Privacy Policy
Wrenly shows the status of your online orders by reading order and shipping emails in your Gmail account. This policy explains exactly what it reads, what it keeps, and who else can see it. The short version: we read only what we need, we never sell it, and in private mode your email never reaches our servers at all.
Two versions
Private mode is the app on the home page, and the only version open to the public. It runs entirely in your own web browser. Your browser talks to Google directly, and the results are stored only in that browser.
Standard mode is a separate, invite-only version that runs on our servers so it can sync in the background. It is not available to the public: accounts exist only for people the operator has invited. It stores more, as described below.
What we access from Google
We ask for one permission: read-only access to your Gmail
(gmail.readonly). We never send, delete, label or change any email. We use
it to search for messages whose subject suggests an order, shipment, delivery, receipt or
confirmation, from roughly the last 180 days, and to read those messages.
What we keep
From each order email we extract, and keep:
- the store name, order number, order status and tracking number;
- the product names and quantities, and one product picture address;
- the order total and the estimated delivery date, when the email states them;
- the email's subject line and date, and Gmail's message identifier (so we can notice when you delete the email).
We do not keep the full text of your emails, your other email, your contacts, or your attachments.
Private mode: where it is kept
- Everything above is stored in your browser's own storage (IndexedDB) on your device. It is not sent to us.
- Google's access token is held in the page's memory for about an hour and is never written to storage. Closing the page discards it.
- We run no analytics, advertising or tracking in private mode.
- Product pictures are off by default. If you switch them on, they load directly from each store's website, so those stores can see your IP address and that a picture was requested. Switching them off again stops all such requests.
- "Sign out and erase data" deletes everything private mode stored in your browser.
Standard mode (invite-only): where it is kept
- The data above is stored in a database (Neon Postgres) so it can update automatically once a day.
- To sync while you are away we keep a Google refresh token, encrypted at rest with a key held separately from the database.
- We keep your Google email address, and set one sign-in cookie that lasts 7 days.
- Order emails may be sent to Google's Gemini API to help read product names and tracking numbers. Google handles that content under its Gemini API terms.
- Our hosting provider (Vercel) and database provider (Neon) process this data on our behalf.
How we use it
Only to show you your own orders inside the app. We do not use it for advertising, we do not sell or rent it, and we do not use it to build or train general AI or machine-learning models. Nobody reads your emails or order data, except where you ask us to for support, where it is needed for security or abuse prevention, or where the law requires it.
Google API Services User Data Policy
Wrenly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing
We share your data only with the services needed to run the app:
- Google - Gmail (to read your mail) and, in standard mode, Gemini.
- Vercel and Neon - hosting and database, standard mode only.
- Stores' image servers - product pictures, private mode only.
We do not sell your data or share it with advertisers or data brokers.
The banner at the top of the app is a sponsored affiliate link to Hype Proxies. Its image is served from this site, so nothing is sent to them unless you click it. If you buy something after clicking, we may earn a commission.
Deleting your data and revoking access
- Private mode: use "Sign out and erase data", or clear this site's data in your browser.
- Standard mode: use "Delete account" to permanently erase your orders, your account and your stored Google token, and to revoke our access to your Google account. "Clear all" removes only your stored orders.
- Either mode: you can withdraw our access at any time at myaccount.google.com/permissions. Deleting an email in Gmail also removes its order from the app the next time it syncs.
Security
Connections use HTTPS. In standard mode, tokens are encrypted at rest, access is limited to your own account, and sessions can be ended by signing out. No system is perfectly secure, which is one reason private mode keeps your data off our servers entirely.
Children
Wrenly is not directed at children under 13, and we do not knowingly collect their data.
Changes
If we change how we handle data, we will update this page and its effective date. We will not begin using Google user data for a new purpose without asking you first.
Contact
Questions, or requests to delete data: support@umbraworks.dev — operated by Umbra Works.