Privacy
Sula reads your mail so your dashboard can keep itself current. That is a real thing to ask for, so here is exactly what happens, in the order it happens.
Last updated 25 July 2026
What Sula connects to
Sula connects to Gmail and Google Calendar, and only ever reads. The access Google grants it cannot send, reply, delete, archive, or label anything. If Sula were compromised tomorrow, the most anyone could do with its access is read what you can already read.
The permissions are gmail.readonly and calendar.readonly. Sula requests nothing else, and no write permission is planned. You grant them on Google’s own consent screen and you can withdraw them at any time.
What Sula reads
Sula does not read everything. When you describe a view — the job applications you have open, the invoices you are waiting on — Sula searches your mail for what that view describes and opens only the threads that match. A view about apartments opens mail about apartments.
When it opens a thread it reads the sender, the recipients, the subject, the date, and the message text, shortened to the first part of each message. It does not download attachments. On Calendar it reads the events on your primary calendar.
What Sula keeps, and for how long
The text of a message is working material, not a record. It is held for under an hour in a short-lived cache so that two views reading the same thread do not fetch it twice, and then it is deleted outright. Sula never keeps the body of your mail, and never downloads attachments.
So that Sula can find the mail a view needs without re-reading your mailbox every time, it keeps a short index of the messages it has already seen: who sent each one, its subject line, and when it arrived. No message text, no attachments. Entries are deleted after about a year, and the whole index for a workspace is removed when you disconnect the account or delete your data.
What Sula does keep is the structured result: the company, the amount, the date, the status — the fields you can see on your dashboard — and a link back to the message each one came from, so you can always check a value against its source. Alongside that it keeps a record of the changes it made and why, so nothing it does is a surprise, and its own operational logs about how long things took and how much they cost.
This information is kept for as long as you have an account. When you close your account it is deleted.
Who else sees it
To turn a message into a row, Sula sends the text of matched threads to Google’s Gemini model. Sula uses the paid tier, whose terms state that Google does not use the content to train or improve its models and does not have people review it; Google retains it briefly only to detect abuse of its service.
Beyond that, the companies that run Sula’s infrastructure hold your data because they store and move it for us: Supabase (database), Vercel (the servers the app runs on), and Inngest (scheduling). They act on Sula’s instructions and for no other purpose.
That is the complete list. Sula does not sell your data, does not share it for advertising, and does not use it to build a profile of you for anyone else.
Google API Services User Data Policy
Sula's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sula does not use information received from Google Workspace APIs to develop, improve, or train non-personalized artificial-intelligence or machine-learning models. Your data is used only to produce your own dashboard and brief, and is never pooled with another user’s to build anything shared.
In plain terms: Sula uses Gmail and Calendar data only to provide the dashboard and daily brief you can see in the app. Sula does not transfer this data to anyone except as necessary to provide those features — the language model described above — to comply with the law, or in a merger or acquisition with your explicit consent. Sula does not use this data for advertising of any kind. Sula does not allow people to read this data, except with your explicit consent, where necessary for security, to comply with the law, or where the data has been aggregated and anonymised for internal operations.
You can read the policy itself at developers.google.com/terms/api-services-user-data-policy.
Your choices
You can disconnect Gmail or Calendar at any time from the Account tab. Disconnecting revokes Sula’s access at Google immediately and deletes the keys Sula holds, so no further reading is possible.
You can ask for a copy of everything Sula holds about you, ask for it to be corrected, or ask for all of it to be deleted, by writing to privacy@getsula.ai. Deletion removes your dashboards, your rows, the change history, and any cached message text, and closes your account. It is completed within 30 days and usually much sooner. Where you are covered by the UK or EU GDPR, these are your rights of access, rectification, erasure, restriction, objection and portability, and you may also complain to your data protection authority.
Nothing Sula decides automatically is final. Every automated change is recorded with the message that caused it, and you can undo it in the app for a day afterwards.
Where your data sits, and keeping it safe
Sula runs on servers in the United States. If you are in the UK or the European Economic Area, your information is transferred there under the standard safeguards our providers offer for such transfers.
The keys that grant Sula access to your accounts are encrypted before they are stored, and only Sula’s servers can read them. Access to the production database is limited to the application itself.
Children
Sula is not intended for anyone under 16, and we do not knowingly collect information from children. If you believe a child has an account, write to us and we will remove it.
Changes, and how to reach us
If this policy changes in a way that affects what happens to your data, we will tell you in the app before the change takes effect. For anything at all about privacy, including the requests above, write to privacy@getsula.ai.