Legal

Privacy Policy

Last updated: July 7, 2026

This Privacy Policy explains what personal data Erdos (formerly Mailflare / “Pointer AI”) collects, why we collect it, how we use and protect it, and the rights you have over it — including rights under the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable privacy laws. The short version: we collect only what the product needs, we never sell your data, and your Gmail stays yours.

1. Who we are

Erdos is the "data controller" of the personal data described in this policy. Contact for all privacy matters: privacy@erdos.app.

2. Data we collect

Account data

  • Name, email address, and password (stored as a salted hash by our authentication provider; we never see your plaintext password), or your Google account identifier if you sign in with Google.

Profile / onboarding data

  • Age, education level, school or university, grade level, research interests, and — if you choose to upload one — your resume. This data exists solely to personalize matching and email drafting.

Gmail connection data

  • If you connect Gmail, we store the OAuth access and refresh tokens Google issues and the Gmail address you connected. We use them only to send emails you approve and to refresh expired tokens.
  • We do not read, store, or analyze your inbox. Our access is limited to sending messages on your behalf and tracking the messages the service sends.

Campaign and usage data

  • The campaigns you create, the emails generated and sent, delivery status, and open events for emails sent through the service.
  • Basic technical logs (IP address, browser type, timestamps) for security and debugging.

We do not collect data from third-party data brokers, and we do not use your data for advertising.

3. How we use your data (and our legal bases)

  • To provide the service — matching professors to your interests, generating drafts, sending approved emails from your Gmail, and reporting opens. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
  • To operate AI features — your interests and profile text are processed by AI/embedding providers to compute matches and drafts. These providers act as our processors and may not use your data to train their models. Legal basis: performance of a contract.
  • To secure and improve the service — debugging, abuse prevention, aggregate analytics. Legal basis: legitimate interests (Art. 6(1)(f)).
  • To communicate with you — service emails (receipts, security notices). Marketing emails are sent only with consent and always include an unsubscribe link, consistent with CAN-SPAM and equivalent laws. Legal basis: consent (Art. 6(1)(a)) for marketing.
  • To comply with law — responding to lawful requests. Legal basis: legal obligation (Art. 6(1)(c)).

4. Google user data — Limited Use disclosure

Erdos's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Gmail access only to provide user-facing features (sending your approved emails); we do not transfer Gmail data to third parties except as necessary to provide those features, comply with law, or as part of a merger with notice to you; we do not use Gmail data for advertising; and no humans read your Gmail data except with your explicit permission, where necessary for security or legal compliance.

5. Open tracking — what recipients should know

Emails sent through Erdos may include a tracking mechanism that tells you when your message is opened. This processes limited technical data about the recipient's mail client. You are responsible for using open tracking lawfully in your jurisdiction; we surface it only to you, the sender, and do not build profiles of recipients.

6. Who we share data with

  • Service providers (processors): cloud hosting, database/authentication (e.g., Supabase), AI model providers for matching and drafting, and payment processors for paid plans. Each is bound by a data processing agreement and may use your data only on our instructions.
  • Google: when you connect Gmail, data necessarily flows through Google's APIs to send your messages.
  • Legal: when required by law or to protect rights, safety, or the integrity of the service.
  • Business transfers: in a merger or acquisition, with notice to you before your data becomes subject to a different policy.

We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising as those terms are defined by the CCPA/CPRA.

7. International transfers

We are U.S.-based and store data on servers that may be located in the United States. Where data of EU/UK/EEA or Swiss residents is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) with our processors.

8. Retention

  • Account and profile data: kept while your account is active; deleted within 30 days of account deletion, except minimal records we must keep for legal/accounting purposes.
  • Gmail OAuth tokens: deleted immediately when you disconnect Gmail or delete your account.
  • Resumes: kept until you replace or remove them, or delete your account.
  • Sent-email records and open events: kept while your account is active so your dashboard history works.
  • Security logs: up to 12 months.

9. Security

We use industry-standard measures: TLS encryption in transit, encryption at rest for stored data, hashed passwords, row-level access controls in our database, OAuth (never password storage) for Gmail, and least- privilege access internally. No system is perfectly secure; if a breach affects your personal data, we will notify you and regulators as required by law (including GDPR's 72-hour authority notification and applicable U.S. state breach notification statutes).

10. Your rights

Everyone

  • Access, correct, or delete your profile data at any time from the app (Onboarding/Settings), or by emailing us.
  • Disconnect Gmail at any time from Settings or via your Google Account security page.
  • Delete your account, which triggers the retention schedule above.

EU/UK/EEA residents (GDPR)

  • Rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior processing.
  • You may lodge a complaint with your local supervisory authority; we'd appreciate the chance to address concerns first at privacy@erdos.app.

California residents (CCPA/CPRA)

  • Rights to know, delete, correct, and to opt out of sale/sharing (we do neither). We will not discriminate against you for exercising these rights.
  • You may use an authorized agent; we will verify requests via your account email. We respond within 45 days as required.

Other U.S. states

  • Residents of states with comprehensive privacy laws (e.g., Virginia, Colorado, Connecticut, Utah, Texas) have similar rights of access, correction, deletion, and portability, and may appeal a refusal by replying to our decision email.

11. Children

Erdos is not directed to children under 13, and we do not knowingly collect personal data from them (COPPA). If you believe a child under 13 has created an account, contact us and we will delete it. Users under 18 should use the service with parental or guardian consent.

12. Cookies and similar technologies

We use strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies. Where analytics cookies are used, EU/UK visitors are asked for consent first, and you can clear or block cookies in your browser (the service may not function without the authentication cookie).

13. Do Not Track and opt-out signals

Because we do not track you across third-party sites or sell your data, there is nothing for DNT or Global Privacy Control signals to opt you out of; we honor the spirit of those signals by default.

14. Changes to this policy

We will post any changes here and update the date above. For material changes we will notify you by email or in-app notice at least 14 days before they take effect.

15. Contact

Privacy questions, requests, or complaints: privacy@erdos.app.