Privacy Policy
Effective August 11, 2026 · Last updated August 13, 2026
Cheers is operated by Principle Technologies, Inc. (“Cheers,” “we,” “us,” or “our”), a Delaware corporation. This policy explains what information we collect, why we collect it, who we share it with, and what control you have over it.
If you have questions about anything here, email us at support@cheers.so. For security matters, email security@cheers.so.
The short version
Cheers connects to your Gmail account with your permission, uses AI to work out what in your inbox actually needs your attention, and talks to you about it in a chat — on the web and, where available, over iMessage. When you ask it to, it replies to emails on your behalf.
To do that, we need to read your email. We take that seriously:
- We don't store the contents of your emails. We read them when we need to, and keep identifiers, the addresses involved, and notes we write in our own words.
- We never sell your data, and we never use it for advertising.
- We never use your email content to train AI models, and neither do our AI providers.
- Everything is encrypted in transit and at rest, and the keys to your Google account are encrypted a second time, separately from the database they sit in.
- You can disconnect Cheers from your Google account at any time, and you can delete your account and all associated data whenever you want.
- We ask for the narrowest Google permission that supports the product.
The rest of this document is the detail.
Information we collect
Google account information. When you sign in with Google, we receive your email address, and a unique identifier for your Google account. We use this to create and identify your Cheers account.
Gmail content. With your explicit consent, we access the contents of your Gmail mailbox through the Gmail API. This includes message subjects, bodies, sender and recipient addresses, timestamps, labels, thread structure, and information about attachments. We access this to identify what needs your attention, to summarize it for you, and to draft and send replies you approve.
We do not store the contents of your emails. When Cheers needs to work with a message, it retrieves that message from Gmail at that moment, processes it, and discards the content. No body, subject line, or preview is written to our database. What we keep is the Gmail message and thread identifiers, the labels we applied, timestamps, the names and addresses of the people in a thread along with which of them sent which message, and notes Cheers writes in its own words. Your mailbox stays in your mailbox.
One consequence worth knowing: because we hold identifiers rather than copies, if you delete a message in Gmail, Cheers can no longer retrieve it.
How Cheers knows when mail arrives. While your Gmail is connected, we ask Google to notify us when new messages reach your inbox, so that Cheers can be useful without waiting for you to ask. Those notifications travel through Google Cloud Pub/Sub, a Google service, and each one contains your email address and a marker of your mailbox's position — never the message itself. Google retains undelivered notifications for up to seven days before discarding them.
When we receive one, we read only what is needed to record who is involved in the thread and when they wrote: participants, timestamps, and which of them sent which message. We do not retrieve or store the subject or the body as part of this, and no AI model is involved. It is what lets Cheers tell you which conversations are waiting on you.
This stops the moment you disconnect. Pressing “Stop Cheers” or deleting your account cancels the notification request with Google before revoking our access, so nothing continues to arrive after you have withdrawn consent.
Notes Cheers writes. So that it is useful over time rather than starting from nothing each day, Cheers keeps a short note on each email thread — what it is about and what it believes is still outstanding — and a few short documents about you, such as how you write, who matters to you, and any standing instructions you have given it. These are written by an AI model in its own words rather than copied from your mail, and their length is capped in our database.
Your phone number and messages. So we can reach you over iMessage, we store your phone number and the conversation between you and Cheers, including your instructions and our responses. Because Cheers talks to you about your email, these conversations contain summaries of and references to your messages.
Those conversations and the notes above are the only places where text drawn from your email is stored. All of them hold our description of your mail rather than a copy of it, and all are deleted when you delete your account.
Technical and usage information. We collect standard operational data such as IP address, browser and device type, timestamps, and records of errors and API activity. We use this to operate the service, diagnose problems, and detect abuse. We do not include message content in our application logs.
We do not collect payment information directly; if and when we charge for Cheers, payments will be handled by a third-party processor disclosed here at that time.
How we use your information
We use the information above to:
- Authenticate you and maintain your account
- Read incoming mail and determine what warrants your attention
- Summarize messages and surface them to you over iMessage or the web
- Draft replies and, at your direction, send them from your account
- Apply and modify Gmail labels to organize your mailbox
- Keep notes about your threads and your preferences, so Cheers is useful over time
- Communicate with you about the service, including security notices
- Detect, investigate, and prevent abuse, fraud, and security incidents
- Comply with legal obligations
We do not use your information for advertising, and we do not build advertising profiles.
Google user data
This section governs our use of data obtained through Google APIs and takes precedence over any general statement elsewhere in this policy.
Scopes we request, and why.
| Scope | What it permits | Why Cheers needs it |
|---|---|---|
gmail.modify | Read, organize, compose, and send mail; it does not permit permanent deletion | Reading incoming mail to triage it, applying labels to organize your inbox, and sending replies you approve |
openid, userinfo.email | Your email address and a stable account identifier | Creating and identifying your account |
We request gmail.modify because Cheers both reads and acts on your mail. A read-only scope would not let us apply labels or send the replies you ask for. gmail.modify does not allow Cheers to permanently delete your messages.
Limited Use. Cheers's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and without limiting the above:
- We use Google user data only to provide and improve the user-facing features of Cheers that you have chosen to use.
- We do not transfer Google user data to third parties except as necessary to provide those features, for security purposes, or to comply with applicable law.
- We do not use Google user data for serving advertising of any kind.
- We do not sell Google user data.
- We do not allow humans to read your Google user data, except with your explicit consent for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized.
- We do not use Google user data, or any data obtained through Google Workspace APIs, to develop, improve, or train generalized (non-personalized) artificial intelligence or machine learning models.
Revoking access. You can disconnect Cheers from your Google account at any time, either from within Cheers or at myaccount.google.com/permissions. Revoking access stops all future processing immediately. To also delete data we have already stored, see “Deleting your data” below.
How we use AI
Cheers uses large language models to read, classify, summarize, and draft responses to your email. This means the content of your messages is sent to our AI provider for processing.
We use Anthropic's Claude models, accessed through Anthropic's API.
Under our agreement with Anthropic:
- Your email content is not used to train or improve any AI model.
- Processing is automated. Model outputs are returned to Cheers and surfaced to you; no human at Anthropic reviews your content in the ordinary course.
- We send only the content needed for the specific task at hand rather than bulk exports of your mailbox.
AI output can be wrong. Cheers asks for your approval before sending email on your behalf, and you remain responsible for anything sent from your account.
Who we share information with
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We disclose it only to the service providers below, each of which processes it on our behalf under a written agreement, and only as needed to operate Cheers.
| Provider | Purpose | What it receives | Privacy policy |
|---|---|---|---|
| Google LLC | Source of email data; authentication; new-mail notifications via Cloud Pub/Sub | OAuth tokens; API requests; your email address in notifications | policies.google.com/privacy |
| Anthropic PBC | AI processing of email content | Email content and your instructions | anthropic.com/privacy |
| Amazon Web Services, Inc. | Application hosting, container registry, secrets, and logs | All service data in transit and at rest | aws.amazon.com/privacy |
| Supabase, Inc. | Database and authentication | Account data, tokens, message and conversation data | supabase.com/privacy |
| Linq App Inc. | iMessage delivery | Your phone number and the messages exchanged with Cheers | linqapp.com/policies/privacy-policy |
| Vercel Inc. | Web application hosting | Web request data | vercel.com/legal/privacy-policy |
We may also disclose information when required by law, to enforce our terms, to protect the rights, property, or safety of Cheers, our users, or the public, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you before your information becomes subject to a different privacy policy.
How long we keep your information
| Data | Retention |
|---|---|
| Google OAuth tokens | Until you disconnect or delete your account, at which point they are revoked and deleted |
| Email content, including subject lines | Not stored. Retrieved from Gmail when needed, processed, and discarded |
| Gmail message and thread identifiers, labels, timestamps, and the addresses of people in a thread | While your account is active; deleted within 30 days of a deletion request |
| Notes Cheers writes about your threads and about you | While your account is active; deleted within 30 days of a deletion request |
| Conversations between you and Cheers, including summaries of your email | While your account is active; deleted within 30 days of a deletion request |
| Messages held by our iMessage provider | Permanently deleted within 24 hours of sending |
| New-mail notifications held by Google Cloud Pub/Sub (your email address and a mailbox position) | Discarded once delivered, and within 7 days regardless |
| Application and security logs | 30 days; these contain no message content |
| Encrypted backups | Purged within 90 days |
We may retain information longer where required by law or to resolve disputes, in which case we retain only what is necessary for that purpose.
Your choices and rights
Disconnecting Google. Revoke Cheers's access at any time from within the app or from your Google Account permissions page.
Deleting your data. You can delete your account from within Cheers, or email support@cheers.so. When you do, we revoke your Google OAuth tokens immediately and, within 30 days, delete your account data, your conversation history, and the notes Cheers has written about your threads and about you. Encrypted backups are purged on the schedule above.
Access and correction. You can request a copy of the personal information we hold about you, or ask us to correct it, by emailing support@cheers.so.
If you are in the EEA, UK, or Switzerland. You have rights under the GDPR to access, rectify, erase, restrict, and port your personal data, and to object to processing. Our legal basis for processing is your consent for accessing Gmail data, and our legitimate interests in operating and securing the service. You may withdraw consent at any time, and you have the right to lodge a complaint with your local supervisory authority.
If you are a California resident. You have rights under the CCPA to know what personal information we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of. We will not discriminate against you for exercising your rights.
To exercise any of these rights, email support@cheers.so. We will respond within the timeframe required by applicable law.
Security
We protect your information with measures including:
- Encryption in transit. All connections to Cheers use TLS 1.2 or higher, and our own connections to Google, our AI providers, our database, and our messaging provider are encrypted in the same way. We do not transmit your data over unencrypted channels.
- Encryption at rest. All stored data is encrypted on disk.
- A second layer for your Google credentials. Your Google OAuth tokens are encrypted at the application layer with a key held separately from the database, so that database access alone does not yield access to your mailbox.
- Separation between accounts, enforced by the database. Our database only returns rows belonging to the user whose request is being served, rather than relying on our code to filter correctly every time. Automated tests enforce this, and also fail our build if anyone adds a place in the database capable of holding email content.
- Access controls limiting production access to authorized personnel, with multi-factor authentication required
- Network protections including a web application firewall and rate limiting
- Automated dependency and code scanning in our development pipeline
- Logging and monitoring of security-relevant events
No system is perfectly secure. If you believe you have found a vulnerability, please contact security@cheers.so.
International transfers
We are based in the United States and process information there. If you access Cheers from outside the United States, your information will be transferred to and processed in the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum.
Children
Cheers is not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact support@cheers.so and we will delete it.
Changes to this policy
We may update this policy. If we make a material change to how we handle your information, we will notify you by email or in the app before it takes effect, and we will update the date at the top. Continued use after a change takes effect means you accept the updated policy.
Contact us
Principle Technologies, Inc.
3454 Chieri Place, San Jose, CA 95148
General and privacy: support@cheers.so
Security: security@cheers.so