Privacy Policy
Last updated: April 17, 2026
Digest (“Digest,” “we,” “us”) is a reading app that helps you collect and read articles from RSS feeds and newsletters. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using Digest you agree to this policy.
1. Information we collect
Account information
When you create an account we collect the information you provide, such as your email address, phone number, or the identifier returned by your chosen sign-in provider (Apple, Google). If you use Sign in with Apple’s private-relay email, we only receive the relay address.
Email inbox connection (Gmail, Outlook, iCloud)
If you choose to connect an email account to find newsletters you already subscribe to, Digest accesses a limited subset of messages in your inbox solely to detect newsletter senders. Specifically:
- We read message headers only (From, Subject, Date, List-Unsubscribe, List-ID, Precedence, X-Mailer) for messages received in the scan window you select. We do not read message bodies or attachments.
- We aggregate headers into a list of detected newsletters and show that list to you. Only the sender name, sender email, sender domain, estimated frequency, and most recent subject line are displayed or stored as part of the scan result.
- We do not download, copy, or persist the content of your emails.
OAuth tokens and email credentials
When you connect Gmail or Outlook, we receive an OAuth refresh token and short-lived access tokens from the provider. When you connect iCloud, we receive the app-specific password you provide. These credentials are encrypted at rest (AES-GCM with a key stored separately from the database) and are used only to perform scans you initiate. You can disconnect an email account at any time from Digest’s settings, which deletes the stored credential.
Content you add to Digest
Feeds you subscribe to, articles Digest fetches from those feeds, channels, tags, highlights, and reading state are stored in your Digest account so they are available across your devices.
Technical information
We collect standard server logs (IP address, user agent, timestamp, request path) to operate and secure the service. Logs are retained for up to 90 days.
2. Google API Services User Data Policy (Limited Use)
Digest’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, data obtained through Gmail APIs is:
- used only to provide or improve the newsletter-detection feature you explicitly enabled;
- not used for advertising;
- not sold and not transferred to third parties except as necessary to provide or improve the feature, to comply with applicable law, or as part of a merger or acquisition with the same protections in place;
- not read by humans except with your explicit consent, for security purposes (e.g., investigating abuse), to comply with law, or in aggregated and anonymized form for internal operations.
3. How we use information
- To operate, maintain, and secure Digest;
- To perform inbox scans and display newsletter-import suggestions;
- To fetch, parse, and deliver RSS articles you subscribe to;
- To sync your reading state across your devices;
- To respond to your support requests;
- To detect and prevent fraud, abuse, or violations of our terms.
4. How we share information
We do not sell your personal information. We share information only in the following circumstances:
- Service providers. We use Supabase to host our database, authentication, and backend functions. Supabase processes data on our behalf under a data-processing agreement.
- Email and identity providers. When you connect Gmail, Outlook, or iCloud, we communicate with those providers on your behalf using the credentials you authorized.
- Legal. We may disclose information if required by law, court order, or to protect the rights, property, or safety of Digest, our users, or others.
- Business transfers. If Digest is involved in a merger, acquisition, or sale of assets, your information may be transferred, subject to the same protections as this policy.
5. Data storage and security
Data is stored on Supabase infrastructure hosted in the United States. Row-level security ensures each user can only access their own data. OAuth refresh tokens and IMAP app passwords are encrypted at rest with AES-GCM. Transport to and from Digest uses TLS. No system is perfectly secure, but we work to protect your information against unauthorized access.
6. Data retention
We retain account information and content for as long as your account is active. When you delete your account, we delete associated data within 30 days, except where retention is required by law. You can also disconnect an email account at any time; doing so immediately deletes the stored credential.
7. Your rights and choices
- Access and correction.You can view and edit your account details from Digest’s settings.
- Deletion. You can delete your account at any time from settings, or by emailing us.
- Revoke access.You can revoke Digest’s access to your Gmail, Outlook, or iCloud account at any time from the provider’s security settings (Google, Microsoft, Apple) or by disconnecting from Digest’s settings.
- Regional rights. If you are in the EEA, UK, or California, you may have additional rights (access, portability, objection, restriction). Contact us using the information below to exercise them.
8. Children’s privacy
Digest is not directed to children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, please contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. Material changes will be announced in-app or by email before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.
10. Contact
Questions or requests regarding this policy can be sent to [email protected].