Privacy

Your inbox is yours. We just help you read it.

An AI email client asks for a lot of trust, so this page is written to be read rather than skimmed past. Plain sentences, no definitions section, nothing hedged.

Last updated 27 July 2026

Your mail never trains a model

Not ours, not a vendor's. Categorization runs on-device, and drafting reads your thread in memory and discards it.

Nobody reads your inbox

No human at Parrot can open your mail. Support sees only what you paste into a ticket.

Leaving takes one click

Disconnect revokes our access instantly. Everything we hold is purged within 30 days.

What we collect

Parrot is a mail client, not a mailbox. Your email lives with your provider — Google, Microsoft, or your IMAP host — and we hold the minimum needed to show it to you and keep it in sync.

Account details
Your name, email address, and the OAuth tokens for each mailbox you connect. Tokens are scoped to mail access only.
Message data
Headers, bodies, and attachments, cached encrypted on your device for offline reading. On our servers we keep only sync metadata: message IDs, timestamps, and the label assigned.
Label corrections
When you re-label a thread we store that signal against your account, so your labels tighten around how you work.
Product analytics
Aggregate, non-identifying usage counts — which features get used, where things break. No message content, ever.
Billing
Handled by Stripe. We store a customer ID and your plan; we never see or hold your card number.

How we use it

Every use below is either something you asked for by connecting an account, or something we need to keep the service running and paid for. We do not sell your data, rent it, or hand it to advertisers — there is no version of Parrot where that pays better than the subscription does.

To run your inbox
Sync mail, categorize it, search it, and send what you write.
To improve your account
Your corrections refine your labels. They stay yours and are not pooled with anyone else's.
To support you
Answering your messages, and only using what you share in them.
To keep it safe
Detecting abuse, fraud, and outages — and meeting legal obligations when we have no lawful choice.

AI processing, specifically

This is the part most policies bury, so here it is up front. Categorization runs on-device: the model that tags a message as work or finance never sends that message anywhere.

Reply drafting and thread summaries need more capacity, so those requests go to our AI provider over an encrypted connection under a zero-retention agreement. Your thread is processed in memory, the draft comes back, and the provider keeps nothing. It is not logged for review and it is not used as training data by them or by us.

Parrot never sends mail on its own. Drafts wait for you, and nothing leaves your outbox without an explicit send.

Who we share with

A short list, because a long one is a liability. Each is contractually bound to confidentiality, limited to the purpose below, and prohibited from using your data for its own ends.

Cloud hosting
Runs the sync service and stores encrypted metadata.
AI provider
Reply drafting and summaries, under zero retention.
Stripe
Subscription payments and invoicing.
Error monitoring
Crash reports with message content scrubbed before it leaves your device.

Where it lives, and how long

Servers are in the EU and the US, and transfers out of the EEA run on Standard Contractual Clauses. Message caches live on your own devices and are wiped when you sign out.

Sync metadata is kept while your account is active. Close your account and everything — metadata, tokens, corrections, backups — is purged within 30 days. Aggregate analytics that can no longer be tied to you may remain. Billing records are held for seven years because tax law says so.

Security

TLS 1.3 in transit, AES-256 at rest. OAuth tokens sit in an isolated secrets vault with keys rotated on a schedule, and access to production is limited to a small on-call group behind hardware keys and audit logging.

Teams of 25 or more can add SAML SSO, SCIM provisioning, exported audit logs, and enforced retention. If your security team needs to review us before you roll Parrot out, ask — we would rather do the review than skip it.

Your rights

Under the GDPR, the CCPA, and comparable laws you can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, or take it elsewhere in a portable format. Most of that is self-serve in Settings; anything that is not, we handle within 30 days at no cost.

Marketing email always carries a one-click unsubscribe. There is no charge, and no consequence, for exercising any of this.

Cookies

One session cookie to keep you signed in, and local storage for your preferences and the offline cache. No advertising cookies, no third-party trackers, no cross-site profiling — which is why you have never seen a consent wall on this site.

Changes, and how to reach us

If we change something that materially affects your privacy, we will email you at least 30 days before it takes effect. Smaller edits get a new date at the top of this page.

Parrot is not built for children under 13, and we do not knowingly collect their data. Questions, requests, or a data-protection complaint: privacy@parrotmail.com. We answer within one business day.

Still have a question about your data?

A real person answers privacy mail — including the awkward ones about the AI.

Parrot Mail

Your inbox, finally under control.

Connect unlimited accounts, free for 30 days. No credit card required — cancel anytime.

SOC 2 Type IIEncrypted at rest & in transit