← Back to blog

Privacy by design: how Rewado earns trust without selling you

A walkthrough of every place your data touches our system — what stays on your phone, what leaves it, who processes it, and how long we keep it.

When you build a rewards app powered by people’s inboxes, the only thing that matters is whether you can be trusted. Here’s exactly what happens when you connect Gmail to Rewado — including the parts that are less flattering than a marketing page would tell you.

What stays on your phone, and what leaves it

Your Gmail credential never leaves your device. You generate a Google app-specific password and enter it in the app, where it is stored encrypted on the phone. We never receive it, and we never see your main Google password. Be aware of what that credential is, though: an app password technically grants broad mailbox access, and we use it solely to find and process promotional mail.

The mailbox scan runs on your device. The app reads mail locally and classifies each sender as a company or a person — that check involves reading the message on the phone, and it can touch senders you have no relationship with. Only mail from allowlisted company senders goes any further. Mail from people is discarded, and other messages are not retained.

Screenshots do leave your device, and they are read by AI. When you upload a screenshot of a promotional SMS or push notification, that image goes to our servers and is processed by Google Gemini (via Vertex AI) and Google Cloud Vision for text extraction and offer details. Our own trained reviewers, bound by confidentiality, quality-check the results and may see content before de-identification is complete. You choose what to upload, each time — but once uploaded, the image is processed server-side, not on your phone.

What we keep, and for how long

DataWhere it livesRetention
Gmail app passwordEncrypted on your device onlyUntil you disconnect
Sender-classification (triage) metadataServer30 days, then auto-purged
Raw promotional content (emails, images, extracted text)Server (Neon, Frankfurt; images in Google Cloud Storage, EU)Until the insight is extracted and verified, then a 3-month clarification window
Pseudonymised research datasetServerWhile you participate; deleted 30 days after the relationship ends
Account identity and contactServerWhile your account is active, plus a short tail
Crash and error diagnosticsFirebase Crashlytics; Sentry (EU, Frankfurt)Up to 90 days
Backups and operational logsServerA further 30–35 days after live deletion

The architecture

Your phone
   ↓  app password held encrypted on-device
   ↓  local IMAP scan → classify sender: company or person
   ↓  mail from people discarded
Our servers (Vercel API; Neon Postgres, Frankfurt; GCS, EU)
   ↓  Gemini (Vertex AI) + Cloud Vision read the content
   ↓  human review; direct identifiers removed
   ↓  persona assigned  ← this record stays linkable to you
Customer-facing dataset (pseudonymised, persona-level)

Pseudonymised, not anonymous

This is the part worth being precise about, because the industry is usually sloppy with it.

What our business customers receive is pseudonymised: your name and email are removed, and they see that a communication reached a given persona — never your identity. But our internal research records remain linkable to you. That makes them personal data under the GDPR, with all the rights that follow, and we treat them that way rather than calling them anonymous.

So: there is no path from what a customer sees back to you. There is a path from our internal records back to you — which is exactly why you can ask us for a copy, ask us to correct it, or ask us to delete it.

What we sell

Pattern data at the brand and persona level:

  • “Brand X sent 4.2 emails per week to opted-in participants in March”
  • “Brand Y’s average subject-line length grew 18% YoY”
  • “Push notifications from category Z peaked at 7pm local”

That’s the product. The companies running these brands pay us for that intelligence. You get a cut for letting your messages contribute to the dataset. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Auditability

Every provider that processes your data is listed publicly at rewado.io/subprocessors — what each one does, where it sits, and the transfer safeguard we rely on. The full picture of purposes, legal bases, retention and your rights is in the Privacy Policy.

You can disconnect your email integration any time from Settings → Privacy, and access is cut immediately. Account deletion erases your data; if you withdraw consent or ask for erasure, raw content is deleted promptly rather than waiting out the retention window above.

If you spot something we should explain better — or something here that doesn’t match what you see in the app — write to support@rewado.io.