Privacy

Your data stays yours.

ReQueue is built for contractors who trust us with their inbox. Here is exactly what we do with that trust.

Last updated: August 2026

How ReQueue reads your email

ReQueue connects to your Gmail account using Google OAuth. We hold exactly two permissions:read access to your mail, and permission tocreate a draft in your mailbox. We are technically incapable of sending: the permission that would let us send email is one we have never requested. A follow-up leaves your account only when you open the draft and press send yourself. We cannot delete or alter a message you already have.

When we look

We check your sent mail and your inbox every thirty minutes, around the clock, so a reply that arrives on a Friday evening is on your board before Monday. A check that finds nothing new does nothing and costs nothing.

What we read, and what we keep

We read subjects, participants, dates and attachment filenames across your mail to work out which messages are about a quote. Where a message belongs to a quote we are tracking, we also read its content, so the follow-up we write for you answers what your client actually said.

For those messages, and only those, we keep the content. A deal that runs for months is a conversation, and a system that remembers only a one-line summary of each message forgets the budget they named in April by the time it writes to them in July. Keeping it is what lets ReQueue answer a client rather than send a template.

That content is encrypted before it is stored, using a key held separately from the key that protects your Google credentials, and it is readable only by our servers - never by your browser, and never by another company. It is deleted 90 days after a deal is marked won, lost or removed, 18 months after the last activity on one still open, and within 24 hours of you disconnecting Gmail, whichever comes first.

Everything else in your mailbox is read in passing and never written down. Newsletters, internal mail, vendor threads and personal messages are not stored, and neither are the contents of attachments - we extract the figures a quote needs and discard the file.

What we store

From your email: subject lines, sender and recipient addresses, dates, attachment filenames, and threading identifiers (Message-ID, In-Reply-To, References). For messages that belong to a quote we are tracking, the message content as well, encrypted and time-limited as described above.

From your activity: notes, call logs, and meeting records you enter manually.

Never stored: the content of mail that is not about a tracked quote, the files attached to any message, your password, and payment details beyond what Stripe processes on our behalf.

What we do not do

  • xSell, share, or license your data to third parties
  • xUse your email content to train AI models
  • xSend, modify, or delete email on your behalf without your explicit approval
  • xKeep the content of mail that is not about one of your quotes
  • xRead newsletters, internal conversations, or personal messages
  • xShow your email conversations to your team or employer

Google user data

ReQueue’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In plain terms, that means four commitments:

  • Only for the features you signed up for. Gmail data is used to identify your quotes, track which ones are waiting on a reply, and draft follow-ups for your approval. Nothing else.
  • Never for advertising. We do not run ads, and we do not provide Gmail data to anyone who does.
  • Never transferred, except as required to run the product. Gmail data reaches only the processors listed under Data sharing below, and only to deliver a feature you are using. It is not sold, rented, or licensed, and it is never used to train AI models.
  • No human reads your mail. Our staff do not read Gmail content, with the narrow exceptions Google requires us to name: where you have given explicit permission (for example, when you ask us to look at a specific thread for support), where it is necessary for security or to fix an active problem, or where the law compels it.

If you revoke ReQueue’s access from your Google account permissions page, or disconnect from Settings, we stop reading your mailbox immediately and delete the stored message content described above.

Security

OAuth tokens are encrypted at rest with AES-256-GCM and stored in your workspace only. Each workspace is isolated by row-level security policies. No workspace can access another.

All data is transmitted over HTTPS/TLS 1.3. Our infrastructure is hosted on Vercel (frontend) and Railway (scanner), both running in U.S. data centers with SOC 2 compliance.

SOC 2 Type II certification for ReQueue is in progress.

Your controls

Disconnect Gmail: to stop ReQueue from accessing your email, disconnect Gmail at any time from Settings or revoke access from your Google account. Disconnecting stops all access immediately.

Delete contacts: remove all imported contacts from Settings. Your next scan will repopulate them from email metadata.

Delete account: permanently delete your account and all associated data from Settings. This cannot be undone.

Data sharing

We use the following third-party services to operate ReQueue:

  • Google: OAuth authentication, and the Gmail API for reading your mail (gmail.readonly) and placing a draft in your Drafts folder for you to review (gmail.compose). ReQueue cannot send mail from your account.
  • Supabase: database and authentication infrastructure.
  • Anthropic (Claude): classification and draft generation. Email summaries may be sent to the Claude API for processing. Claude does not retain or train on customer data.
  • Stripe: payment processing. ReQueue does not store credit card numbers.
  • Resend: transactional email delivery (digest emails you opt into).
  • PostHog: anonymized product analytics. No PII is sent to PostHog.

We do not sell, rent, or trade your data. We do not run advertising. Our business model is subscriptions.

Questions about your data?

Reach us at privacy@requeue.io. We respond within 2 business days.