Your email stays yours.
Quiet is an early-access email subscription manager. This page explains the data used by this version.
What Quiet accesses
With your permission, Quiet reads email metadata: sender, subject, date, mailing-list identifiers, authentication results, and unsubscribe headers. It does not request access to email bodies, attachments, sending email, or deleting email. Google handles sign-in; Quiet never receives your email password.
What is stored
Quiet stores your provider account identifier, email address, display name, encrypted access and refresh tokens, subscription metadata, scanned message identifiers to avoid duplicates, and a record of your actions. Unsubscribe links are encrypted because they can include personal identifiers. Other subscription metadata is stored in the application database.
How data is used and shared
Data is used to show your subscriptions, keep the senders you choose, and process the unsubscribe actions you request. Quiet’s application runs on Vercel and stores data in Neon Postgres. Google supplies the email headers. When you select Unsubscribe, Quiet sends the sender’s prescribed unsubscribe request to its endpoint. If a sender requires a simple website confirmation, Quiet can open that page and submit its unsubscribe form on your behalf after you click Unsubscribe. Quiet does not run the sender’s scripts or share your Google tokens with it. Forms requiring a login, CAPTCHA, new personal details, or extra choices are left for you to complete. Email-only requests remain manual.
Quiet does not sell mailbox data, use it for advertising, or use it to train AI models. Use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Your controls
Your connected email address is part of your Quiet account record, so the service can identify your inbox and show your subscriptions. It is not added to a separate marketing or permanent visitor list. Deleting your workspace deletes this account record too.
From Email accounts, you can disconnect an inbox and delete its stored tokens, subscriptions, and scan history. You can also permanently delete your Quiet workspace, which removes its application records and sessions. Disconnecting does not delete email in your mailbox or reverse unsubscribe requests already sent.
Quiet attempts to revoke Google access when you disconnect a Google account. You can also revoke access in your Google account settings. Deleting a Quiet workspace removes the stored access tokens; provider-side consent may remain until you remove it at the provider.
Retention and cookies
Account and subscription data is retained until you disconnect the account or delete the workspace. Essential cookies maintain your signed-in session and protect the connection flow. Sessions expire after 30 days; connection attempts expire after 10 minutes. No advertising cookies or third-party analytics are added by Quiet. Your browser also remembers whether it has shown our optional support prompt, so it does not keep asking. Buy Me a Coffee opens only when you choose its link, and handles donations under its own privacy policy.
Early access
Unsubscribe availability depends on the sender. An accepted request means its server accepted the request, not that all future mail has already stopped. Google access also depends on provider approval and your organization’s policies.
For product questions or privacy requests, contact Alex at alex@fallx.io.