Privacy Policy
Last updated: July 24, 2026
bonsai (“we”, “us”) is a feed of brand opportunities that lets you pitch a brand in one tap. This page explains exactly what data we collect, why, and what we do with it — including the Google Gmail data covered by Google’s Limited Use requirements.
1. Information we collect
- Account information.Your email address, and — depending on how you signed up — either your Google account’s name and profile photo, or a name and password you provide directly (the password is stored only as a salted hash, never in plain text).
- Preferences.The role (“I am a…”) and interest tags you pick during onboarding, used to rank which brand opportunities we show you first.
- Pitch history.Each time you click “Pitch,” we store the brand, product, recipient address, subject, and message body of that pitch, plus whether it sent successfully — so you have a record on your own “Sent pitches” page.
- Google account data (only if you sign in with Google). Your Google OAuth access and refresh tokens, used solely for the purpose described in Section 2 below.
2. How we use Google user data
If you sign in with Google, we request one Gmail scope: gmail.insert. We use it for exactly one thing: when you click “Pitch,” after your pitch email is sent, we file a copy of that same message directly into your own Gmail Sentfolder, so it’s visible from Gmail itself without needing to open this app.
This scope does not let us, and we never:
- Read, search, or view any of your existing email
- Send email on your behalf without you clicking “Pitch” yourself
- Modify, delete, or forward any message already in your mailbox
- Share your Google data with any third party, or use it for advertising
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use your data
- To authenticate you and keep you signed in
- To rank brand opportunities against the interests you picked
- To compose and send the pitch emails you request, and log them on your Sent pitches page
- To file a copy of a sent pitch into your Gmail Sent folder (Google sign-in only, see Section 2)
We do not sell your data, and we do not use it for advertising.
4. Third parties we rely on
- Google — authentication and, if granted, the Gmail Sent-copy feature described above.
- Resend — the email relay that actually delivers your pitch emails over SMTP.
- Neon — our Postgres database host, where your account and pitch records are stored.
- Bonsai’s public brand-tracking API — the source of the brand/product feed itself. We only send it read requests; no account or personal data of yours is ever sent to it.
5. Data retention and deletion
We keep your account and pitch history for as long as your account exists. To request deletion of your account and all associated data — including revoking stored Google tokens — email teams@bonsai.ink. You can also revoke this app’s access to your Google account at any time from your Google Account permissions page.
6. Security
Passwords are hashed with bcrypt before storage — we never store or transmit plain-text passwords. OAuth tokens are stored server-side only and are never exposed to the browser or to any third party besides Google itself.
7. Contact
Questions about this policy or your data can be sent to teams@bonsai.ink.