Privacy Policy

Callback List, operated by Scorptek LLC · Last updated 14 July 2026

Callback List connects to your work mailbox and tells you which email threads are waiting on a reply from you, and which ones have gone quiet. This page explains exactly what we access, what we keep, who we share it with, and how to make us delete it.

The short version. We read your Gmail in read-only mode — we cannot send, delete, or modify anything. We do not store the contents of your emails. We send limited parts of a thread (subject, participants, timestamps and a short preview snippet) to an AI provider so it can sort your inbox, and we keep only the short summary card it produces. We never use your data to train AI models, and neither does our AI provider. You can delete your account and everything in it at any time, from inside the app.

1. Who we are

Callback List is operated by Scorptek LLC ("we", "us"). For the purposes of the UK/EU GDPR, when you use Callback List with your work mailbox we act as a processor on behalf of your employer or firm, which is the controller. Where you sign up as an individual, we act as controller for your account data.

Contact: [email protected]

2. What we access from your Google Account

When you connect Gmail, we request a single, restricted scope:

ScopeWhat it allowsWhy we need it
gmail.readonly Read your mail. It does not permit sending, deleting, or modifying anything. To see which threads are awaiting your reply and which have gone quiet. A narrower scope does not work: gmail.metadata cannot search your mailbox, so it cannot find the threads to review.
openid, email Your Google account identifier and email address. To link the mailbox to your Callback List account.

We physically cannot send email on your behalf. Every draft the product suggests is copied by you into Gmail. Nothing is ever sent automatically.

3. What we actually process, and what we keep

This is the part most privacy policies are vague about, so we will be precise.

Processed, but never stored

To review a thread we fetch, in memory only: the subject line, the participants, message timestamps, read/unread state, and the snippet — the short preview of the message that Gmail returns. When you explicitly open an item to draft a reply, we also fetch that thread's message text so it can be summarised.

To be clear, because it matters: a snippet and a message body are email content, not merely metadata. We do not pretend otherwise. That content is held in memory for the duration of the request and is never written to our database.

Stored

WhatWhyKept for
Your email address, and a hash of your password if you set oneYour accountUntil you delete your account
Your Google refresh token, encrypted (AES-256-GCM)To reconnect to your mailbox without asking you to sign in repeatedlyUntil you disconnect Gmail or delete your account
Derived cards: a one-line summary, a category (needs reply / waiting on them / FYI / ignore), an urgency score, and any candidate name, role, stage or next step stated in the threadThis is the product — the worklist you see30 days, then automatically deleted
Gmail thread IDs (pointers, not content)So a card links back to the right thread in Gmail30 days
A writing-style profile derived from your sent mail, encrypted at restSo suggested drafts sound like you (only if you enable it)Until you delete it or your account
Usage counters and basic request logsBilling, rate limiting, security and debuggingRolling, short-term

We do not store the body of your emails. Not in our database, not in backups, not in a cache.

4. AI processing — and who sees your data

Callback List uses third-party AI models to classify threads and draft replies. This means limited parts of your email content leave our servers.

Google API Services User Data Policy.

Callback List's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we use Google user data only to provide and improve the user-facing features you can see in the app; we do not transfer or sell it for advertising, credit-scoring, or any unrelated purpose; we do not allow humans to read it except with your explicit consent, for security purposes, to comply with law, or where the data is aggregated and anonymised; and we do not use it to develop, train, or improve generalised AI or machine-learning models.

5. Sub-processors

These are the third parties that may process your data on our behalf. We are responsible for them.

Sub-processorPurposeData it may seeLocation
Anthropic (Claude)Thread classification, summaries, draft repliesSubject, participants, timestamps, snippets; thread text when you open an itemUnited States
OpenAISpeech-to-text and text-to-speech — only if you use voiceYour spoken query and its transcriptUnited States
GoogleThe mailbox itself (your own account)Your mail, under a read-only grant you controlUnited States
RailwayApplication hosting and databaseEverything listed under "Stored" aboveUnited States
StripePaymentsBilling details. We never see or store your card number.United States
ResendTransactional email (sign-in links)Your email addressUnited States

We will give notice before adding a new sub-processor. International transfers out of the UK/EEA are made under the Standard Contractual Clauses.

6. About other people's data

Your mailbox contains messages from candidates and clients who have never heard of us. We take that seriously.

If you are a candidate and believe a Callback List customer holds your data, contact the recruiter or firm directly — they are the controller. You can also write to us at [email protected] and we will assist them in responding.

7. Security

No system is perfectly secure. If you find a vulnerability, please report it to [email protected] — we will not pursue good-faith researchers.

8. Your rights, and how to actually use them

You can, at any time:

If you are in the UK or EEA and think we have handled your data badly, you may complain to your national data-protection authority.

9. Legal basis (UK/EEA)

Where we act as controller: performance of a contract (providing the service you asked for), and our legitimate interests in securing the service and preventing abuse. Where we process your mailbox on behalf of your employer, they determine the legal basis and we act on their documented instructions.

10. Cookies

We set one strictly-necessary cookie (cbl_session) to keep you signed in, plus short-lived cookies during sign-in and Google connection to protect against cross-site request forgery. We do not use advertising or tracking cookies, and we do not run third-party analytics.

11. Children

Callback List is a business tool and is not directed at anyone under 18.

12. Changes

If we change this policy materially — particularly if we add a sub-processor or change what we send to an AI provider — we will notify account holders by email before it takes effect.