Deb
What it does For sales How it works Thalassis ↗ Connect your accounts Connect

Privacy

Privacy

Last updated August 2026

Deb ("we", "us") connects your AI client to the email, calendar, and file accounts you choose to link. This policy explains what we access, what we store, and what we never do. It covers the Deb service operated by Thalassis.

What we access

When you link a Google or Microsoft account, you grant access via OAuth — we never see or store your password. We request the minimum scopes required to provide the features you use: reading, organizing, drafting, and sending mail; viewing and managing calendar events and availability; and searching, reading, and creating files. We request these only for the accounts you explicitly connect.

What we store

  • Your account identifiers (email address, provider) and the OAuth tokens needed to act for you, encrypted at rest.
  • Minimal operational metadata — such as which account a request used — to make the service work and to keep an audit trail. This records actions taken, never the content of them.
  • Content you explicitly stage for later: scheduled sends and unsent drafts, including any attachments you add to them. These are encrypted at rest and held only until the message is sent or you delete it.

Everything else — the mail, events, and files you ask about — is fetched on demand to answer your request, returned to your AI client, and not retained on our servers afterward. The distinction is simple: we store what you asked us to hold for you, not what we fetched to answer you.

What we never do

  • We never sell your data or share it with advertisers.
  • We never send email, create events, or modify your data without an explicit action you approve.
  • Each linked account is isolated to you; no other user can reach it.

How we protect your data

  • Encryption at rest. OAuth tokens, scheduled sends, and draft content are encrypted with AES-256-GCM before they reach our database, each record with its own random nonce. Encryption keys are held outside the database, and we have a documented key-rotation procedure.
  • Encryption in transit. All traffic to Deb, and onward to Google and Microsoft, travels over TLS.
  • Isolation between users. Row-level security is enabled across our data tables, and requests made on your behalf through your AI client run with per-user scoped database credentials rather than blanket access, so one account cannot reach another's data.
  • Secure sign-in. Sign-in uses passkeys — we never store a password. Every OAuth flow uses PKCE with S256 challenges.
  • Least privilege. We request the minimum provider scopes needed for the features you use, and only for the accounts you explicitly connect.
  • Content-free diagnostics. Our diagnostic logs are designed to exclude the contents of messages, files, and events.
  • Revocation on disconnect. Disconnecting an account revokes our access token with Google or Microsoft directly, not only on our side.

How long we keep your data, and how to delete it

  • OAuth tokens — until you disconnect the account or delete your Deb account.
  • Account identifiers — until you disconnect the account or delete your Deb account.
  • Scheduled sends — deleted within 30 days of being sent, failed, or cancelled.
  • Drafts — kept until you send or delete them.
  • Attachment blobs — deleted within 24 hours.
  • Audit metadata — up to 180 days, for security and abuse investigation. It contains no message, file, or event content, and it is de-identified when you delete your account.
  • Sign-in and OAuth artifacts — short-lived by design, from minutes to 30 days, then purged.

Disconnecting an account immediately revokes our access with Google or Microsoft and removes its stored tokens. Deleting your Deb account removes your accounts, tokens, drafts and scheduled sends. Any residual copies, including backups, are purged within 30 days.

Who we share with

Providing Deb requires sharing your content with a small set of processors, only as needed to deliver the features you use:

  • Your AI client. Content you ask about — email, events, files — is returned to the AI client you connect (such as Claude or ChatGPT) so it can answer you. That client operates under its own terms.
  • Messaging provider. For WhatsApp and LinkedIn features. If you attach a Google Drive or OneDrive file to a message you send, that file's contents are transmitted through this provider to deliver your message.
  • Hosting and database provider. Stores your encrypted tokens, staged message content, and operational metadata.

We do not transfer your data to anyone else except to comply with the law or as part of a merger, acquisition, or sale of assets with notice to you. We never sell your data or use it for advertising.

Human access

We do not allow humans to read your Google or Microsoft data unless: (a) you give affirmative consent to view specific items; (b) it is necessary for security, such as investigating abuse; (c) it is required by law; or (d) the data has been aggregated and anonymized for internal operations. Diagnostic logs are designed to exclude message, file, and event contents.

Disconnecting

You can unlink any account at any time from your account page, which revokes our access. You may also revoke access directly from your Google or Microsoft security settings.

Contact

Questions about privacy? Email deb.support@thalassis.co.

Deb

A Thalassis product · Privacy · Terms · Limited Use · thalassis.co