Effective and last updated: August 30, 2026
Security and privacy contact: support@getcaughtup.io
Review cycle: At least annually and after material product, provider, regulatory, or security changes.
1. Governance and risk management
The CaughtUp owner and operator is accountable for the program and acts as Security and Privacy Lead. Security decisions consider data sensitivity, Internet exposure, tenant impact, provider dependency, likelihood of misuse, and the effect of unauthorized disclosure. High-risk changes involving authentication, sending, secrets, personal data, or production access require explicit verification before release.
2. Access control
Access follows least privilege, need to know, and unique identity. Administrative access is limited to specifically authorized persons with an operational need. Multi-factor authentication is required wherever a provider supports it. User requests require authenticated identity and are scoped to the owning account. Public clients never receive service-role credentials, Gmail or TikTok provider refresh tokens, OAuth client secrets, or privileged service keys.
3. Data classification and encryption
CaughtUp classifies information as Public, Internal, Confidential, or Restricted. Normalized alias-inbox message bodies, thread metadata, and observation evidence are Confidential. OAuth tokens, passwords, secret keys, and privileged credentials are Restricted. Internet traffic carrying account or personal data uses HTTPS and TLS. Sensitive integration configuration remains in server-side protected storage. Managed database and storage providers supply encryption at rest for hosted data. Raw MIME and forwarded attachment files are not retained in the persistent alias archive.
4. Network and endpoint protection
Managed cloud services separate public delivery, application processing, database and private storage, authentication, and secret management. Public delivery uses Cloudflare edge protection and restrictive security headers. Signed inbound requests feed service-role-only, row-level-security-protected tables linked to one owner and sending account. Retrieval is bounded and owner scoped. Email and derived observations remain untrusted context and are separated from creator-confirmed settings and server-side Auto-send authority. Google forwarding control messages use a deterministic trusted-sender and allowlisted-host path and do not enter language-model memory. Company endpoints must use supported software, automatic security updates, antivirus, firewall protection, screen locking, device encryption where supported, and unique password-protected accounts.
5. Google and extension data controls
Google identity and Gmail authorization are separate. CaughtUp requests gmail.send only and does not use Google OAuth to read inbox messages, manage Gmail drafts, change labels, delete email, or change Gmail settings. Incoming messages use user-configured Gmail forwarding and signed Cloudflare delivery. Google and extension user data is limited to visible user-facing features and related security and reliability purposes, consistent with the Google API Services User Data Policy, Google Workspace Limited Use requirements, and Chrome Web Store Limited Use requirements.
CaughtUp does not sell this data or use it for advertising, creditworthiness, lending, or generalized AI-model training. OAuth credentials are not included in language-model prompts. Routine human review of message content is prohibited; narrowly scoped access requires the user’s affirmative support permission, a necessary security or abuse investigation, or a legal obligation.
6. Incident response and notification
Suspected unauthorized access, data exposure, malware, credential loss, service compromise, or material policy violation must be reported promptly. The Incident Lead records, triages, contains, investigates, remediates, and validates recovery. When an incident affects TikTok Shop, a seller, a creator, Google user data, or personal data, CaughtUp will notify the affected party, provider, and any required authority without undue delay and within applicable legal, platform, or contractual deadlines.
7. Vulnerability and threat management
CaughtUp reviews application code, authentication boundaries, dependencies, provider advisories, error reports, and public exposure at least monthly and after material releases. Findings are prioritized by exploitability, exposure, data sensitivity, tenant scope, privilege gained, and operational impact. Secret exposure, authentication bypass, cross-user access, unauthorized sending, or public personal-data exposure is treated as urgent.
8. Personal data requests and deletion
Authenticated users can review learned patterns and their evidence, export CaughtUp-held data, correct profile or preference information, reset learned patterns, and complete verified deletion from the extension. Users, sellers, creators, authorized agents, and TikTok Shop may also request access, correction, restriction, export, appeal, or deletion through the support channel. Identity and authority are verified before disclosure or change. Owner-linked database records and uploaded media use deletion cascades or explicit storage deletion. Disabling intake, revoking Google access, and signing out are separate actions and do not delete archived content. After a verified deletion request or the end of the applicable relationship, customer data is removed from active systems without unreasonable delay, subject to limited legal, security, fraud-prevention, dispute, and backup-recovery exceptions. California-specific choices are described on the Your Privacy Choices page.
9. Assurance and limitations
CaughtUp reviews this program at least annually and after material changes. These documents describe CaughtUp’s controls and operating requirements; they are not an independent audit report or certification. CaughtUp uses security-conscious service providers, but a provider's certification does not certify CaughtUp. CaughtUp does not claim ISO 27001, ISO 27701, SOC 2 Type 2, ePrivacy, or another independent certification unless one is formally obtained.