Draft for review · 11 August 2026
Privacy notice
This plain-language notice describes the feature as currently built. It is a product draft for Andrei to review, not reviewed legal advice.
What you authorize
The current managed Google connection grants full Gmail account access, including permission to read, send, and delete messages, along with basic Google profile and contacts permissions. Those permissions are broader than the actions PostmarkOS currently performs. PostmarkOS does not send, edit, archive, or delete Gmail messages.
How the connection is stored
Composio handles Google authorization and stores and refreshes the Google credentials. PostmarkOS stores the connected Gmail address, a non-secret Composio account identifier, connection status, and sync timestamps. Google access and refresh tokens are not stored in the PostmarkOS database or sent to browser code.
Optional public-presence research
If you opt in and save a LinkedIn profile URL, PostmarkOS uses its configured live-web-search provider to look for publicly indexed sources about your professional focus and writing style. It does not log into or directly scrape LinkedIn, X, or another social account, and it does not reproduce your posts. The source-backed search result is cached so regenerating your profile does not repeat the live search. Unchecking the option deletes that derived research and invalidates the prior profile analysis.
How reply tracking works
PostmarkOS searches metadata for new inbox messages after the last successful sync. Before reading a body, it checks whether the subject or sender name mentions a company you applied to, the subject looks like career correspondence, or the sender domain matches an applied company. Only messages that pass one of those checks have their body fetched and sent to the configured AI provider. The classifier compares each candidate with your applications that were awaiting a reply when the message arrived, then identifies an application confirmation, interview, rejection, or an unrelated message.
What PostmarkOS keeps
For a high-confidence application confirmation, interview, or rejection, PostmarkOS stores the Gmail message identifier, matched application, classification, confidence, received time, sender address, and a short subject snippet. It does not store the full message body or attachments. Low-confidence and unrelated messages do not create application events. Applications added manually do not trigger company research, positioning advice, or cover-letter generation, but they are included in reply matching when Gmail is connected.
Notifications
New high-confidence replies add an in-app badge and appear in the matching application's history. Reply tracking does not send mail from your Gmail account or send separate reply-notification emails.
Disconnecting
You can disconnect from Mailbox settings. PostmarkOS asks Composio to revoke the Google connection and remove its managed connected account, then marks the local connection as disconnected. The local status and previously detected application events remain as history.