Privacy Policy
Effective June 2026. Updated September 29, 2026.
Albatross is hosted email and personal operations software from Lab86. This policy explains what data Albatross collects, how it uses and shares that data, how long it keeps it, and the choices you have.
Data we collect
- Account data: your name, email address, and sign-in records, through our sign-in provider Clerk.
- Connected mailbox data: after you connect a mailbox, Albatross connects to your mail provider only with the access you authorize. It processes message headers, message bodies, snippets, labels, attachments, drafts, and outbound send metadata. It also keeps copies of the attachment files from the last 60 days of mail, so that they open quickly.
- Calendar, contact, and file data: the calendar events and contacts of a connected account, and files when you connect a file service such as Google Drive.
- Content you create: tasks, notes, plans, rules, labels, saved replies, signatures, and settings.
- Billing data: your plan and billing entitlement records. Stripe processes card payments through Clerk Billing. Lab86 does not receive or store card numbers.
- Usage and security data: usage records, rate-limit counters, security audit events, and device tokens for notifications that you turn on.
How we use data
We use your data only to provide the features you use: to show, search, and sort your mail, to draft replies and summaries, to prepare your brief, to perform actions you request, to send notifications you turn on, to bill your plan, and to keep the service secure. We store the minimum app state needed to operate Albatross, including a Convex-backed mail index used for search and synchronization.
To sort and search your mail and to do the work you ask for, Albatross sends relevant message content and your instructions to model providers. They return summaries, classifications, search vectors, drafts, and other results. Hosted requests go through OpenRouter. OpenRouter sends each request only to a model host that does not train models on the data. Some of these hosts keep requests for a limited time under their own policies, for example to find abuse.
If you add your own OpenRouter key, the same rule applies. If you add your own OpenAI or Anthropic key, requests go directly to that provider under your agreement with it.
Google user data
Albatross's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. When you connect a Google account, Albatross uses the Gmail access you grant to read, sort, label, draft, and send mail for you, and uses your Google email address to identify the connected account. It uses the Google Calendar access to show, create, and change your events, and the contacts access to show names and suggest recipients. If you connect Google Drive, Albatross uses that access to find, open, and create the files you ask for.
A Google account can connect directly to Google. Then Albatross uses the Google APIs for the mail, calendar, and contacts of that account. A Google account that connected through Nylas stays on Nylas until you connect it again. Microsoft and iCloud accounts connect through Nylas.
We do not sell Google user data, use it for advertising, use it to train generalized artificial intelligence or machine learning models, or allow humans to read message content except with your consent, for security, to comply with law, or for support you request.
We transfer Google user data to the service providers in "How we share data" only to give you the features that you use, for security, or to obey the law.
How we share data
Albatross does not sell personal information. We use service providers to run the product: Railway, Convex, Nylas, Clerk, Stripe, Resend, and OpenRouter. OpenRouter sends model requests only to hosts that do not train models on the data. Examples are OpenAI, Anthropic, Amazon Web Services, Microsoft Azure, and Google Cloud. If you add your own model key, we also send requests to the provider of that key.
Some features also send data to these services:
- Browserbase: runs the web browser for web search, for the web pages that you or the assistant open, for guided work, and for slide images. It receives the search words, the page addresses, and the slide content. It records the browser sessions of guided work.
- Apple Push Notification service: receives the device token of your iPhone, iPad, or Mac and the text of each notification that you turn on, for example the sender and subject of new mail.
- Browser push services: browser notifications go through the push service of your browser, for example Google, Mozilla, or Apple. They are encrypted and hold only fixed text, such as a check-in reminder.
- DuckDuckGo and Google site icons: to show the logo of a company sender or a web site, we ask these icon services for the icon of that domain. Your browser sends some of these requests, so the service also receives your IP address. We do not send personal mail domains such as gmail.com.
- Open-Meteo: for the weather in your brief, receives the location that you share from your device, or up to three place names from your calendar events, or the city of your time zone.
- OpenStreetMap Nominatim: when a plan needs places near you and your device shares its location, receives that latitude and longitude and returns the name of the city and region.
- Google Maps: when you open an event that has a place, your browser shows a map of that place from Google Maps. Google receives the place text and your IP address.
- Connected tools: if you connect GitHub, Bitbucket, Jira, Slack, or Granola, we send your requests to that service and read the results for you, with the access that you give.
Your browser also loads some content directly from other hosts. These hosts receive your IP address. The fonts of some pages come from Google Fonts. The art in your brief comes from public museum collections. A social post with no author picture gets a generated picture from DiceBear, which receives the author name. Images in a message come from the servers that the sender chose, as in other mail apps.
These providers process data only to provide, secure, bill, or support Albatross. We may also disclose data when the law requires it or to protect users and the service from fraud or abuse.
Security
Data moves between your device, Albatross, and our service providers over encrypted (TLS) connections. Convex stores the data, including the attachment copies, encrypted at rest. Model provider keys that you add are encrypted before we store them. Access to production systems is limited to the people who operate the service.
Retention and deletion
We keep your data while your account is active. When you disconnect a mailbox, we revoke our access to it and delete its Lab86-hosted grant records. Then we delete its stored mail, labels, calendar events, contacts, attachment copies, search index, and sync state. We also delete its provider webhook records and what we made from its mail: memory notes, Work receipts, notifications, event suggestions, and prepared brief items. If another connection in Albatross uses the same Google sign-in, for example your Google Drive connection, we delete our copy of the access but do not revoke the sign-in, so that the other connection keeps working.
If a mailbox needs a reconnect for 30 days, a daily job deletes the same mailbox data. It keeps the mailbox entry and its grant record, so that you can reconnect or disconnect the mailbox in Settings. Some items stay until you delete them or your account. These are tasks and Work that you made from a message, notes about an area, the activity log, and past briefs.
We delete provider webhook records after 14 days, or after 30 days if we could not process them. Account deletion removes your Lab86-hosted account data, model settings, usage records, index data, attachment copies, and connected mail grants. These actions do not delete messages from the original mail provider mailbox unless you separately perform a delete action in that provider.
Your choices
- Export your data from Settings at any time.
- Disconnect a mailbox and its calendar from Settings, or Google Drive from Files.
- Delete your account from Settings, or ask us to delete it.
- Remove Albatross's access to your Google account at myaccount.google.com/permissions.
Children
Albatross is not for children under 13, and we do not knowingly collect their data.
Changes
When we change this policy, we update the date at the top of this page. If a change materially affects how we use your data, we tell you in the app or by email before it takes effect.
Contact
Questions, privacy requests, or deletion requests: support@lab86.io. Security reports: security@lab86.io.