What we keep, and for how long.
This page describes what FridayFolder actually does with your family’s mail. It is written in plain English rather than legal English, and everything on it is checkable against the product — where a claim has a number in it, that number comes from the code that enforces it.
Last updated August 24, 2026 · questions to support@fridayfolder.ai
“We can’t read what you don’t send us.”
FridayFolder never asks for your inbox password or a scan-everything permission. You forward what belongs; we process it, deliver it, and delete it. Your inbox stays the archive — we keep only the family tracker. No training on your family’s data. One-click deletion, always.
How your mail reaches us
Your household gets its own address — something like yourname@in.fridayfolder.ai. Mail arrives only because you forwarded it, or set your mail provider to forward it, or replied to a briefing. There is no OAuth connection to Gmail or Outlook, no mailbox access, and no password. If you stop forwarding, we stop receiving. Nothing else in your inbox is visible to us at any point.
What we store, and how long
Two different things are kept for two very different lengths of time, and the distinction is the important part of this page.
The email itself — deleted within a day
| What | How long we keep it |
|---|---|
| Attachments | Never written down at all. A spreadsheet, a form, a scanned letter is received straight out of the arriving message and dropped when the reading finishes; only the filename, its type and its size are kept, so we have a record of what we saw and not a copy of it. Two kinds are held a little longer, because a briefing carries them back to you. Both are in the next two rows, and there is nothing else. |
| Photographs | If a nursery or a teacher sends a picture, we keep it until the end of the day your briefing carries it, so you can look at it again in the app, then delete it overnight — never more than three days whether a briefing was sent or not. After that the only copy is the one in your own inbox. The video itself is never stored: a briefing links to it where it already lives. If the nursery offers a still frame from that video, we hold that one picture on exactly the terms above and no others. |
| PDFs we found something in | Same bargain as a photograph, and for the same reason: a school newsletter often is the attachment, and reading it to you is only half the job. When a PDF turns out to matter, we hold it until it has gone out attached to your next briefing, then delete it — again at most a day, and never more than three days. A PDF we read and found nothing in is deleted right away, like every other attachment. |
| Email body | Erased 24 hours after processing. If something fails to process, it is erased after 7 days whether we managed to read it or not. |
| Sender, subject, date | Kept, so a commitment can point back to where it came from and so the same email forwarded twice is not read twice. |
The clean-up runs automatically after every briefing we send — it is not a monthly job or a promise to get around to it.
The tracker — kept until you delete it
What survives is the useful part: the commitments themselves. A form due Friday, a swim meet on Saturday, the name of the organization that sent it. Your children’s names and any nicknames the school uses, so mail can be attributed to the right child. Your household’s schedule and the addresses briefings go to. That is the tracker, and it stays until you remove it.
What you did, and when — kept with the tracker
Tapping Did it, Snooze or Hide is recorded: which item, which parent, what time. That is not us watching — it is how the item changes for your household, and how the other parent finds out you already handled it. Telling them is the product. The same record is what lets a briefing say “Jolanta signed off the allergy form at 6:02 this morning.”
It is a record of actions, not of reading. We do not know which parts of a briefing you looked at, how long you spent, or what you decided not to do. And it lives with your tracker: delete the household and it goes with everything else.
Counts about your household — kept, and detached when you leave
Once a day we write down a row of numbers about the day before: how much mail arrived, how many things were extracted, how many briefings went out and how large they were, how many actions were taken, and what the AI cost us to run. Numbers only — no subjects, no titles, no names, no sentences. It exists so we can see what the product costs and whether it is working without re-reading anybody’s mail, and so those figures survive the email being deleted a day later.
This row outlives the mail it was computed from. That is the one place where measuring something means keeping something after the thing itself is gone, and we would rather say so than have you find out from a policy update. What is in it could not identify you if it were printed in a newspaper: dates and counts.
Where you are — five digits, and only if you give them
The one piece of location this product asks for is a ZIP code, and it is optional. It is what puts the afternoon forecast in your briefing — the four-to-seven window, when practice happens. Five digits name a few square miles; we do not ask for a street, a house number or your device’s location, and there is nowhere to enter one.
From the ZIP we work out a single point on the map, once, and keep it beside the code so we are not looking it up every morning. The forecast itself is cached for two days and then deleted — yesterday’s weather is not weather. Clearing the ZIP in Settings removes the point and stops the forecast; nothing else changes.
Deleting things
Three levels, all in Settings, all immediate:
- Delete stored email content — erases every email body, attachment, photograph and held PDF we still have, now rather than waiting on the timer. Your tracker is untouched.
- Delete history — removes every commitment, every briefing we have sent, and every message record. The household and its settings remain, so you can start again from empty.
- Delete account — removes the household and everything attached to it, and removes your login. There is no recovery, which is the point.
The one thing that stays, and why
Deleting your account removes your mail, your tracker, your children’s names, your schedule, your ZIP, your actions and your login. Seventeen tables’ worth, all at once, with no undo.
What remains is the row of daily numbers described above, and a single line recording that a household existed, when it started, and when it ended. Both are detached from you at the moment you delete. They carry a random identifier that was generated for that purpose and has no relationship to your name, your address or your account — and the only record connecting that identifier to you was on the row we just deleted. It cannot be reconstructed, by us or by anyone, because there is nothing left to reconstruct it from.
The honest reason: if the numbers left with the households that leave, we would only ever be able to study the families who stayed — and the families who leave are the ones we most need to learn from. A product that can only see its happy users does not get better for anybody else. What survives is arithmetic about nobody.
If you would rather nothing at all remained, write to support@fridayfolder.ai before you delete and we will remove those rows too. We cannot do it afterward, for the same reason nobody else can.
Who else is involved
FridayFolder is a small operation and does not run its own datacentres. Six companies process data on our behalf, and the last two receive nothing about your family at all:
| Who | What they handle |
|---|---|
| Supabase | The database and your sign-in. Hosted in the United States. |
| Vercel | Runs the website and the code that reads mail. |
| Postmark | Receives forwarded mail and delivers briefings. |
| Anthropic | Reads a school email and turns it into commitments. |
| Zippopotam | Turns a ZIP code into a point on the map. Sees five digits, once, and nothing else — not your name, not your email, not that a family is involved. |
| Open-Meteo | The forecast. Sees a latitude and a longitude, hourly, and nothing else. Neither of these two is told who is asking. |
We do not sell your data, and we do not share it with anyone beyond these six.
Model training
Your family’s mail is not used to train any AI model. Reading happens through Anthropic’s commercial API, whose policy is that “by default, we will not use your inputs or outputs from our commercial products to train our models.” The exceptions in that policy are submitting feedback and explicitly opting in — FridayFolder does neither, and has no setting that would enable either.
Email we send you
Briefings carry no tracking pixels and no rewritten links. There is no invisible image that reports when a message was opened, and no link in a briefing is redirected through a tracking service that logs it on the way past. Our mail provider records whether delivery succeeded, because a briefing that silently bounces is worse than one that doesn’t arrive at all.
Two things in a briefing do reach us, and both are things you press on purpose:
- The buttons. Tapping Did it, Snooze or Hide is how the item changes for your household — that is the button working, not a record of it being watched. We keep who pressed it and when, because telling the other parent is the point.
- “Add FridayFolder to your contacts.” That link passes through our own server, which notes that it was tapped and by which of you, and then hands you the contact card. We keep the fact of the tap and nothing about your device. It is there so we can tell whether offering it is worth doing at all.
“Add to calendar” changed in September 2026, and this paragraph changed with it. Those links used to go straight from your mail app to Google or Microsoft. They now pass through our own server first, which sends you on to exactly the same place.
We did that because they were broken on phones. Gmail on a phone does not open a Google link in a browser — it hands it to the Google Calendar app, which refused it and said no calendar was available. A link to our address has no app to be handed to, so your phone opens a browser, and the browser goes on to Google or Microsoft the way your computer always did.
We record nothing when you use one. Not that it was tapped, not when, not by which of you, and nothing about your device. The address is rebuilt from what the button already carried and you are redirected, and that is the whole of it. This is the one link in a briefing that touches our server and leaves no trace, and it is deliberate: the contact card above is counted because we needed to know whether it was worth offering, and a calendar button is not a question we have.
The website
fridayfolder.ai counts visits using cookie-free analytics — which is why this site has never asked you to accept anything. What is recorded is which page was viewed, roughly where in the world from, and which kind of device: counts, not people. No cookie is set, no profile is built, nothing follows you to another site, and nothing is shared with an advertiser.
Inside the app we count which tab was opened and which setup step was reached, so we can see where people get stuck. Those counts never carry a name, an email address, a school, a child, or anything from your tracker. And there is no session recording and no heatmap — the app shows your children’s schedules, and there is no version of a replay of that screen we would want to explain to you.
Nothing that identifies a household ever appears in a web address, which is what a visit-counter can see. That is a rule we hold ourselves to rather than a happy accident, and it is why the counting can be as dull as it is.
The short version, if you read nothing else
There are three different things here and they are worth keeping apart:
- Content — what the school actually wrote, what your children are called, what is on your list. Read, used, and deleted on the schedule above. Never sent to any third party for measurement, and never in any count.
- Actions — which parent pressed which button, and when. Kept with your tracker because telling the other parent is the whole product, and deleted with it.
- Counts — how much, how many, how big, how much it cost. Dates and numbers. Kept, and detached from you if you leave.
Anything that leaves our own systems is in the third category and nothing else.
Children
FridayFolder is for parents, not children. We store a child’s first name, any alternate name their school uses, and optionally their grade, teacher and classroom — because attributing mail to the right child is most of the job. That information comes from you, not from the child, and it is removed with the household.
Both parents
A household is shared by design: both parents see the same tracker and the same briefings. Anyone with a seat can add or remove a recipient and can delete the household’s data. If that is not the arrangement you want, use separate households.
This is a private beta. The product is changing weekly and this page changes with it. If something here stops matching what FridayFolder does, that is a bug — write to support@fridayfolder.ai and we will fix the product or the page, whichever is wrong.
Getting in touch
Ask for a copy of what we hold, ask us to correct it, or ask us to delete it, at support@fridayfolder.ai. It is answered by a person.