How your data is protected
Chiefy encrypts your email contents and mailbox access tokens before storing them. Chiefy connects to Gmail and Outlook over OAuth, so it never sees or stores your password — and you can revoke that access at any time.
Chiefy reads your email so it can draft, summarize, and organize it for you. That means it has to handle genuinely sensitive data, and we treat it that way. This page explains, in plain terms, how that data is protected — what’s encrypted, how Chiefy connects to your inbox, and the limits we put on what we keep.
Encryption at rest
Your email contents and mailbox access tokens are encrypted by our application before they are stored, using industry-standard encryption.
Encryption keys are managed in a dedicated, access-controlled key management service. We also encrypt database storage and backups.
Protected stored content includes:
- Your email message contents — the stored messages in the conversations Chiefy syncs, including their bodies.
- The credentials that connect to your mailbox — the access and refresh tokens for your Gmail and Outlook accounts (more on these below).
- Drafts and other content — stored draft text, summaries, assistant conversations, and writing-style data.
Encryption at rest protects stored data. Chiefy can decrypt it to draft, summarize, and organize your email; this is not end-to-end encryption. Data is also encrypted in transit over standard HTTPS/TLS whenever it moves between your browser, Chiefy, and the email providers.
How Chiefy connects to your inbox
Chiefy connects to Gmail and Outlook using OAuth 2.0 — the standard “Sign in with Google” / “Sign in with Microsoft” flow. This matters for a simple reason: Chiefy never sees or stores your email password. Instead, your provider issues Chiefy a scoped token that grants access to your mailbox, and you can withdraw that token whenever you like.
Mailbox access tokens are encrypted before storage, just like your email contents.
Because access works through a revocable token rather than a password, you stay in control. You can disconnect a mailbox from Chiefy, or revoke access entirely from your Google or Microsoft account settings — see Delete your data or revoke access.
Privacy & data
Control what Chiefy adds to your mail, the language it speaks, and access to your inbox.
Sent with Chiefy
Adds a small line at the end of drafts Chiefy writes for you.
Language
Controls Chiefy product text. Email drafts still follow the conversation language.
bookings@bayviewcottages.com
Disconnecting pauses sync and stops Chiefy reading this mailbox. You can reconnect anytime.
Sign out
End your session on this device.
Protecting your Chiefy sign-in
Chiefy rotates refresh tokens to help protect your sign-in. When we detect replay of a retired refresh token, we reject the request and revoke the related refresh tokens.
You can sign out of one device without signing out of the others.
Data minimization
The strongest protection for sensitive data is not collecting it in the first place. Chiefy is built to keep what it needs to do its job for you and avoid spreading sensitive details further than necessary:
- Scoped access. Chiefy requests the access it needs to read and draft mail on your behalf — not blanket access to your whole account.
- Tight credential handling. Mailbox tokens and your email contents are encrypted before storage. The application decrypts them when needed to connect to your mailbox and provide your features.
- Care with third parties. Where Chiefy works with outside services, it’s deliberate about what leaves our systems, and avoids passing along sensitive identifiers that aren’t needed for the task.
For the full picture of what Chiefy reads and what it deliberately leaves alone, see What Chiefy can and cannot access.
You stay in control
Encryption and careful handling are only half of trust — the other half is being able to walk away. You can disconnect any mailbox, sign out of a single device, or delete your data and revoke Chiefy’s access to your accounts entirely. When you revoke access at your email provider, the token Chiefy holds stops working. See Delete your data or revoke access for the steps.
Was this helpful?
Thanks for the feedback.