1. Overview & Architecture
Guardian House (“the Service”) is an email inbox guarding service developed by Alqime LLC. It protects your personal inbox by screening incoming mail from senders who are not in your contacts, have never received a reply from you, or do not belong to an ongoing thread.
Zero Deletion Without Consent: Guardian House is built on a fail-open, no-trash architecture. Senders not recognized by your screening rules are archived to a dedicated screening label within your email account. Guardian House never deletes or trashes your messages without your explicit direction.
2. Provider API Services & User Data Policy
Guardian House's use and transfer of information received from email provider APIs adheres to provider data policies, including strict Limited Use requirements.
Permissions Requested and Purpose:
- Mailbox Access: Required to inspect incoming message metadata (sender, recipient, subject, headers, and thread continuity), apply screening labels, and move messages out of your primary inbox. Message bodies are examined transiently in memory to calculate feature statistics and are discarded immediately. Guardian House never calls trash or deletion APIs.
- Contacts Access: Required to read your address book to maintain your known-sender allowlist, and to add senders to your contacts when you click “Legitimate” in your weekly email digest.
- User Profile & Email: Used solely to verify your account identity and display your connected account email address in your dashboard.
3. Data Storage & Cryptographic Protection
We implement strict data minimization principles:
- No Message Body Storage: Email bodies are never saved to disk, database, or persistent storage.
- Token Encryption: OAuth access and refresh tokens are encrypted at rest using industry-standard AES-256-GCM.
- Cryptographic Hashing: Contact local-parts and audit records are protected using keyed cryptographic hashes, preventing rainbow-table recovery while preserving privacy.
- Digest Tokens: Weekly digest action links use single-use, cryptographically signed tokens that expire after 14 days and fail closed upon replay.
4. Third-Party Infrastructure
Guardian House utilizes SOC 2 / ISO 27001-compliant infrastructure providers located in the United States:
- Cloud Pub/Sub: Real-time push notifications for mailbox events.
- Serverless & Database Hosting: Encrypted edge hosting and relational database storage.
- Transactional Email: Delivery of weekly digest summaries, non-identifying bounce notifications, and inbound block gesture intake.
5. Revocation and Deletion
You may revoke Guardian House's access at any time through your provider's security settings. Revocation immediately terminates our ability to watch your mailbox. You may also request complete deletion of your account and cryptographic records at any time.
6. Contact & Inquiries
For privacy inquiries, questions, or data erasure requests, please . Our team responds promptly to all requests.