Privacy Policy
DASH (the "App") is an iOS application provided by an individual developer (GitHub: skier-song9, the "Developer"). This policy explains what information the App processes, for what purpose — and what it does not process. This is a translation provided for convenience; if it conflicts with the Korean version, the Korean version prevails.
1. Information processed
| Item | Details | Stored in |
|---|---|---|
| Google account info | Email address (openid, email scopes) | On device |
| Gmail data | Sender, subject, received time, labels, and a body snippet of unread mail
— gmail.modify scope |
On device (cache) |
| OAuth tokens | Tokens linking your Google account and AI coding tool (Claude Code, Codex) accounts | iOS Keychain (encrypted) |
| AI service usage | Usage limits and remaining quota for Claude Code · Codex | On device |
2. Purposes of use
- Reading Gmail metadata to display the unread mail list and count.
- Classifying mail importance using rules and AI triage.
- Marking mail you have checked as read in Gmail, via the
gmail.modifypermission. The App never sends, deletes, or makes any change to mail other than marking it read. - Reading each service's usage API to display AI coding tool limits.
3. Transient transmission for AI triage
To classify mail importance, the following information is sent through a relay server operated by the Developer (Cloudflare Workers) to an external LLM (large language model) API:
- Sender name and address, subject, the beginning of the body (up to 220 characters), and signals such as bulk-mail markers
This transmission is transient — it exists only while the classification response is produced. The relay server is stateless and records nothing, and the LLM provider the Developer uses does not train models on API inputs or outputs under its commercial API terms. Full mail bodies and attachments are never transmitted.
4. Compliance for Google user data (Limited Use)
The App's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Gmail data is used only to provide the user-facing features in Section 2.
- Gmail data is not used for advertising.
- Gmail data is not sold or transferred to third parties.
- Gmail data is not used to develop, improve, or train generalized AI/ML models. The AI triage in Section 3 is transient processing solely to provide the feature you requested.
- No humans read Gmail data, except with your explicit consent, for security purposes, or to comply with legal obligations.
5. Storage and security
- All data is stored on your device. The Developer operates no server that stores user data.
- OAuth tokens are stored encrypted in the iOS Keychain.
- All network traffic is encrypted with TLS (HTTPS).
- The App contains no advertising, tracking, or analytics SDKs.
6. Third parties and processors
The Developer does not provide or sell user data to third parties. Processing delegated to provide features:
| Processor | Purpose | Scope |
|---|---|---|
| Cloudflare, Inc. | API relay | Stateless forwarding of triage requests (nothing stored) |
| LLM API provider | Mail importance triage | Transient processing of the minimum information in Section 3 |
Error reports sent to the Developer automatically redact personal information such as email addresses and tokens.
7. Retention and deletion
- On-device data is deleted when you delete the App.
- Disconnecting an account in the App's settings immediately deletes that account's tokens and cache.
- You can revoke the App's Google account access at any time in your Google account security settings.
8. Children's privacy
The App is not directed at children under 14 and does not knowingly collect their personal information.
9. Changes to this policy
Changes will be posted on this page; material changes will be announced in the App.
10. Contact
Privacy inquiries: 0603paul@gmail.com