Privacy policy
Last updated: July 10, 2026 · Tombstone is a graduate project operated in a private beta capped at 100 users.
The short version
- We read your email headers only (sender, subject, date). We never read message bodies or attachments.
- All we keep is the short summary we build for you: the list of companies, dates, and breach flags. Your actual emails and their headers aren't stored.
- We never sell your data and never use it to train AI models.
- Disconnecting revokes our access at Google and lets you delete everything we hold.
What we access, and why
When you connect Gmail, Tombstone requests the gmail.metadata permission: the
narrowest read scope Google offers, which exposes message headers and labels but
not message bodies. In practice the app fetches only the From,
Subject, and Date headers of your messages. It uses these to
identify which companies have emailed you (and therefore likely hold an account for you), when
they first and last contacted you, and which look dormant. Reading message bodies is not just
disallowed by policy: the permission itself does not grant it.
The free breach check on the home page does not require Gmail at all. It sends the single email address you type, with your explicit consent, to the LeakCheck public API to see which known breaches it appears in.
Google API Services and Limited Use
Tombstone's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means: the only Gmail permission we request is gmail.metadata; we
read the From, Subject, and Date headers only,
never message bodies or attachments; we use that data solely to build your own account
inventory; we never sell it, never use it for advertising, and never use it to train
machine-learning or AI models. No human reads your Google data except with your explicit
permission for a support or security issue, or where required by law. Disconnecting deletes it.
What we store
Think of it as keeping the index, not the book. We save the short summary we build for you: the list of companies, when each one first and last emailed you, breach flags, and any deletion drafts you choose to create. That's it.
We don't keep your actual emails or their headers. As the scan reads each header to work out who sent it, that header is used and then discarded; it never lands in a database. Your Google sign-in is stored as an encrypted token, never in plain text, and only so you don't have to reconnect every visit.
What we never do
- We never read the body or attachments of your email.
- We never use your data, in any form, to train machine-learning or AI models.
- We never sell, rent, or share your data with advertisers or data brokers.
- We never store passwords for any third-party service.
AI processing
Tombstone uses a large-language-model API for three narrow tasks: sorting companies into categories, ranking your breach exposure into an action plan, and drafting the personalized paragraph of a deletion letter. Only minimal, task-specific text is ever sent: a bare domain name for categorization; public breach descriptors (name, date, severity) for the action plan; and a short set of facts for a letter (the company name and the dates you interacted with it). We never send message bodies, subject lines, or your email address to the model, and nothing is used to train any model.
We require a no-training, zero-data-retention configuration from our LLM provider: under that configuration the provider does not retain the request and does not train on it. The only things ever sent about a company found in your Gmail are its name, its domain, and the first/last dates it emailed you (used to draft a deletion letter), never message bodies, subject lines, or your email address.
Your control
You can disconnect at any time. Logging out revokes Tombstone's access token with Google directly, not just your local session. Deleting your account from the Account page removes your user record and cascades to all associated data in our database.
Data sharing
The only third parties that receive any of your data are the service providers that make the tool work: Google (the source of your authorized Gmail metadata), LeakCheck and HaveIBeenPwned (breach lookups, keyed on email), and our LLM provider (classification and letter drafting, as described above). We do not share data for advertising.
Contact
Questions about your data can be sent via the contact form.