Last updated 9 September 2026
Privacy policy
Eva Nova Email Triage is a private, single-user application used only by its owner. It is not available for public registration or third-party use.
Purpose and access
The application accesses the owner's Gmail account to perform a daily inbox review, separate known noise, surface messages that may need attention, and summarize senders that the owner has explicitly approved as news feeds.
Access is separated by purpose:
gmail.metadatareads message metadata used for triage.gmail.modifyis used by constrained code only for approved label operations.gmail.settings.basicis used only for owner-approved sender filters.
Protected messages
Protected, personal, sensitive, directly addressed, attachment-bearing, and uncertain messages are processed as metadata only. Full message bodies are fetched only for senders the owner has explicitly classified as approved news feeds. Attachment contents are not accessed.
Data stored
Private local state may contain sender, subject, received time, protection reason, sender-classification candidates, summaries from approved feeds, and direct Gmail links. Raw email bodies are not persisted in the dashboard state. OAuth credentials are retained on the owner's private server and are not included in this website or its source repository.
Data sharing and transfer
Google hosts the Gmail service and processes Gmail data as the email provider. The application does not route mailbox data through connector intermediaries, sell mailbox data, or use it for advertising. This public website receives no mailbox data.
Eva Nova Email Triage's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Actions the application does not expose
The application does not expose sending, replying, forwarding, attachment access, deletion, moving to Trash, archiving, or marking messages read.
Website privacy
This website uses no advertising, analytics, tracking scripts, cookies, forms, remote fonts, or externally hosted assets. Standard infrastructure request logs may still be generated by the hosting and network providers.
Control, revocation, and deletion
The owner can revoke the application's Gmail access from the third-party access controls in their Google Account. The owner can also stop the private service and delete its locally stored OAuth credentials, rules, and triage state.
Contact
Privacy or support questions may be submitted through the public support issue tracker. Do not include email contents, credentials, or other sensitive information in an issue.