Who operates Pidgeot
Operator: Siddharth S.
Privacy contact: siddharthajith97@gmail.com.
Privacy policy
This policy describes the current Pidgeot application. You sign in with Google, connect Gmail only if you choose to, and stay in control of unsubscribe and Trash actions.
Operator: Siddharth S.
Privacy contact: siddharthajith97@gmail.com.
Pidgeot uses Google sign-in to learn the verified account email needed to create your session.
After you separately connect Gmail, Pidgeot reads Gmail message metadata only. The headers used for analysis are From, To, Subject, Date, List-Unsubscribe, List-Unsubscribe-Post, List-ID, Precedence, Reply-To, and Sender.
Pidgeot does not fetch message bodies, snippets, or attachments.
Sign-in requests the OpenID scopes openid and email.
Gmail access is a second, explicit step. That step requests https://www.googleapis.com/auth/gmail.modify so Pidgeot can scan your Gmail metadata and move unread messages you select to Gmail Trash.
Moving mail to Trash is not permanent deletion. Gmail keeps trashed messages according to Gmail’s own Trash rules.
Metadata is used to group recurring senders, show you what Pidgeot found, and let you choose keep, unsubscribe, or Trash cleanup.
Pidgeot does not decide on your behalf. Classification uses local rules on the server. It does not send mailbox data to an external AI or LLM service.
If you ask Pidgeot to unsubscribe, it may submit a request using the unsubscribe mechanism advertised on the email, such as a standard one-click HTTPS request.
Those one-click requests are sent from Pidgeot’s server. The destination is the unsubscribe address from the email, not an address supplied by your browser.
The destination receives the request that mechanism requires. Pidgeot does not send Gmail message bodies to unsubscribe endpoints.
If only a manual or mailto instruction is available, you remain in control of that step.
A submitted unsubscribe request does not guarantee that a sender will stop sending mail.
OAuth tokens for an active session are held in server process memory so Pidgeot can talk to Google on your behalf during that session.
Tokens are not persisted to a database, the filesystem, browser localStorage, or analytics systems.
Pidgeot does not see or store your Google password.
Pidgeot does not keep a persistent Gmail message database.
Session, scan, and cleanup state live in the memory of the running application process. That state is discarded when the process restarts.
Pidgeot does not currently restore cleanup progress across devices or restarts.
Google receives OAuth and Gmail API requests when you sign in, connect Gmail, scan, or move selected unread mail to Trash.
If you run an automatic unsubscribe, the unsubscribe destination from the email receives that unsubscribe request.
Pidgeot does not send Gmail data to advertising, analytics, error-reporting, or external AI providers.
Signing out of Pidgeot ends the Pidgeot session and clears that process-local session. It does not revoke Google’s OAuth grant.
You can revoke Pidgeot’s Google access from your Google Account permissions. After that, Pidgeot cannot use Gmail until you connect it again.
Google sign-in uses OAuth state validation and PKCE.
Gmail reads and Trash moves happen on the server. The browser does not supply Gmail message IDs or unsubscribe URLs to execution endpoints.
Pidgeot does not persist Gmail message content.
Questions about this policy: siddharthajith97@gmail.com.