Security & privacy

Your inbox is the most sensitive thing you own. We treat it that way.

An AI email client only works if you trust it. So here is exactly what Parrot stores, what it never touches, and what happens the day you decide to leave.

TLS 1.3 in transitAES-256 at restSOC 2 Type IIGDPR & CCPA
Read the privacy FAQ
The guarantees

Six commitments, none of them footnoted.

These aren't aspirations for a future release. They describe how Parrot is built today.

Categorization runs on-device

The model that labels your mail ships with the app and runs locally. Your messages don't leave your machine to get sorted.

Your mail never trains a model

Not ours, not anyone else's. Reply drafting processes a thread in memory and discards it the moment the draft is handed back to you.

OAuth tokens, isolated

We never see or store your mailbox password. Access tokens live in a dedicated secrets vault, encrypted with per-tenant keys.

Minimum viable metadata

We keep only what's needed to keep your inbox in sync — sync cursors, message IDs, and your label corrections. Nothing more.

Hardened infrastructure

Private networks, no public database endpoints, least-privilege IAM, and every deploy scanned for known CVEs before it ships.

Access you can audit

Engineer access to production is short-lived, approval-gated, and logged. Nobody reads your mail — and the log proves it.

Data, plainly

What we hold onto — and what we refuse to.

What Parrot stores

  • OAuth access tokens, in an isolated vault
  • Message IDs and sync cursors, to stay in step with your provider
  • The label corrections you make, scoped to your account only
  • Your account settings and billing record

What Parrot never stores

  • Your mailbox password — OAuth means we never receive it
  • Message bodies on our servers after a draft is returned
  • Your mail in any training set, ours or a third party's
  • Attachments, beyond the moment they're passed through to you
The lifecycle

Follow one message from arrival to deletion.

  1. On connect

    You authorize read and send scopes with your provider. Parrot receives a token — never a password — and you can revoke it from your provider or from Settings at any time.

  2. On arrival

    The message is fetched over TLS 1.3 and categorized locally on your device. The label is stored; the body is not.

  3. On drafting

    If you ask for a reply, the relevant thread is sent to the model over an encrypted channel, held in memory for the duration of the request, and dropped immediately after.

  4. On disconnect

    Revoking access cuts our reach instantly. Every trace of your data is purged from our systems and backups within 30 days — no ticket, no retention call.

For teams

Everything your security review will ask for.

Available on Ultimate for teams of 25 or more. We've been through the questionnaire before — we'll make it quick.

SAML SSO & SCIM

Bring your own identity provider. Provision and deprovision seats automatically as people join and leave.

Audit logs & retention

Exportable logs of every connect, send, and admin action, plus enforced retention windows your compliance team sets.

Security review support

Questionnaires, DPAs, subprocessor lists, and our latest SOC 2 report — sent under NDA, usually the same week you ask.

Found something? Tell us before you tell anyone else.

We acknowledge every report within one business day and keep you updated until it's closed. Test only against accounts you own, don't degrade the service for anyone else, and we'll never come after you for good-faith research.

security@parrotmail.com
Parrot Mail

Your inbox, finally under control.

Connect unlimited accounts, free for 30 days. No credit card required — cancel anytime.

SOC 2 Type IIEncrypted at rest & in transit