Privacy Policy

Effective June 2026. Updated September 29, 2026.

Albatross is hosted email and personal operations software from Lab86. This policy explains what data Albatross collects, how it uses and shares that data, how long it keeps it, and the choices you have.

Data we collect

How we use data

We use your data only to provide the features you use: to show, search, and sort your mail, to draft replies and summaries, to prepare your brief, to perform actions you request, to send notifications you turn on, to bill your plan, and to keep the service secure. We store the minimum app state needed to operate Albatross, including a Convex-backed mail index used for search and synchronization.

To sort and search your mail and to do the work you ask for, Albatross sends relevant message content and your instructions to model providers. They return summaries, classifications, search vectors, drafts, and other results. Hosted requests go through OpenRouter. OpenRouter sends each request only to a model host that does not train models on the data. Some of these hosts keep requests for a limited time under their own policies, for example to find abuse.

If you add your own OpenRouter key, the same rule applies. If you add your own OpenAI or Anthropic key, requests go directly to that provider under your agreement with it.

Google user data

Albatross's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. When you connect a Google account, Albatross uses the Gmail access you grant to read, sort, label, draft, and send mail for you, and uses your Google email address to identify the connected account. It uses the Google Calendar access to show, create, and change your events, and the contacts access to show names and suggest recipients. If you connect Google Drive, Albatross uses that access to find, open, and create the files you ask for.

A Google account can connect directly to Google. Then Albatross uses the Google APIs for the mail, calendar, and contacts of that account. A Google account that connected through Nylas stays on Nylas until you connect it again. Microsoft and iCloud accounts connect through Nylas.

We do not sell Google user data, use it for advertising, use it to train generalized artificial intelligence or machine learning models, or allow humans to read message content except with your consent, for security, to comply with law, or for support you request.

We transfer Google user data to the service providers in "How we share data" only to give you the features that you use, for security, or to obey the law.

How we share data

Albatross does not sell personal information. We use service providers to run the product: Railway, Convex, Nylas, Clerk, Stripe, Resend, and OpenRouter. OpenRouter sends model requests only to hosts that do not train models on the data. Examples are OpenAI, Anthropic, Amazon Web Services, Microsoft Azure, and Google Cloud. If you add your own model key, we also send requests to the provider of that key.

Some features also send data to these services:

Your browser also loads some content directly from other hosts. These hosts receive your IP address. The fonts of some pages come from Google Fonts. The art in your brief comes from public museum collections. A social post with no author picture gets a generated picture from DiceBear, which receives the author name. Images in a message come from the servers that the sender chose, as in other mail apps.

These providers process data only to provide, secure, bill, or support Albatross. We may also disclose data when the law requires it or to protect users and the service from fraud or abuse.

Security

Data moves between your device, Albatross, and our service providers over encrypted (TLS) connections. Convex stores the data, including the attachment copies, encrypted at rest. Model provider keys that you add are encrypted before we store them. Access to production systems is limited to the people who operate the service.

Retention and deletion

We keep your data while your account is active. When you disconnect a mailbox, we revoke our access to it and delete its Lab86-hosted grant records. Then we delete its stored mail, labels, calendar events, contacts, attachment copies, search index, and sync state. We also delete its provider webhook records and what we made from its mail: memory notes, Work receipts, notifications, event suggestions, and prepared brief items. If another connection in Albatross uses the same Google sign-in, for example your Google Drive connection, we delete our copy of the access but do not revoke the sign-in, so that the other connection keeps working.

If a mailbox needs a reconnect for 30 days, a daily job deletes the same mailbox data. It keeps the mailbox entry and its grant record, so that you can reconnect or disconnect the mailbox in Settings. Some items stay until you delete them or your account. These are tasks and Work that you made from a message, notes about an area, the activity log, and past briefs.

We delete provider webhook records after 14 days, or after 30 days if we could not process them. Account deletion removes your Lab86-hosted account data, model settings, usage records, index data, attachment copies, and connected mail grants. These actions do not delete messages from the original mail provider mailbox unless you separately perform a delete action in that provider.

Your choices

Children

Albatross is not for children under 13, and we do not knowingly collect their data.

Changes

When we change this policy, we update the date at the top of this page. If a change materially affects how we use your data, we tell you in the app or by email before it takes effect.

Contact

Questions, privacy requests, or deletion requests: support@lab86.io. Security reports: security@lab86.io.