Mamaflow logo

Privacy Policy

Last updated: 2026-07-10. Status: DRAFT for Google OAuth verification. Replace bracketed placeholders and host at a public URL (e.g. https://mamaflow.app/privacy or the Railway domain) before submitting for verification.

Mamaflow ("we", "our") helps parents turn family-related emails into a calendar and to-do list. This policy explains what data we access, what we do with it, and — just as importantly — what we never do with it.

The short version

What we access

With your explicit consent, Mamaflow requests read-only access to your Gmail (gmail.readonly). We also receive your email address and basic profile from Google Sign-In to create your account.

How the processing works

  1. We first read only message headers (sender, subject, date). Senders on our financial/promotional blocklist are excluded before their message content is ever fetched.
  2. For remaining messages, the content is processed in memory to remove sensitive numbers (credit cards, bank accounts, government IDs) before any further processing.
  3. The redacted text is sent to Anthropic's Claude API solely to extract structured event data (Anthropic does not train on this data per their commercial API terms).
  4. Only the structured result is stored: event title, date, time, location, child name as written, event category, sender address, and a link back to the email in your own Gmail.

What we never do

Limited Use disclosure (Google API Services)

Mamaflow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Gmail data is used only to provide the user-facing calendar/to-do feature the user requested; it is not used for advertising; it is not sold; humans do not read it except with your explicit consent, for security purposes, or to comply with law; and transfers are limited to the processing described above (Anthropic as a data processor for extraction).

Data retention & deletion

Sub-processors

Provider Purpose
Google (Gmail API, Sign-In) mailbox access you authorize; authentication
Anthropic (Claude API) event extraction from redacted text (no training on data)
Railway (hosting) + PostgreSQL application hosting and storage of structured items
Google Cloud Secret Manager server-side storage of OAuth tokens
Google Firebase Cloud Messaging (FCM/APNs) delivery of reminder notifications; notification text contains the titles/times of your extracted items (e.g. an event name), transmitted only to your registered devices — never used for advertising

Contact

[Contact email — e.g. privacy@optimacore.io]

Changes

We will post any changes here and update the date above. Material changes will be announced in the app.