Your inbox, your ledger,your data — and your call.
We read your Gmail so your books close themselves. Here's exactly what we collect, how we use it, how long we keep it, and the controls you have at every step. No surprises, no dark patterns.
Last updated · August 3, 2026
What we collect
Three things, and only three things — your account email, your Gmail receipt and subscription traffic, and your billing information.
- Account email. The address you use to sign in. We use it to authenticate you and to send product and billing notifications.
- Gmail messages — metadata and body. When you connect Gmail, Bookwren requests the
gmail.readonlyOAuth scope. We read message metadata (sender, recipient, date, subject) and message body content for the receipts, invoices, and subscription notices that drive your ledger. The scope is read-only — we never send, delete, or modify mail on your behalf. - Billing information, via Stripe. Paid plans are billed through Stripe-hosted checkout. We never see your card number — Stripe handles the card form, the PCI surface, and the recurring subscription. We store only the Stripe customer and subscription identifiers and the plan tier you chose.
How we use it
Everything we read feeds the bookkeeping pipeline — the categorization, the subscription audit, and the monthly packet your accountant opens at month-end.
- Schedule C transaction categorization. Receipts and invoices are matched to the IRS Schedule C line items your accountant already uses — utilities, software, supplies, travel, contractors — and dropped on the right row of the categorized ledger.
- Subscription auditing. Recurring charges are watched over time. Duplicate subscriptions (two tools doing the same job) and price-creep (the same SaaS charging you more six months later) are flagged before they compound.
- Monthly bookkeeper packet. At month-end we assemble the categorized ledger, the subscription audit, and any items that need a human eye into a single packet your bookkeeper can open without re-keying anything.
What we don't do
The list of things that will never happen on your inbox:
- We never sell your data — not to marketers, not to data brokers, not to anyone.
- We never train third-party models on your inbox. The categorization pipeline is purpose-built for receipts and subscriptions; nothing about your mail leaves the Bookwren pipeline to be used as model training data.
- We never read mail outside the categorization pipeline. Promotions, personal correspondence, and anything that isn't a financial event is filtered out before it's ever shown to a human or a model.
- We never write, send, delete, or label mail. The
gmail.readonlyscope is read-only by definition.
Retention
Your data lives in Bookwren only while your account is active. When you close your account — or when a paid subscription ends and is not renewed — your Gmail-derived data and your categorized ledger are permanently deleted within 30 days. The Stripe subscription record is retained only for as long as Stripe requires for tax and refund purposes; once that period closes, we delete our copy of the customer identifier.
While your account is active, you can export everything we hold on you (the categorized ledger, the subscription audit, the categorization decisions) and you can request full account deletion from the dashboard settings — both are surfaced in the app, no support ticket required.
Your rights
You stay in control of your data at every step. Concretely, you can:
- Export everything. Download your full categorized ledger, the subscription audit, and every categorization decision as a CSV or JSON, from the dashboard.
- Delete your account. Close the account from dashboard settings and we wipe Gmail-derived data and the ledger within 30 days. The Stripe billing record follows the retention rule above.
- Read the categorization audit log. Every categorization decision is logged with the message it came from, the category it was assigned to, and the rule or model signal that fired. Open the log from the dashboard, see exactly why a charge landed where it did, and override it if the rule was wrong.
- Disconnect Gmail at any time. Revoke the OAuth grant from your Google account or from Bookwren settings. The moment the grant is revoked, Bookwren stops reading mail.
Subprocessors
To run the service we rely on a small set of trusted subprocessors. Each one handles a specific part of the pipeline and receives only the data it needs to do that job.
- Google. Gmail OAuth and the Google Cloud region where the categorization pipeline runs.
- Stripe. Billing and subscription management, including card handling on Stripe-hosted checkout.
- Hosting & database provider. Application hosting and the managed database that stores your categorized ledger and audit log.
- AI inference provider. The model API used to extract merchant, amount, and date from receipt and subscription messages.
We keep this list short on purpose — every subprocessor is added to a written data processing agreement and reviewed before it goes live.
Questions about your data?
We'd rather answer a privacy question before you sign up than after. Email us at getbookwren@polsia.app and a real human will reply within one business day.
Have more questions?
Want a walkthrough of the categorization audit log, or a plain-English explanation of the Gmail scope before you connect? Reach out and we'll talk it through.
Talk to us