Privacy

Clear boundaries. Careful protection.

Effective August 26, 2026. This policy explains what Porchlight accesses, why it is needed and how it stays under your family's control.

What Porchlight is

Porchlight is a protective email service for families. A trusted family member (the guardian) reviews incoming email for an elderly relative (the family member) who has chosen to connect their mailbox. Suspicious messages are held out of sight until the guardian approves or blocks them.

The data we access, and why

When a family member connects their mailbox with their explicit consent, using their email provider's official sign-in, Porchlight accesses:

The guardian signs in with their own account solely to identify themselves. Porchlight never accesses the guardian's mailbox.

  • Basic details about each incoming message: who sent it, the subject, the date, a short text preview and the message's standard unsubscribe information. This lets the guardian review what arrived and decide.
  • Mailbox settings needed for protection: on Gmail, one mail filter that routes new mail for review; the ability to move messages by delivering approved mail or removing blocked mail; and, when the guardian asks, the ability to send an unsubscribe request on the family member's behalf.

What we store

Porchlight stores the minimum needed to operate:

We do not store the contents of emails. Message bodies and previews are fetched from the mail provider when the guardian opens the app and are not retained on our servers.

The trusted-sender and blocked-sender lists live inside the family member's own mailbox as ordinary mail filters and labels, not on Porchlight's servers. The same is true of the marker that remembers which messages were already delivered. They remain under the account holder's control at all times.

The one exception is if a family member is disconnected. An encrypted copy of these lists is kept for 30 days so an accidental disconnect can be undone by reconnecting, and then it is deleted automatically.

  • The digital keys that let Porchlight check the mailbox, called tokens. These are stored scrambled, encrypted with AES-256-GCM, so that no one - including us - can read them directly. We never see or store the family member's password.
  • Account identifiers: the guardian's and family member's email addresses and names, used only to show who is connected to whom.

What we never do

  • We never sell, rent or share your data with anyone.
  • We never use mailbox data for advertising, profiling or training AI systems.
  • We never send email from the family member's account except a single unsubscribe request the guardian explicitly triggers.
  • We never write email addresses, names or tokens into our logs.

Retention and deletion

Data is kept only while the protection connection is active. You can cut off Porchlight's access at any time from your email provider's security settings, such as Google Account permissions or Yahoo Account Security. This immediately invalidates the stored keys.

Disconnecting a family member in the app removes Porchlight's mail filters from their mailbox, so their email flows exactly as it did before Porchlight, and deletes the stored keys and account details from our servers. The only thing kept afterward is the encrypted 30-day copy of the sender lists described above, which is deleted automatically.

Revoking access at your email provider stops Porchlight's access instantly but does not remove our stored account details. Use Disconnect in the app for that, or contact us at callyourgrandsonplease@gmail.com.

Provider-specific notes

  • Google/Gmail: Porchlight's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
  • Yahoo, planned: the same practices will apply to mailboxes connected through Yahoo's official sign-in.

Security

Porchlight was built through a formal security-hardening program, and protecting your family's data is the product's entire purpose. Everything is encrypted in transit, sensitive data is encrypted where it is stored and we never write personal information into our system logs.

A technical summary of our security measures is available on request at callyourgrandsonplease@gmail.com.

Changes to this policy

If this policy changes, the effective date above changes with it, and material changes will be communicated to guardians in the app.