Privacy Policy

Last updated: August 5, 2026

What Bump is

Bump connects to your Gmail, finds sent emails that never got a reply, drafts follow-ups using AI, and lets you review every draft before anything is sent. That is the entire product. This policy explains what data we touch and what we do with it.

What we collect

  • Google profile info — your name, email address, and profile photo, provided by Google when you sign in with OAuth.
  • Gmail message content — we read your sent messages and their threads (read-only) to identify unanswered emails and draft follow-ups. We also use send access to deliver follow-ups you explicitly approve.
  • OAuth refresh token — a credential that lets Bump access your Gmail on your behalf. This token is encrypted with AES-256-GCM at the application layer before it is written to our database. It is never stored in plaintext.
  • Draft and outcome records — the follow-up drafts shown in your review queue, your edits and decisions, thread identifiers, recipient addresses, and whether a sent follow-up later received a reply. These records make review history, duplicate prevention, and outcome reporting possible.

What we do with it

  • Scan your sent folder for threads with no reply
  • Draft follow-up emails using AI (three independent variants per thread)
  • Present drafts for your review with confidence stamps
  • Send the follow-ups you approve, in-thread, from your Gmail
  • Send account notifications you enable, such as a drafts-ready alert or weekly outcome summary. These contain counts and Bump links, never thread content.

What we do NOT do

  • We do not sell your data to anyone, ever.
  • We do not share your data with third parties for their own purposes. Limited service providers process data only to operate Bump, including Google, Anthropic, our database host, Stripe for billing, and Resend for enabled account notifications.
  • We do not use your emails for advertising or ad targeting.
  • We do not train AI models on your email content.
  • We never send a follow-up from your Gmail without your explicit approval. Account notifications follow the choices in your Settings.

Storage and security

Your OAuth refresh token is encrypted with AES-256-GCM before being stored. Our database is hosted on managed PostgreSQL infrastructure. Gmail threads are processed in memory during a scan. Bump stores only what is needed for your review queue, decision history, duplicate prevention, and outcome tracking; it does not retain a separate copy of your mailbox.

Cookies

We use a session cookie to keep you logged in. Bump does not use advertising cookies or third-party ad scripts.

Your controls

From Settings, you can download a JSON archive of your Bump data, disconnect Gmail, change notification preferences, or permanently delete your account without contacting support. Account deletion cancels active Bump billing, attempts to revoke the Google grant, and erases your profile, credentials, drafts, events, outcomes, usage records, and sessions. You can also revoke Bump directly from your Google account settings.

Contact

Questions about this policy? Email rashidalikhan99@gmail.com.