Privacy Policy
Last updated 19 August 2026
VizFeed is a feed of small agents that keep running for you. This policy explains what we store, what the one agent that connects to your Google account reads, how long anything is kept, and how to take it all back. It is written in specifics on purpose. If you want the short version: we store what an agent needs to do its work and nothing we do not need, we do not sell anything to anyone, and we do not run ads.
VizFeed is operated from vizfeed.app. Questions, requests, and complaints go to privacy@vizfeed.app.
What VizFeed stores
Your account
Your email address, a username, and a display name. Sign-in is handled by our identity service, which holds your credentials; we hold the account record that your agents belong to. If you sign in with Apple or Google, we receive the email address that sign-in gives us and nothing else from it.
The agents you set up
For each agent: which agent it is, the answers you gave when you set it up — the product you are watching, the price you named, the city, the time you want to hear from it — and whether it is running or paused. An agent also keeps a small note to itself between checks so it can tell what changed since last time.
What your agents produced
The result of a check, as it appears on the card in your feed. Your feed is yours: results from your agents are shown to you, not to other people.
Running the service
- If you turn on notifications, a device token so we can send them. It identifies a device, not you.
- Ordinary server logs and error reports, kept to keep the service up and to investigate abuse. We do not put the contents of your mail, or anything an agent read on your behalf, into logs.
Connecting your Google account
One agent connects to a Google account: the morning mail summary. It is the only agent in VizFeed that asks for access to any account of yours. Nothing is connected unless you choose that agent and approve it on Google’s own screen.
The one permission we ask for
We request a single Google OAuth scope, https://www.googleapis.com/auth/gmail.readonly. It is read-only. We do not request permission to send, modify, delete, or label mail, and we could not do any of those things with the access we have.
We ask for this scope because it is the narrowest one Google offers that permits reading the message list. There is no metadata-only Gmail scope; the read-only scope is the minimum that lets the agent see that mail arrived and who it is from.
What the summary actually reads
This is a ceiling, not a wish list. The agent is built so that it cannot read more than the following, and it reads less whenever less will do.
- Who wrote to you, the subject line, the date, and whether a message is unread. This is the default and it is all the agent needs.
- A one-line preview of each message only if you switch previews on yourself. It is off when you start, and you can switch it back off whenever you like.
- Message bodies are never opened — not to check a detail, not to resolve an ambiguity. If a subject line is unclear, the agent writes a vaguer summary rather than looking inside.
The agent is also instructed never to repeat a sign-in code, one-time passcode, account number, or anything else that looks like a secret, even when it appears in a subject line — such a message is referred to by sender and purpose only.
What it is used for, and where it appears
Solely to write your own summary card. The mail the agent reads is turned into the digest that appears in your feed and, if you have them on, the notification that tells you it is ready. It goes nowhere else. It is not used to build a profile of you, to train models, to rank anyone else’s feed, or to recommend anything.
To write the summary in readable English, the agent sends what it read — sender names, subject lines, dates, and previews if you turned them on — to the model provider that writes the wording, which returns the summary. Under our agreement with that provider, what we send is not used to train their models. This is the only third party that sees anything derived from your mail, and it sees it only for as long as it takes to answer.
How long it is kept
Your latest summary is kept so the card has something to show when you open the app, along with a small note recording where the agent got to, so tomorrow’s summary knows what is new. Each new summary overwrites the last one — we do not build an archive of your mail history, and there is no back catalogue of old digests to leak. When you remove the agent, its results go with it; the app says so before you confirm.
Disconnecting the account, on its own, stops new summaries but leaves the last one on your card until you remove the agent or delete your account. If you want it gone immediately, remove the agent.
Your Google credentials
When you approve the connection, Google issues us a refresh token. It is encrypted before it is stored — sealed under a key held for your agent alone — and is unsealed only in memory, inside the isolated process that runs your agent, at the moment a check happens. It is never written to logs, never shown in the app, and never sent to your device or to any third party. Our main database holds no token material at all; a copy of it would give no one access to anyone’s mail.
No ads. No sale.
We do not serve ads in VizFeed, and we do not use anything read from your Google account for advertising of any kind — not retargeting, not personalised or interest-based advertising. We do not sell your data, and we do not transfer it to data brokers.
Human access
No one at VizFeed reads your mail or your summaries as a matter of course. There is no dashboard for it and no routine that samples it. A human may access this data only in the narrow cases Google’s Limited Use requirements permit:
- with your explicit prior agreement, for specific messages — for example if you ask us for help with something the summary got wrong;
- where it is necessary for security purposes, such as investigating abuse or a suspected compromise;
- to comply with applicable law; or
- where the data has been aggregated and anonymised, and is used for internal operations.
Limited Use
VizFeed’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Taking it back
You can end this at any time. There are two places to do it, and they do different things, so it is worth knowing which is which.
- In VizFeed — open the mail summary agent and disconnect it, or remove the agent entirely. We destroy our stored copy of the token: the encrypted value is overwritten, and the agent can no longer reach your mail.
- At Google — go to myaccount.google.com/permissions and remove VizFeed’s access. This withdraws the permission at Google itself, and it works whether or not you still have the app.
Disconnecting inside VizFeed destroys our copy but does not by itself remove the permission recorded in your Google account. If you want the grant gone from both sides — and we think you should — do both. We will not pretend one covers the other.
Either way, the agent stops producing summaries. It will not carry on quietly with stale data: the card says plainly that it lost access to your account and offers to reconnect, rather than showing you yesterday’s summary as though it were today’s.
What deletion removes. Removing the agent deletes the summaries it produced, along with its settings and the note it kept between checks. Deleting your VizFeed account from Settings deletes your account record, your agents, their settings, and their results. Because a connected account is a permission granted at Google, remove VizFeed’s access at the link above as well to be certain it is fully withdrawn.
Who else sees anything
We do not sell personal data and we do not share it for anyone else’s marketing. Data is handled on our behalf by a small number of providers, each only for the agent named:
- Our cloud provider — hosts the service and its databases.
- Our model provider — writes the wording of a card from what an agent found, as described above.
- Apple and Google push services — deliver notifications you asked for.
We may also disclose data where the law requires it, or where it is necessary to investigate abuse or protect people from harm. If VizFeed is ever acquired, information received from Google APIs would only transfer with your explicit prior consent.
How it is protected
- Traffic between your device and VizFeed is encrypted in transit.
- Credentials for connected accounts are encrypted before storage and decrypted only in memory while a check runs.
- Our databases are not reachable from the public internet, and access is limited to the services that need it.
- We keep what an agent read out of logs and error reports.
No service can promise perfect security, and we will not pretend otherwise. If something goes wrong that affects you, we will tell you.
Your choices
- See and change an agent’s settings, or pause it, from the agent itself.
- Remove an agent — its results go with it.
- Disconnect a connected account without deleting your VizFeed account.
- Delete your VizFeed account from Settings.
- Ask us for a copy of what we hold about you, or ask us to correct or delete it, by writing to privacy@vizfeed.app. Depending on where you live you may have these as legal rights; we will honour the request either way.
Children
VizFeed is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us data, write to us and we will delete it.
Changes to this policy
If we change what an agent reads or what we do with it, we will change this page and move the date at the top. Material changes to how we handle data from a connected account will be told to you in the app before they take effect, not slipped in.