Legal
Privacy Policy
Operated by Scalatic Digital · Last updated: March 17, 2026
Follow-Through ("the Service", "we", "us") is a product of Scalatic Digital. This Privacy Policy explains how we collect, use, and protect your personal information when you use Follow-Through. By using the Service, you agree to the practices described here.
For Scalatic's broader company privacy policy, visit scalatic.com/privacy.
1Information We Collect
Account Information
When you sign up, we collect your name, email address, and profile picture through Google OAuth. This is used solely to create and manage your Follow-Through account.
Gmail Data
When you connect your Gmail account, we access your emails using the gmail.readonly scope. This means:
- We can read your email messages — we cannot send, delete, or modify them.
- We fetch email subject lines, body text, sender/recipient addresses, and timestamps.
- We process emails to detect commitments you have made ("I'll send the report") and questions directed at you ("Can you review this?").
- Raw email content is transmitted to our AI processing engine for analysis. It is not permanently stored. Only the extracted commitment/question text, entities, and metadata are saved to our database.
- We do not read attachments, calendar data, contacts, or any data outside of email messages.
Usage Data
We collect standard usage data including pages visited, features used, and actions taken within the dashboard. This helps us improve the Service.
Billing Information
Payment is handled by Stripe. We do not store your credit card number or full payment details. Stripe stores payment information subject to their own privacy policy.
2How We Use Your Information
- To provide the core service: scanning emails, extracting commitments and questions, and displaying them in your dashboard.
- To send digest emails: a daily or weekly summary of your outstanding follow-throughs, delivered to your registered email address via Resend.
- To manage your account and subscription, including billing through Stripe.
- To improve and debug the Service using aggregated, anonymized usage data.
- To communicate with you about product updates, important notices, and support requests.
We do not use your email data to train AI models. We do not sell, rent, or share your personal data with third parties for advertising purposes.
3Gmail & Google API — Specific Disclosures
Follow-Through's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is used only to provide and improve Follow-Through's core email tracking service.
- We do not transfer Google user data to third parties except as necessary to operate the Service (e.g., AI processing described in Section 4), and never for advertising or to data brokers.
- We do not use Google user data for serving ads.
- We do not allow humans to read your Gmail data unless you have explicitly given permission, or it is required for security purposes or to comply with applicable law.
- You can disconnect your Gmail account at any time from Settings → Integrations. Upon disconnection, your OAuth tokens are immediately revoked and deleted from our database.
4AI Processing & Third-Party Services
To extract commitments and questions from your emails, we transmit email text to OpenAI's API (GPT-4o model). This is the core function of Follow-Through.
- Email content sent to OpenAI is subject to OpenAI's API data usage policy. OpenAI does not use API data to train models by default.
- We transmit only the minimum required content (subject, body snippet, sender/recipient metadata) needed for detection.
- We also use OpenAI's text embedding API to generate semantic similarity vectors for deduplication purposes. These vectors are stored in our database but contain no readable text.
Other Sub-processors
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & Authentication | Account info, extracted follow-throughs, OAuth tokens |
| OpenAI | AI extraction & embeddings | Email subject + body text (transient) |
| Resend | Transactional email delivery | Your email address + digest summary |
| Stripe | Billing & subscriptions | Email address, payment details |
| Google (Gmail API) | Email access (OAuth) | OAuth tokens, email content (read-only) |
5Data Retention
- Raw email content is never permanently stored. It is processed in memory and discarded after extraction.
- Extracted follow-throughs (the commitment/question text, entities, status) are retained for as long as your account is active, plus 30 days after account deletion.
- OAuth tokens (Gmail refresh tokens) are stored encrypted and deleted immediately upon disconnecting the integration or deleting your account.
- Account data is deleted within 30 days of account deletion upon request.
- Billing records may be retained for up to 7 years to comply with financial regulations.
6Security
We implement industry-standard security measures including:
- HTTPS/TLS encryption for all data in transit.
- Encryption at rest for sensitive data including OAuth tokens.
- Row-Level Security (RLS) policies enforced at the database level — users can only access their own data.
- OAuth tokens are stored with minimal scope (
gmail.readonlyonly — we cannot send or delete your emails). - Service-role database access is restricted to server-side processing jobs only.
7Your Rights & Choices
- Access: You can view all your follow-throughs in the dashboard at any time.
- Deletion: You can delete individual follow-throughs from the dashboard, or delete your entire account from Settings.
- Disconnect Gmail: Remove Gmail access at any time from Settings → Integrations. This immediately revokes our access and deletes stored tokens.
- Data export: Contact us to request a full export of your data.
- Correction: Contact us to correct inaccurate account information.
- GDPR/CCPA: If you are in the EU or California, you have additional rights under GDPR and CCPA respectively. Contact us at privacy@scalatic.com to exercise these rights.
8Children's Privacy
Follow-Through is intended for professional use and is not directed at children under 13. We do not knowingly collect personal information from children under 13.
9Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice in the app. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
10Contact Us
For privacy-related questions or to exercise your rights, contact: