Privacy
Last updated 2026-09-28. Ample Day is made by Neuro Pathmaker LLC.
What Ample Day does
Ample Day reads school email in your Gmail account and turns it into one list of tests, forms, and events. That is the whole product.
What we access in Gmail
- We ask for the read-only Gmail permission (
gmail.readonly). Ample Day cannot send, delete, label, or move mail. - During setup we look at sender names and subject lines from your newest mail, back to 60 days, to guess which senders are your kids' schools. Subject lines are used for that guess and are not stored.
- After setup, Ample Day reads only messages from the senders you approved. No other mail is fetched.
What we store
- Your name, email address, household name, your kids' first names, grades, and schools.
- The list of approved senders and the setup guesses (sender domain, display name, message counts).
- For each school email we processed: its Gmail message id, sender, subject line, and the items we extracted from it (title, date, time, kind).
- Your Gmail refresh token, encrypted, so the scan can keep running.
- What you tell us about the list: items you marked Wrong, and items you added because we missed them (title and date).
- Your phone's push token, the notifications we sent you, and the days you opened the app.
We never store the body of an email or its attachments. Each message is fetched, read once by our extraction step, and discarded.
How we use it
Three outside services read the text of your school email. Ample Day keeps only what is listed above: the extracted items, message ids, senders, and subject lines. What each service keeps on its own side is set by its own terms.
Anthropic (Claude). Each message from an approved sender is read by one of two AI services, Anthropic's Claude API or OpenAI's API. We choose which one, and the choice can change. The service receives the message text, the text of Google Docs it links to, and its images, and returns the dates and deadlines in it. Anthropic runs under its commercial terms, which do not permit training on your data.
OpenAI (GPT). When a message goes to OpenAI instead, OpenAI receives the same things Anthropic would: the message text, the text of linked Google Docs, and its images. OpenAI's API terms do not permit training on your data. Your mail is sent to OpenAI only with zero data retention in place for our account. Under that setting OpenAI keeps no copy of the request, with one exception in its terms: an image its child-safety screen flags is held for review.
TypeSafe (Jev). The same email text is also sent to TypeSafe, whose Jev model answers small yes-or-no questions that keep our extraction honest: whether a message is worth reading closely, whether it holds text aimed at our software rather than at you, which child an item belongs to, whether an item should be hidden from your list, whether an extracted date checks out, whether we missed anything, and whether two items are really the same one. For each of those, the message's subject, sender, body, the text of documents it links to, and the names, types and sizes of its attachments are sent. During setup, the names and addresses of senders in your inbox and their recent subject lines are sent so we can propose which ones are schools. TypeSafe does not train on your data. Under its terms it may keep request data as long as it needs to run and secure its service. Here we keep a record of each question asked: the message id, when it ran, and the model's scores. Never the text.
Other services Ample Day runs on:
- Google: the Gmail API, read-only, to fetch mail from your approved senders.
- Supabase: the database and sign-in.
- Vercel: hosting for this site and the scan.
- Expo and Apple: push notification delivery. The text on your lock screen is counts only, such as "Tomorrow: 1 test." It never names a child or an item.
We do not sell your data, share it with advertisers, or use it for anything other than building your list.
Google user data is used only to provide the features described here, in line with the Google API Services User Data Policy, including the Limited Use requirements.
Deleting your data
In the iPhone app, go to Settings, then Your mail and account, then Delete account and data. If Gmail is not connected, use Delete account and data on the Connect Gmail screen. Ample Day then does this, in order:
- In one step, it deletes your household, your kids, your approved senders, your list, your feedback (Wrong and missed items), your push tokens, your encrypted Gmail token, and your sign-in account. If this step fails, nothing is deleted.
- It revokes Ample Day's access to your Gmail at Google.
- It revokes Sign in with Apple for Ample Day.
- It signs your phone out.
If the revoke at Google or Apple fails, your data is still deleted, and you can remove Ample Day's access yourself. For Google, go to myaccount.google.com, then Security, then Third-party connections, and remove Ample Day. For Apple, open iPhone Settings, tap your name (Apple ID), then Sign in with Apple, and remove Ample Day.
Encrypted database backups are not edited. Backups are kept for 7 days, so deleted data is gone from them within 7 days.
Disconnecting Gmail, without deleting your account, deletes your encrypted Gmail token and your household's processed-message log, and Ample Day stops reading your mail. Your list, your kids, and your approved senders stay, so you can reconnect later. To erase those too, use Delete account and data. Email privacy@neuropathmaker.com to ask for a deletion or a copy of your data.
Security
Data is stored with Supabase (Postgres, hosted in the US) with row-level security so each household can only see its own rows. Tokens are encrypted at rest. The extraction step runs with no tools and no network access beyond the model API.