Security & Privacy Architecture
Learn how Pyramail protects your data, handles permissions, and respects your privacy inside Google Workspace.
1. Privacy-First Architecture
Pyramail is engineered as a direct execution layer within Google Workspace. Rather than copying your spreadsheets and recipient lists onto external database servers, Pyramail operates in-session, communicating directly with Google APIs to send your personalized email campaigns.
2. What Pyramail Can & Cannot Do
Here is a breakdown of what Pyramail is permitted to do and what is strictly impossible:
- Sends personalized emails directly through your Gmail / Google Workspace account when you click Send.
- Reads columns from the active Google Sheet in your current browser session to replace merge tags.
- Fetches attachment files exclusively from public Google Drive folder URLs you explicitly provide in your campaign settings.
- Syncs open and click engagement events back to your spreadsheet columns if tracking is enabled.
- CANNOT read your incoming emails, existing inbox conversations, or private email drafts.
- CANNOT browse, search, or access personal files in your Google Drive.
- CANNOT store, harvest, or sell your recipient contact lists or spreadsheet data.
- CANNOT view or store your credit card or payment credentials (processed via Lemon Squeezy).
- CANNOT use your email content to train AI models.
3. Data Handling & Zero Contact Retention
Your recipient lists, names, and custom fields are processed entirely in your local browser session and within Google's cloud infrastructure. Pyramail does not maintain a database of your spreadsheet rows.
Account identifiers (such as your Google user email address) are stored solely to verify your subscription tier and manage your account status. Temporary email tracking events are purged automatically once synced to your spreadsheet.
4. AI Assistant Data Policy
Pyramail provides AI-assisted email drafting and refinement powered by Google Gemini and Groq. When you submit a prompt to generate or refine an email, the text is transmitted via secure encrypted channels (TLS 1.3), processed in real time, and returned directly to your compose window. Neither Pyramail nor our AI providers use your prompts or email content to train public AI models.
5. Infrastructure & Sub-processors
Pyramail utilizes industry-leading infrastructure providers to ensure high availability and security:
6. Revoking Access & Uninstallation
You maintain complete authority over your Google account. You can uninstall Pyramail at any moment from the Google Workspace Marketplace, or revoke its permissions immediately through your Google Account Security Permissions page (myaccount.google.com/permissions). All locally cached template settings inside Google Apps Script are automatically purged upon uninstallation.
7. Security Contact & Reporting
If you are a security researcher, admin, or user with questions regarding Pyramail's security architecture or wish to report a security vulnerability, please email our team directly at:
Email: [email protected]