Privacy Policy
Effective July 27, 2026
DaySurface ("the Service") is operated by GPU-EVM LTD ("we", "us"). This
policy explains what data the Service accesses, how we use it, and the
choices you have. It applies to the hosted Service at https://daysurface.com
and the MCP endpoint at https://mcp.daysurface.com/mcp.
What the Service does
DaySurface is a Model Context Protocol (MCP) server. When you connect your Google account, it acts as a bridge between the AI client you choose (for example Claude, Cursor, or another MCP host) and the Gmail API, letting that client read, organize, draft, and send email on your behalf at your direction.
Data we access
- Google account identity — via the
openidandemailscopes, we receive your Google account email address to identify your connection. - Gmail content and metadata — via the
https://www.googleapis.com/auth/gmail.modifyscope, the Service can read messages, threads, labels, and drafts, and can modify labels, archive, compose drafts, and send mail. These actions are performed only in response to requests from the AI client you have connected and authorized. - OAuth tokens — the refresh token Google issues so the Service can maintain your authorized connection. Access tokens are minted on demand for a single request and are never stored.
How we use it
We use Google user data solely to provide the user-facing features of the Service: retrieving the email data your connected AI client requests and carrying out the email actions you direct. Gmail data is returned to the AI client you connected and is not used for any other purpose.
No server-side AI processing
Your email is never sent to an AI model by us. The Service performs no LLM inference on Gmail content: ranking and filtering in the Service are deterministic code, and all AI processing happens in the AI client you chose and connected, under that client's own privacy terms. This is stronger than a promise not to train on your data — your messages do not reach a model on our side at all.
Push notifications and webhooks
The Service offers an optional real-time pipeline. It is off until you turn it on, and it moves Gmail data to two places beyond your AI client:
- Google Cloud Pub/Sub — if you start a mailbox watch, Gmail publishes a notification to a Google Cloud Pub/Sub topic we operate, which delivers it to the Service. These notifications carry only your Google account email address and a Gmail history cursor, not message content; the Service then fetches the new message's details from the Gmail API. Pub/Sub is a Google service and the data stays within Google's infrastructure until it reaches us.
- Webhook endpoints you register — if you subscribe a webhook URL, the Service sends an HTTPS POST to that URL for each new message, containing the message and thread identifiers, labels, and the sender, subject, date, and Gmail snippet (a short preview) of the message. Full message bodies are not sent. Requests are signed with a per-endpoint secret so your receiver can verify them. The destination is yours to choose, and once data is delivered there it is governed by whoever operates that endpoint, not by this policy. You can remove a subscription at any time from your settings, which stops future deliveries.
To support retries, pending and recently attempted deliveries and their event payloads are stored by the Service until delivery completes or is abandoned. They are deleted when you disconnect (see below).
Limited Use disclosure
DaySurface's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- use Google user data to serve advertising;
- sell Google user data;
- transfer or use Google user data for purposes other than providing or improving the Service's user-facing features;
- allow humans to read Google user data unless we have your affirmative agreement for specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data has been aggregated and anonymized; and
- use Google user data to develop, improve, or train generalized or non-personalized AI and/or machine learning models.
Storage and retention
Your Google refresh token is stored encrypted at rest so your connection persists between sessions. Message data requested by your AI client is passed through rather than stored: we keep no copy of message bodies. Two narrow exceptions are stored per user, both created only by features you use:
- the curation ledger — short summaries your AI client derived while triaging a thread, kept encrypted at rest so repeat requests do not re-read your mailbox; and
- webhook event payloads — the message details listed above, kept while a delivery is pending or recently attempted.
When you disconnect (see below) we revoke your token with Google, erase the stored token itself, and delete your curation ledger and your webhook events and pending deliveries.
Subprocessors
We rely on the following processors to operate the Service:
- Google — the Gmail API, account authentication, and Google Cloud Pub/Sub for mailbox push notifications.
- Railway — application hosting and managed database.
- WorkOS (AuthKit) — account authentication for the Service.
Your choices and deletion
You can revoke the Service's access at any time by disconnecting within your AI client, by emailing [email protected], or directly from your Google account permissions. Disconnecting within your AI client erases the stored token for that connection and deletes the curation ledger and webhook events described above. To request deletion of any other data we hold about you, email the address above.
Changes
We may update this policy; material changes will be reflected by a new effective date above.
Contact
Questions about this policy or your data: [email protected].
The Service is operated by GPU-EVM LTD, a company registered in England and Wales, at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE.