Skip to main content
Preview Tombstone is in private preview: Gmail sign-in only works for approved test accounts. Send a message to join the waitlist and we'll add your email.
Privacy

Privacy policy

Last updated: August 2, 2026 · Tombstone is a graduate project operated in a private beta capped at 100 users.

The short version

  • We read your email headers only (sender, subject, date). We never read message bodies or attachments.
  • All we keep is the short summary we build for you: the list of companies, dates, and breach flags. Your actual emails and their headers aren't stored.
  • We never sell your data and never use it to train AI models.
  • Disconnecting revokes our access at Google and lets you delete everything we hold.

What we access, and why

When you connect Gmail, Tombstone requests the gmail.metadata permission: the narrowest read scope Google offers, which exposes message headers and labels but not message bodies. In practice the app fetches only the From, Subject, and Date headers of your messages. It uses these to identify which companies have emailed you (and therefore likely hold an account for you), when they first and last contacted you, and which look dormant. Reading message bodies is not just disallowed by policy: the permission itself does not grant it.

The free breach check on the home page does not require Gmail at all. It sends the single email address you type, with your explicit consent, to the LeakCheck public API to see which known breaches it appears in.

Google API Services and Limited Use

Tombstone's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, that means: the only Gmail permission we request is gmail.metadata; we read the From, Subject, and Date headers only, never message bodies or attachments; we use that data solely to build your own account inventory; we never sell it, never use it for advertising, and never use it to train machine-learning or AI models. No human reads your Google data except with your explicit permission for a support or security issue, or where required by law. Disconnecting deletes it.

The per-scope detail, including why each permission is requested and what the code does with it, is on the Google API data use page.

What we store

Think of it as keeping the index, not the book. We save the short summary we build for you: the list of companies, when each one first and last emailed you, breach flags, and any deletion drafts you choose to create. That's it.

We don't keep your actual emails or their headers. As the scan reads each header to work out who sent it, that header is used and then discarded; it never lands in a database. Your Google sign-in is stored as an encrypted token, never in plain text, and only so you don't have to reconnect every visit.

What we never do

  • We never read the body or attachments of your email.
  • We never use your data, in any form, to train machine-learning or AI models.
  • We never sell, rent, or share your data with advertisers or data brokers.
  • We never store passwords for any third-party service.

AI processing

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Google user data, whether raw, aggregated, or derived, is never used, transferred, or sold to create, train, or improve any generalized or foundational AI or machine-learning model, by us or by anyone we send it to.

Tombstone uses large-language-model APIs for five narrow tasks: sorting companies into categories, ranking your breach exposure into an action plan, drafting the personalized paragraph of a deletion letter, writing the step-by-step walkthrough for closing an account, and looking up the privacy contact address a company publishes. Only minimal, task-specific text is ever sent: a bare domain name for categorization; public breach descriptors (name, date, severity) for the action plan; a short set of facts for a letter (the company name and the dates it emailed you); and a company name with its domain for a walkthrough or a contact lookup.

Some of that, principally the sender domain and the first and last dates a company emailed you, is derived from your Gmail metadata, so we treat it as Google user data and hold it to the Limited Use rules above. We never send message bodies, subject lines, your email address, or your full account list to any model.

Two providers, both used under commercial terms that prohibit training on what we send:

  • Groq, running Llama 3.3 70B on Groq's own infrastructure: categorization, action plan, letter paragraph, walkthroughs, and the first-pass contact guess. Groq does not train on API inputs or outputs, and we run the account with Zero Data Retention enabled, so requests are not retained after they are answered.
  • Anthropic, running Claude Haiku with web search: a last resort used only when our own directory and a scrape of the company's own site both fail to turn up a published privacy contact. It receives the company name and its domain, nothing else. Anthropic does not train on API inputs or outputs.

Neither provider is an aggregator or gateway to some further model, and no data of yours reaches the organizations that originally published these model weights.

Your control

You can disconnect at any time. Logging out revokes Tombstone's access token with Google directly, not just your local session. Deleting your account from the Account page removes your user record and cascades to all associated data in our database. Step-by-step instructions, including how to revoke access from Google's side, are on the data deletion page.

Data sharing

The only third parties that receive any of your data are the service providers that make the tool work: Google (the source of your authorized Gmail metadata), LeakCheck and HaveIBeenPwned (breach lookups, keyed on email), and our two AI providers, Groq and Anthropic (classification, letter drafting, and contact lookup, as described above). We do not share data for advertising, and none of them may train on what we send. Every one of them is named, with what it receives, on the subprocessors page.

Cookies

Tombstone sets one strictly necessary cookie to keep you signed in, and loads Google Analytics in production only. There are no advertising cookies and no cross-site trackers. The full list, with what each cookie does and how to turn analytics off, is on the cookie policy page.

Contact

Questions about your data can be sent to support@tombstonepro.com. Security reports go to security@tombstonepro.com.