Week in Hand — Privacy Policy

Effective date: August 10, 2026

Who we are. Week in Hand is a service operated by SparkForge, LLC ("SparkForge," "we," "us"). Week in Hand reads your school email and turns it into short summaries of what your children's school needs from you. SparkForge, LLC is the data controller responsible for the personal data described in this policy. This policy explains what data Week in Hand accesses when you connect your Google account, what we do with it, what we keep, and the choices you have.

Plain-English summary (the whole thing, briefly). If you connect Gmail, Week in Hand reads your recent email read-only to find messages from your kids' school and build you a short summary of what's coming up ("your week"). You can also ask us to build one for an earlier period, or to show you what your school has sent over time; we read that period in the same read-only way. If one of those emails carries an attachment, or links to a Google Doc or Sheet that anyone with the link can open, we may read that text too. To write the summary, we send that content to our AI processing provider(s). We can't send, reply, change, or delete anything in your mailbox. We never copy your mailbox. What we build for you — and enough of the original email to show you where each item came from — we keep only as long as the features you have turned on require. We never sell your data, use it for advertising, or use it to train general-purpose AI models. You can disconnect at any time, and reading stops immediately.

1. The Google data we access

When you choose to build your week, Week in Hand requests these Google permissions:

The gmail.readonly scope is read-only. Google enforces this at the permission level: Week in Hand cannot send, reply to, label, modify, archive, or delete any message, and this permission gives us access to no other part of your Google account.

What we actually read. We read your email when you ask us to, and on a schedule — we set one up for you when you start, and the day, the time, and whether it runs at all are yours to change. We also read to check whether something time-sensitive has come up or changed — an event cancelled, a deadline moved, a form due sooner than you thought — so we can tell you without waiting for your next summary. A read that happens without you present reads exactly what an on-demand one reads; turning the feature off, or disconnecting Gmail, stops it. By default we read a recent window of your mail — about the past week — and only a bounded number of messages from it. When you ask us for a different period, such as an earlier week or a look back across the school year, we read that period instead, under the same kind of bound.

Whose mail we read. When you have configured a list of your kids' school senders, we build your summary only from messages from those senders. When you haven't, we read the messages in that window and build your summary from the school-related ones — telling them apart is part of producing the summary, so every message we read in that window is processed as described in Section 2.

Finding senders you haven't added. A school rarely writes from one address, so one you never thought to add is easy to miss. To catch those, we check a bounded window of your recent mail — when you first set up, and to keep that list current — for a single purpose: working out which senders are your school's, so we can suggest them to you. We use the least that will tell us: who each message is from and its subject line, and the message itself only where those aren't enough. Nothing we find this way is used for anything else, and you decide which suggestions to accept.

Every read is a bounded, targeted query for the mail we need — we never scan your whole mailbox, and we never copy or sync it. We do not use what we read for anything other than providing and improving the summaries, notices, views, and suggestions described in Section 2.

Attachments, and documents linked in those emails. School email often carries a file, or links out to a Google Doc or Sheet — a supply list, a class calendar, a sign-up sheet. We read a file attached to a message on the same terms as the message itself. When a message we read links to such a document and that document is readable by anyone who has the link, we may fetch its text and use it exactly the way we use the email itself: to build your summary. Only a bounded number of documents are fetched for any one summary, and their text is kept on the same terms as the email itself (Section 7).

We request the minimum permissions our features need. We do not request access to data we don't use, and we will never request permission to send, change, or delete your mail. We do not request Google Drive or Google Calendar access in this version.

2. How we use your Gmail data

We use the content of your email for one purpose: to turn what your children's school sends you into what you need from it, for your account and no one else's. That means your summary of what to do, what to know, and what to decide; a summary for an earlier period when you ask for one; a timely notice when something we have read changes and can't wait for your next summary; a view of what your school has sent you and what we made of it; and suggestions of which school senders to include. We use it for nothing else.

To produce these, we send the email content we read — together with the text of any attachments or linked documents we read (Section 1) — to our AI processing provider(s), which return the extracted items and the summaries for your account. A provider may use this content to return that result to us, and otherwise only for the limited operational purposes described just below. Neither we nor our AI providers use your content to train, create, or improve generalized, non-personalized, foundation, or frontier AI models — we restrict our providers from doing so. The provider we use today is named in the sub-processor list in Section 4.

What an AI provider keeps. We do not hold a zero-retention agreement with any AI provider. The content we send is subject to that provider's standard retention terms: it is held for a limited period so the provider can detect abuse, protect the security of its service, and meet its legal obligations. Content that a provider's safety systems flag may be held substantially longer than that ordinary schedule. If we obtain stronger retention terms from a provider, we will use them.

3. What we store

When you connect Gmail, Week in Hand handles these kinds of data differently.

We store your name and email address (from sign-in) to maintain your account.

We keep the summaries we build — and enough of the source email and documents to show you what we read and where each item came from — only as long as needed to provide the features you have turned on. We never copy or sync your mailbox, and we use what we keep for no other purpose. Where we send your summary to you by email, your copy is delivered to you and stays where we sent it. What an AI processing provider may retain for its own limited period is described in Section 2.

4. Who we share it with

We share data only with the service providers ("sub-processors") that operate Week in Hand on our behalf, each limited to the function it performs. We list them by function; the provider named in each row is the one we use today, and we keep this list current if a provider changes.

Function Provider we use today What it receives
Authentication and token custody Clerk Your identity, your Google OAuth tokens, and your Week in Hand settings
AI processing Anthropic (Claude) The email content and linked-document text we send to build your summary
Application hosting and compute Render Email content and the summaries we build, during processing and for as long as we hold them for you
Email delivery Postmark The name, email address, and optional school you submit through our website (Section 13). Where we send you a summary or a notice by email, this provider also carries your email address and the content of that message in order to deliver it.
Error monitoring Sentry Technical error reports only. Before a report leaves our servers we strip it to the error type, the code location, and a fixed set of technical diagnostics, so it carries no message content, subjects, senders, or your identity.

We do not:

5. Limited Use (Google API Services)

Week in Hand's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, that means we use Google user data only to provide and improve the features described in Section 2 — your summaries, the notices and views that go with them, and the sender suggestions that keep them accurate — we transfer it only to the providers listed above and only to deliver those features, and we do not sell it, use it for ads or credit decisions, or use it to train generalized AI models.

6. Human access to your data

We do not allow our staff to read your Gmail content, except:

7. Data retention and deletion

On our own systems, we keep what we build for you — and enough of the source email and documents to show you what we read (see Section 3) — only as long as the features you have turned on require, and you can ask us to delete it at any time; where we have sent a summary to you, that copy is yours and remains wherever we delivered it, and you can delete it there. Your account identity, OAuth tokens, and settings are held on your behalf by our authentication provider. Disconnecting Gmail revokes our access immediately (see Section 8), and you can ask us to delete your account at any time using the contact details in Section 14.

At our providers, content we sent for AI processing may persist for a limited period on that provider's own retention schedule, and flagged content may persist longer — see Section 2. Where we send you a summary or a notice by email, the provider that delivers it likewise holds the content of that message for a limited period on its own retention schedule, in order to deliver it and to keep a record of delivery.

8. Disconnecting and revoking access

You can revoke Week in Hand's access to your Gmail at any time, by either route:

After you disconnect, we can no longer read your mailbox unless you reconnect.

9. Security

We protect your data with encryption in transit, restricted access, and the security practices of our sub-processors. OAuth tokens are held by our authentication provider rather than on our own servers, and our logs never contain email content (Section 3).

10. Children's privacy

Week in Hand is intended for parents and guardians (adults). It is not directed to children, and we do not knowingly allow children under 13 to create accounts. We recognize that the email we summarize is about children (school communications).

11. Data breach

If we become aware of a data breach affecting your personal data, we will notify affected users and any authorities as required by applicable law, without undue delay.

12. Changes to this policy

We may update this policy. If a change materially affects how we handle your email, we will tell you — by email or in the app — and the effective date above will always reflect the current version.

13. Information you provide directly (waitlist)

If you request an invite through our website, we collect the information you submit — your name, email address, and, optionally, your school. We use it only to contact you about access to Week in Hand. This information is delivered to our own email inbox through our email-delivery provider (Section 4) and retained in that inbox. We do not sell it, use it for advertising, or share it with third parties for their own purposes. You can ask us to delete it at any time using the contact details below.

14. Contact us

Week in Hand is operated by SparkForge, LLC. If you have questions about this policy or your data, or want to exercise any of the choices described above, contact us at privacy@weekinhand.com.