timezone and preferred digest delivery time
- Any feedback or issue reports you submit
Information from your connected mailbox
When you connect Gmail or Outlook, we receive read-only access. We do not read your mailbox indiscriminately. We first look at limited message metadata — sender, sender domain, subject, recipients, and received time — to decide whether a message appears school-related. Only when it does do we retrieve the full content.
For messages that pass that screen, we may process:
- The message body
- Attachments in common school formats such as PDF, Word, PowerPoint, Excel, and images
- The content of a public web page linked directly from the message, such as a school newsletter
We do not follow links found inside those pages, and we do not log into any website on your behalf.
Information generated automatically
- Records of processing: what we found, how confident we were, what succeeded or failed
- Product usage events, such as opening a screen or completing an action, recorded against opaque identifiers rather than names
- Standard technical logs
We do not track whether you open our emails.
3. What we do not do with your mailbox
Our access is read-only, and this is enforced in our software rather than merely promised. We do not:
- Mark messages read or unread
- Move, archive, or delete messages
- Apply labels or folders
- Reply to messages
- Send email from your account
Your daily digest is sent from our own address, never from yours.
4. Why we process your information
- To identify school-related communications in your inbox
- To summarise them and organise them by child
- To identify actions that may need your follow-up and dates worth knowing about
- To send your daily digest
- To improve accuracy for your family based on your corrections
- To troubleshoot problems during the pilot
- To evaluate whether the product works
Our legal basis, where applicable, is your consent, which you may withdraw at any time by disconnecting your mailbox or deleting your family account.
5. Information about children
All My Kid's Emails processes school communications that mention children by name, along with the names, grades, schools, and activity details you provide.
This information comes from your own mailbox and from what you enter. We collect nothing directly from any child. Children have no accounts and no way to interact with the product.
We use this information only to route and summarise communications for you. We do not use it to build advertising profiles, we do not sell it, and we do not use one family's information to change how the product behaves for another family.
6. Who can see your information
You, and the one additional adult you may invite, who has read-only access.
Our support staff, in limited circumstances. During the pilot, an administrator may need to look at processed school content to diagnose a problem. That access is deliberate rather than routine, is limited to school-related content the product has already processed, does not extend to unrelated mailbox content, and is logged with the administrator's identity, what was accessed, when, and why. Raw content does not appear in ordinary dashboards.
Service providers we rely on, which for this pilot means Microsoft Azure for hosting, database, storage, AI processing, and email delivery. They process data on our behalf under their own terms. The AI models we use do not train on your data; that is a contractual commitment from Microsoft. Microsoft's AI service does automatically screen requests for abuse, and content it flags may be held by Microsoft for up to 30 days for that review; nothing that is not flagged is kept by them.
No one else. We do not sell your information, share it with advertisers, or disclose it to third parties except where legally required.
7. How long we keep things
| What | How long |
|---|---|
| Processed message content and attachments | 30 days, then deleted |
| Daily digest history | 30 days, then deleted |
| Actions, dates, corrections, and processing history | While your family account is active |
| Account and family records | While your family account is active |
| After you delete your family | 30-day recovery window, then permanent deletion |
8. Security
We use encryption in transit and at rest. Mailbox authorisation credentials are held in a dedicated secrets service, never in ordinary application storage, and never written to logs. Each family's data is isolated, and that isolation is verified by automated tests. Access to production systems is limited to people who need it.
Your information is processed and stored in the United States.
9. Your choices
- Disconnect your mailbox at any time from Settings. Processing stops.
- Delete your family at any time from Settings. Access ends immediately, processing stops, mailbox authorisation is revoked, and data is permanently deleted after a 30-day recovery window.
- Turn off the digest if you are the invited adult member.
- Correct anything we got wrong. Corrections are part of how the product is meant to work.
- Ask us for a copy of your data, or ask us to delete it, at [PRIVACY CONTACT EMAIL].
10. Google API disclosure
All My Kid's Emails' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we use Gmail data only to provide the user-facing features described in this policy, we do not transfer it except as necessary to provide those features or as required by law, we do not use it for advertising, and we do not allow humans to read it except with your consent, for security purposes, to comply with law, or for the limited, audited troubleshooting described in section 6.
We request a single Gmail scope, gmail.readonly, and no other. It is the
narrowest scope that permits reading message content, which is what identifying and
summarising school communications requires.
11. Changes
We will notify pilot participants by email before any material change takes effect.
12. Contact
[PRIVACY CONTACT EMAIL] · [LEGAL ENTITY NAME] · [ADDRESS]