Privacy

closegraph.com · September 4, 2026

What closegraph does

You connect your Gmail. closegraph works out who you exchange email with. Other members of your circle can then search a name and see whether you know that person, and how close you are.

What we read

We ask Google for the gmail.metadata permission. That permission lets an app read message headers, including subject lines, and labels. It cannot return the text of a message or attachments. We never ask for a permission that could.

closegraph uses less than the permission allows. It requests exactly four headers from each message: from, to, cc, and date. Google returns only those. Subject lines are never requested or received. Labels come back with every message and are discarded. Google also tells us your name and email address so we know which account is yours.

Which messages: closegraph first lists the ids of every message in your mailbox. Ids carry no content. The list shows which conversations had mail both ways: you wrote and someone answered, or someone wrote and you answered. closegraph reads the four headers of the messages in those conversations only. Mail that went one way, in either direction, is never read.

What we keep

Who sees what

Another member can type a name and learn that you correspond with that person, a closeness score, and the organization behind the address (its domain, or “personal address”). They never see the email address, message counts, dates, or anything you wrote. They cannot browse your contacts. Search takes a first and last name and returns only people you have exchanged mail with in both directions.

What we don’t do

We don’t sell your data, use it for advertising, or give it to anyone outside closegraph except the services that run it (a server and a backup). No person reads it, except with your permission, to investigate abuse, or if the law requires it. closegraph’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Leaving

On the home page, while signed in, you can delete any one account or delete everything. Either way closegraph revokes its own access at Google and deletes what it indexed from that account at once. The nightly backup ages out within 30 days. You can also revoke closegraph in your Google Account permissions, which stops our token but leaves the index until you delete it here or email [email protected].

Security

One server, run by us. Tokens are encrypted at rest (AES-256-GCM). Everything travels over HTTPS.

Questions

Nick Soman, [email protected].

Home · Security · Terms