Effective and last updated: August 30, 2026
1. Scope and operator
This policy applies to the CaughtUp website, Chrome extension, and related backend services. “CaughtUp,” “we,” and “us” refer to the owner and operator doing business under the CaughtUp service name. The designated privacy contact is support@getcaughtup.io.
This policy is a factual description of current practices, not a claim that CaughtUp has obtained an independent privacy or security certification. Whether a particular privacy law applies depends on facts such as location, scale, revenue, and processing activity. CaughtUp nevertheless offers the request channels described here.
2. Personal information we collect
| Category and source | Examples | Business purpose |
|---|---|---|
| Identifiers and account data From Google and you | Name or display name, email address, Google account identifier, authenticated account identifier, and account status. | Authenticate you, maintain the account, provide support, prevent fraud, and communicate material service or policy information. |
| Google authorization data From Google | Authorization to send email from the same verified Gmail account, Gmail address, connection status, and server-side OAuth credential. | Send a reply only after your review and confirmation, or under an eligible Auto-send policy you separately enable. CaughtUp requests gmail.send only. |
| Communications and contents From you and senders whose messages you forward | Normalized full message bodies, sender and recipient addresses, subject, timestamps, reply-chain identifiers, chat messages, draft text and edits, summaries, and delivery state. | Build your CaughtUp inbox, reconstruct threads, classify work, prepare editable replies, keep negotiation context, and prevent duplicate processing or sending. |
| Creator profile and preferences From you and your confirmed actions | Occupation, services, writing style, signoff, communication rules, availability, booking details, matching interests, sender rules, and memory confirmations or rejections. | Configure and personalize the features you choose while keeping creator-owned settings separate from untrusted email content. |
| Commercial and creator workflow data From you, forwarded messages, and connected providers | Media kits, brand relationships, opportunities, public product and commission information, negotiation terms, rate preferences, booking state, and estimated matching signals. | Organize creator work, recommend relevant context, match owned media kits, and rank configured opportunities. CaughtUp does not make binding commercial decisions for you. |
| Inferences Derived from your CaughtUp activity | Proposed communication patterns, evidence references, confidence values, match scores, categories, and summaries. | Offer bounded assistance that you can review, confirm, reject, reset, or delete. Forwarded content cannot grant sending authority or change creator-owned settings. |
| Subscription and transaction metadata From Stripe when paid enrollment opens | Limited payment and subscription metadata, including Stripe customer and subscription identifiers, plan, status, billing period, cancellation state, invoice status, and transaction metadata. CaughtUp does not receive full card numbers. | Provide checkout and billing management, determine entitlement, prevent duplicate webhook processing, and meet financial or legal obligations. |
| Technical and security data From service operation | Authentication and settings events, request identifiers, processing status, error codes, timestamps, connection state, and limited diagnostic logs. | Secure, debug, audit, and reliably operate the service. |
| Potentially sensitive content Only if included in material you submit or forward | Information in email, chat, attachments, or profile fields that may reveal sensitive traits. | Process the user-directed communication or workflow. CaughtUp does not use sensitive personal information to infer characteristics for advertising or unrelated profiling. |
CaughtUp does not intentionally collect precise geolocation, government identifiers, biometric identifiers, health records, or payment card numbers as product features. Please do not submit unnecessary sensitive information.
3. How we use personal information
We use personal information to provide the features you request; authenticate and support users; maintain account, inbox, draft, negotiation, opportunity, media-kit, and billing state; send user-authorized email; protect against abuse; diagnose failures; comply with law; and improve reliability and user-facing functionality.
CaughtUp does not use Google, forwarded-email, or TikTok Shop data for advertising, creditworthiness, lending, surveillance, or generalized artificial-intelligence model training. We do not use sensitive personal information to infer characteristics. We do not make decisions that produce legal or similarly significant effects about employment, housing, credit, education, health care, or essential services.
4. Service providers and disclosures
CaughtUp uses Google for identity and Gmail sending; Cloudflare for public delivery and user-configured forwarded-mail routing; Supabase for authentication, Edge Functions, Postgres, private Storage, and protected configuration; a configured language-model provider, currently DeepSeek when enabled, for bounded classification, drafting, summarization, and pattern proposals; TikTok Shop when the separately authorized integration is available; and Stripe when paid enrollment opens.
Only the information reasonably needed for the requested task is sent to a provider. Relevant forwarded content and limited workflow context may be sent to the configured language-model provider. OAuth credentials, secret keys, and payment card numbers are not included in language-model prompts. Providers process information under contractual terms and their own privacy notices. We may also disclose information when reasonably necessary to protect users or the service, investigate abuse or a security incident, complete a transaction directed by the user, or meet a legal obligation.
Past 12 months: CaughtUp has not sold personal information and has not shared personal information for cross-context behavioral advertising. CaughtUp has disclosed the categories described above to the applicable service-provider categories for the business purposes described in this policy. We do not knowingly sell or share the personal information of consumers under 16.
Routine human review of message content is prohibited. Narrowly scoped access may occur with your affirmative support permission, for a necessary security or abuse investigation, or to meet a legal obligation, and is limited to the minimum information required.
5. Google API and Chrome Web Store Limited Use
CaughtUp’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Google Workspace User Data and Developer Policy, including their Limited Use requirements. CaughtUp requests Google identity information and the sensitive gmail.send scope only. It does not use Google OAuth to read inbox messages, manage Gmail drafts, change labels, delete email, or change Gmail settings. Inbox content reaches CaughtUp only through forwarding that the user configures separately in Gmail.
CaughtUp’s use of information received through the Chrome extension also adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Google and extension user data is used only for visible, user-facing features and related security and reliability purposes described here.
6. Website cookies and tracking
The public CaughtUp website is currently a static site and CaughtUp does not configure advertising cookies, analytics cookies, tracking pixels, or cross-site behavioral advertising on it. The extension and authenticated backend use account-session data needed to keep users signed in and secure requests. Providers you visit directly, such as Google or Stripe-hosted pages, may use cookies under their own notices.
7. Retention
We keep each category only for the purpose and duration described below, then delete or de-identify it when reasonably feasible:
- Account, profile, preferences, forwarded content, CaughtUp drafts, chat, media kits, opportunities, negotiations, and derived state: retained until the user deletes CaughtUp-held data through verified deletion or an applicable deletion request.
- Google or other provider credentials: while the related connection is active; they are removed from CaughtUp’s active systems when the connection or account data is deleted. Users can also revoke access directly with the provider.
- Raw message material: Raw MIME and forwarded attachment files are not retained in the persistent alias archive. They are processed transiently; normalized message content and attachment metadata may remain as described above.
- Subscription, transaction, dispute, fraud-prevention, and tax records: for the period reasonably necessary to complete transactions and meet accounting, legal, chargeback, or enforcement obligations.
- Security and diagnostic records: for the time reasonably necessary to investigate incidents, prevent abuse, troubleshoot failures, and maintain reliable operations, using provider retention and backup-recovery cycles where applicable.
Deletion removes active owner-linked product records and uploaded media through deletion paths. Limited copies may persist temporarily in provider backups until the applicable recovery cycle expires, or longer where retention is required for legal compliance, security, fraud prevention, or dispute handling.
8. California privacy rights
California residents may have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, when the law applies:
- Right to know and access: request the categories, sources, purposes, recipient categories, and specific pieces of personal information collected about you.
- Right to delete: request deletion of personal information, subject to legal exceptions.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out: direct a business not to sell personal information or share it for cross-context behavioral advertising. CaughtUp does neither.
- Right to limit: limit certain uses or disclosures of sensitive personal information. CaughtUp does not use sensitive personal information beyond purposes reasonably necessary to provide and secure the requested service.
- Right to non-discrimination: receive equal service and pricing when exercising a privacy right, subject to permitted differences reasonably related to the value of data.
CaughtUp honors opt-out preference signals such as Global Privacy Control by maintaining a no-sale/no-sharing practice. Because no sale or cross-context behavioral advertising occurs, no separate browser setting is needed to opt out. See Your Privacy Choices.
9. Rights in other locations
Depending on where you live, you may also have rights to access, correct, delete, obtain a portable copy, restrict or object to processing, withdraw consent, or appeal a denied request. CaughtUp will evaluate requests under the law that applies and will explain any denial and available appeal method.
10. How to make a privacy request
Send a request to support@getcaughtup.io with the subject “Privacy request,” or use the export and verified deletion controls in CaughtUp Settings. You do not need to create a new account to email a request. Please state the right you want to exercise and the email associated with CaughtUp.
We will acknowledge and respond within the period required by applicable law. For California requests to know, correct, or delete, that is generally 45 days, with a permitted extension and notice when reasonably necessary. We will use information supplied for verification only to verify and fulfill the request. We may ask an authenticated user to confirm through the existing account or match the account email. We will not request unnecessary sensitive information.
An authorized agent may submit a request for you. We may request signed permission or other proof of authority and may ask you to verify your identity or confirm the authorization directly. Opt-out requests, if relevant, will not require identity verification beyond what is reasonably necessary to process the preference.
11. Product controls
Settings lets authenticated users review evidence for learned patterns, confirm or reject a pattern, reset learned patterns without deleting archived messages, export CaughtUp-held data, correct profile and preference information, and complete verified deletion. Users can separately disable CaughtUp intake, remove the forwarding rule in Gmail, revoke Google access through their Google Account, disconnect supported connections, and sign out.
Disabling intake, revoking Google authorization, or signing out does not by itself delete records already stored by CaughtUp. Removing CaughtUp data also does not remove the forwarding rule configured in Gmail; the user must remove that rule separately.
12. Security and incidents
CaughtUp uses reasonable administrative, technical, and organizational safeguards appropriate to the service, including encrypted transport, managed encryption at rest, owner-scoped access, restricted service roles, signed inbound delivery, least-privilege Google scopes, and separation of untrusted email content from creator-controlled sending authority. More detail is available on the Security page.
No online service can guarantee absolute security. Report a suspected vulnerability or privacy incident to support@getcaughtup.io.
13. Children
CaughtUp is intended for creators who are at least 18 years old, or the age of legal majority where they live. It is not directed to children under 13, and we do not knowingly collect their personal information.
14. International processing
CaughtUp and its providers may process information in the United States and other countries where they operate. Where required, transfers will use an appropriate legal mechanism. Users should contact us before submitting information if they need details about an applicable transfer mechanism.
15. Changes
We may update this policy when the product, providers, or law changes. The published policy identifies its effective date. Material changes will be communicated through an appropriate product or account notice before new materially different processing begins when required.
16. Contact
Privacy, access, correction, appeal, and deletion requests: support@getcaughtup.io.