Effective Date: August 22, 2026
Last Updated: August 22, 2026
Confi Technologies, Inc. ("Confi," "we," "us," or "our") is a Delaware corporation. Confi Technologies, Inc. is a consumer-first commerce platform. Confi's V1 product helps users prevent avoidable loss in their post-purchase activity by analyzing order-related emails to track orders, return windows, refund eligibility, and subscription renewals.
Confi operates the Confi service ("Service"), which includes the Confi mobile application ("App") and supporting backend systems.
This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding your data.
Contact:
Confi Technologies, Inc. Principal Office: 513 W Shoreview Drive, San Ramon, CA 94582, United States Delaware Registered Agent: Harvard Business Services, Inc., 16192 Coastal Highway, Lewes, DE 19958, United States Privacy Inquiries: [email protected]
For data subject requests (GDPR, CCPA, and equivalent), see Sections 8 and 9.
Confi connects to the following email providers in Version 1:
gmail.readonly scope)Mail.Read scope)Organizational or work Microsoft 365 accounts are not supported in Version 1. Only personal Outlook.com accounts are supported.
Additionally, organizational or workplace Google Workspace accounts are not supported in Version 1. Only personal Gmail accounts (@gmail.com) are supported. Confi does not access Google Workspace administrative APIs and does not process data subject to Workspace administrator controls.
Additional email providers, if added in future versions, will be declared in an updated version of this Privacy Policy before any such version is released. This is a permanent commitment of the Confi service: no email provider is added silently.
The OAuth scopes above are read-only. Confi does not send, draft, modify, delete, archive, mark as read, or move any email in your account.
Confi's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, when Confi accesses your Gmail data via the gmail.readonly scope:
Permitted use only. We use Gmail data solely to provide and improve the user-facing features of the Confi service described in this Privacy Policy (Sections 3.2, 3.3, 3.4) — namely, parsing order-related emails to track orders, return windows, refund eligibility, and subscription renewals.
No transfer to third parties for unrelated purposes. We do not transfer Gmail data to any third party except: (a) as necessary to provide the user-facing features described above, including to our sub-processors as listed in Section 6 of this Privacy Policy (specifically Google Cloud's Vertex AI service, which performs the AI-assisted extraction described in Section 4); (b) to comply with applicable law or valid legal process; (c) as part of a merger, acquisition, or sale of assets, in which case we will provide notice and obtain consent where required; or (d) for security purposes, such as investigating abuse.
No advertising use. We do not use Gmail data for serving advertisements, including retargeting, personalized advertising, or interest-based advertising. Confi does not operate any advertising surface.
No human reading of your data, except in narrowly defined cases. We do not allow humans to read your Gmail data unless: (a) you have given affirmative consent for specific messages; (b) it is necessary for security purposes, such as investigating abuse; (c) it is necessary to comply with applicable law; or (d) the data has been aggregated and anonymized, and is used solely for internal operations such as quality auditing, security investigation, or compliance review. Such use is not routine and is bounded by internal controls.
In addition, Confi does not sell, license, or commercialize your Gmail data to retailers, advertisers, or any other third party. This is a permanent non-negotiable commitment of the Confi service.
If you have questions about Confi's Limited Use compliance, contact [email protected].
Confi's use of information received from the Microsoft Graph API is governed by Microsoft's API Terms of Use and the Microsoft Identity Platform consent and data-handling principles, and is disclosed below in line with our transparency obligations under GDPR and equivalent regimes.
Specifically, when Confi accesses your personal Outlook.com data via the Mail.Read scope:
Permitted use only. We use Outlook.com mail data solely to provide and improve the user-facing features of the Confi service described in this Privacy Policy (Sections 3.2, 3.3, 3.4) — namely, parsing order-related emails to track orders, return windows, refund eligibility, and subscription renewals.
No transfer to third parties for unrelated purposes. We do not transfer Outlook.com data to any third party except: (a) as necessary to provide the user-facing features described above, including to our sub-processors as listed in Section 6 of this Privacy Policy (specifically Google Cloud's Vertex AI service, which performs the AI-assisted extraction described in Section 4); (b) to comply with applicable law or valid legal process; (c) as part of a merger, acquisition, or sale of assets, in which case we will provide notice and obtain consent where required; or (d) for security purposes, such as investigating abuse.
No advertising use. We do not use Outlook.com data for serving advertisements, including retargeting, personalized advertising, or interest-based advertising. Confi does not operate any advertising surface.
No human reading of your data, except in narrowly defined cases. We do not allow humans to read your Outlook.com data unless: (a) you have given affirmative consent for specific messages; (b) it is necessary for security purposes, such as investigating abuse; (c) it is necessary to comply with applicable law; or (d) the data has been aggregated and anonymized, and is used solely for internal operations such as quality auditing, security investigation, or compliance review. Such use is not routine and is bounded by internal controls.
No access to organizational data. Confi accepts personal Outlook.com accounts only. We do not configure or accept the Mail.Read scope under organizational Microsoft 365 tenants. Confi does not invoke administrator consent flows.
In addition, Confi does not sell, license, or commercialize your Outlook.com mail data to retailers, advertisers, or any other third party. This is a permanent non-negotiable commitment of the Confi service.
If you have questions about Confi's Microsoft Graph data handling, contact [email protected].
The OAuth scopes Confi requests are classified as Restricted by Google and as delegated permissions requiring user consent by Microsoft:
gmail.readonly — Restricted Scope per Google API Services User Data Policy. Confi requests this scope because order-related email content is the only data source for parsing retailer orders, return windows, refund eligibility, and subscription renewals (the user-facing features described in Sections 3.2, 3.3, 3.4 of this Privacy Policy).Mail.Read — Delegated permission requiring user consent. Confi requests this permission for the same purpose described above, for users connecting personal Outlook.com accounts.Confi requests these scopes because no narrower scope is sufficient to deliver the loss-prevention service Confi provides. Specifically:
gmail.metadata, gmail.labels) do not include email body content. Order-related details — order ID, return windows, refund amounts, subscription renewal dates — are in the email body, not headers or labels.gmail.modify, gmail.send, gmail.compose, Mail.ReadWrite, Mail.Send, or any administrative scope.For questions about how Confi uses these permissions, contact [email protected].
When you create an account, we collect:
Purpose: To create and maintain your account and associate your orders with your profile.
When you connect your email account, our backend server queries your email provider's API using filters that target order-related emails only. We never perform a full mailbox fetch.
For each relevant email, the following process occurs server-side:
What we store: Structured extracted data only — retailer, order ID, amounts, dates, tracking numbers, return windows, subscription renewal information, and order state.
What we do not store: Raw email body, email headers, email attachments, non-order emails.
Lawful basis (GDPR): Contractual necessity — processing your emails is necessary to deliver the service you signed up for (Article 6(1)(b) GDPR). You authorize this access through OAuth consent at your email provider.
When you tap "View Emails" for a specific order in the App:
This is an ephemeral, on-demand fetch. No email body content is retained from this flow on Confi systems.
Confi monitors subscription renewal emails as part of its order tracking. This includes detecting upcoming renewal dates, price changes, and subscription status changes. Subscription monitoring is performed using the same parsing pipeline described in Section 3.2 and is subject to the same data handling rules. The raw subscription email body is not stored; only the structured renewal information is retained.
Retention boundary — subscription state vs email-derived events. Subscription state (active vs cancelled vs paused, current price tier, renewal date) is retained while the subscription is active in Confi's view of your account. Email-derived events (the individual renewal emails Confi parsed to derive that state) are not retained as separate records — only the structured state is persisted. If you cancel a subscription in the underlying service, Confi's state may continue to reflect the prior status until either (a) a cancellation confirmation email is parsed, or (b) you mark the subscription as cancelled in the App, or (c) the renewal date passes without confirmation, whichever comes first.
We collect limited analytics and diagnostic data:
If you contact us through in-app support, we collect the content of your support conversations and any information you voluntarily provide during those interactions. Support conversations are processed by our customer-support sub-processor (Crisp) as described in Section 6.
When our automated, non-AI extraction cannot extract structured data with sufficient confidence, a short excerpt of the order-related content — never the full email body — is sent to a large language model ("LLM") for extraction.
All AI-assisted extraction is performed by a single provider:
Order-related excerpts from both Gmail and personal Outlook.com are processed by Google Cloud's Vertex AI service. Google's Cloud Data Processing Addendum prohibits training on customer data. Google Cloud is the only third party that receives email-derived content for AI processing.
Key protections:
Provider-side abuse monitoring. Our AI provider operates its own automated safety systems. Where a request is flagged by one of those systems, the provider may retain that individual excerpt for a limited period for abuse-prevention purposes, under its own data processing terms. This is the provider's security process, not Confi's, and it does not change what Confi stores: Confi never stores the raw email body, and we do not receive or retain the flagged excerpt.
Confi maintains backups of its production databases for disaster recovery and operational integrity.
Backup retention period. Backups are retained for 30 days from the time they are created. Backups older than 30 days are deleted automatically.
Deletion propagation. When you delete data using the in-app data deletion flow or delete your account:
Confi does not maintain backups beyond the 30-day window. Confi does not preserve copies of deleted data for any purpose except as required by applicable law or to investigate abuse (see the human-review carve-outs in Sections 2A and 2B).
This 30-day backup TTL is a permanent commitment of the Confi service. Any material change to backup retention will require a Privacy Policy update before such change is released.
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Structured order data | Until you delete it or delete your account | User-initiated in-app deletion or account deletion |
| Raw email body (parsing) | Not retained — discarded immediately after extraction | Automatic — never stored |
| Email body (viewer flow) | Not retained — session-scoped, in memory only | Automatic — cleared when the session ends |
| Account data | Until account deletion | User-initiated account deletion |
| Backups | 30 days | Automatic per Section 4A |
| Analytics events | Per PostHog retention policy (EU region) | Automatic per PostHog policy |
| Crash reports | Per Sentry retention policy | Automatic per Sentry policy |
| Support conversations | Per Crisp retention policy | Request via [email protected] |
Confi does not sell, rent, or share your personal information with third parties for their own purposes.
We use the following sub-processors to operate the Service:
| Sub-Processor | Purpose | Data Processed | DPA in Place |
|---|---|---|---|
| PostHog (EU region) | Analytics | Event names and non-PII properties only | Yes |
| Sentry | Crash reporting | Crash data with PII scrubbed | Yes |
| Crisp | Customer support | Support conversation content | Yes |
| Firebase Cloud Messaging (FCM) | Push notifications | Device tokens; no order content in payloads | Yes (Google Cloud Data Processing Addendum) |
| Google Cloud (Vertex AI) | AI-assisted extraction from order emails | Short excerpts of order-related email content | Yes (Google Cloud Data Processing Addendum) |
Sub-processor data processing terms. Each sub-processor listed above operates under data processing terms that bind that sub-processor to GDPR Article 28 obligations or equivalent:
Confi has reviewed each sub-processor's published security and compliance posture and confirms each sub-processor meets the security requirements appropriate to the data each processes.
We will update this sub-processor list before releasing any version of the App that adds or removes a sub-processor.
Confi's backend infrastructure is hosted in the United States. If you are located in the European Economic Area ("EEA"), United Kingdom, or Switzerland, your data is transferred to and processed in the United States.
We rely on Standard Contractual Clauses ("SCCs") as approved by the European Commission for international data transfers. These SCCs are incorporated in the data processing agreements in place with each sub-processor that processes personal data of EU users.
If you are located in the EEA, United Kingdom, or Switzerland, you have the following rights:
We will respond to all data rights requests within 30 days.
If you are a California resident, you have the following rights under the California Consumer Privacy Act ("CCPA"):
To exercise your rights, use the in-app data deletion flow (for deletion) or contact us at [email protected].
Do Not Sell or Share My Personal Information: Confi does not sell or share your personal information as defined under the CCPA. We do not sell your data to third parties. We do not share your data with third parties for cross-context behavioral advertising.
You may revoke Confi's access to your email at any time:
When your OAuth token is revoked (either by you or by your email provider):
If you want your stored data deleted after revoking access, use the in-app data deletion flow or contact [email protected].
What happens when you delete your account. We delete your account, your orders, your saved data, and the connection to your mailbox. We also delete the access tokens for your email account, so Confi can no longer reach it.
A small number of records about how our detection patterns performed are kept as anonymous statistics. Before they are kept, the link to your account is permanently removed and cannot be restored. These records contain no email content, no order details, and nothing that identifies you — only the retailer's sending domain, a content-free structural fingerprint of the message layout, and the result of the comparison. We maintain this information in anonymised form, and we do not attempt to re-identify it.
Confi is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at [email protected] and we will delete the data.
Users must confirm they are 13 or older during onboarding before accessing the App.
We implement industry-standard security measures to protect your data, including:
We will update this Privacy Policy if our data practices change. Material changes will be communicated through the App. The "Last Updated" date at the top of this policy reflects the most recent revision.
We will update the sub-processor list in Section 6 before any version of the App is released that adds or removes a sub-processor.
For any questions, concerns, or data rights requests:
Confi Technologies, Inc. Privacy Inquiries: [email protected] Principal Office (mailing): 513 W Shoreview Drive, San Ramon, CA 94582, United States Delaware Registered Agent: Harvard Business Services, Inc., 16192 Coastal Highway, Lewes, DE 19958, United States
Home · Privacy · Terms · Numbers · Founding
Confi Technologies, Inc. · San Francisco Bay Area
← Back to confi.ai · Confi Technologies, Inc., San Francisco Bay Area