← Back to DaySurface

Privacy Policy

Effective July 27, 2026

DaySurface ("the Service") is operated by GPU-EVM LTD ("we", "us"). This policy explains what data the Service accesses, how we use it, and the choices you have. It applies to the hosted Service at https://daysurface.com and the MCP endpoint at https://mcp.daysurface.com/mcp.

What the Service does

DaySurface is a Model Context Protocol (MCP) server. When you connect your Google account, it acts as a bridge between the AI client you choose (for example Claude, Cursor, or another MCP host) and the Gmail API, letting that client read, organize, draft, and send email on your behalf at your direction.

Data we access

How we use it

We use Google user data solely to provide the user-facing features of the Service: retrieving the email data your connected AI client requests and carrying out the email actions you direct. Gmail data is returned to the AI client you connected and is not used for any other purpose.

No server-side AI processing

Your email is never sent to an AI model by us. The Service performs no LLM inference on Gmail content: ranking and filtering in the Service are deterministic code, and all AI processing happens in the AI client you chose and connected, under that client's own privacy terms. This is stronger than a promise not to train on your data — your messages do not reach a model on our side at all.

Push notifications and webhooks

The Service offers an optional real-time pipeline. It is off until you turn it on, and it moves Gmail data to two places beyond your AI client:

To support retries, pending and recently attempted deliveries and their event payloads are stored by the Service until delivery completes or is abandoned. They are deleted when you disconnect (see below).

Limited Use disclosure

DaySurface's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:

Storage and retention

Your Google refresh token is stored encrypted at rest so your connection persists between sessions. Message data requested by your AI client is passed through rather than stored: we keep no copy of message bodies. Two narrow exceptions are stored per user, both created only by features you use:

When you disconnect (see below) we revoke your token with Google, erase the stored token itself, and delete your curation ledger and your webhook events and pending deliveries.

Subprocessors

We rely on the following processors to operate the Service:

Your choices and deletion

You can revoke the Service's access at any time by disconnecting within your AI client, by emailing [email protected], or directly from your Google account permissions. Disconnecting within your AI client erases the stored token for that connection and deletes the curation ledger and webhook events described above. To request deletion of any other data we hold about you, email the address above.

Changes

We may update this policy; material changes will be reflected by a new effective date above.

Contact

Questions about this policy or your data: [email protected].

The Service is operated by GPU-EVM LTD, a company registered in England and Wales, at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE.

Terms of Service