Security
What Pactly can access, what it keeps, how it's protected, and how you take it all back. Every claim below describes the implementation as it exists today — nothing aspirational.
Permissions requested
Pactly connects to Google with OAuth 2.0 (PKCE). It requests exactly these scopes — nothing more:
| Scope | Why Pactly needs it |
|---|---|
openid · email · profile | Sign you in and identify your account. |
gmail.modify | Read threads to find commitments; apply Pactly/Action / Pactly/Waiting labels during sync (you can turn this off); archive threads only when you tap Archive. |
gmail.send | Create drafts and send email — only when you explicitly confirm, or at a time you explicitly schedule. Pactly never sends on its own initiative, except through follow-up rules you personally create and enable. |
calendar.readonly | Read-only access to calendar events for deadlines and meeting prep. Pactly cannot create, modify, or delete calendar events. |
Data retention — what's kept, what isn't
Kept: commitment metadata extracted from your mail — loop titles, contacts, categories, due dates, and short evidence excerpts (the first sentence of the relevant passage, capped at ~220 characters). Calendar event titles, times, and attendees for meeting prep. Your notes, templates, rules, and settings.
Not kept: full email bodies. Message text is processed in memory during a sync to extract commitments, then discarded — it is never written to the database. Pactly does not store your inbox.
Not sent anywhere: by default, commitment extraction runs on Pactly's own servers with a local heuristic engine. Email content is not sent to any third-party AI service.
Encryption
- At rest: Google OAuth tokens are encrypted with AES-256-GCM (unique 96-bit IV per value) before storage. The database never holds plaintext credentials.
- In transit: all connections to Pactly use HTTPS (TLS). Google API calls use TLS.
- Isolation: every database query is scoped to your user id — one account can never read another's data.
Deletion
Delete your account (Settings → Delete account): Pactly first revokes its Google grant server-side, then deletes your user record — all loops, events, notes, briefings, rules, and settings are removed via cascading deletes. Your session is ended immediately.
Unlink one Google account (Settings → Email accounts → Remove): deletes that account's tokens, loops, events, and sync history. Your other linked accounts are untouched. (The last linked account can't be removed — connect another first.)
Download your data (Settings → Download my data): a JSON export of everything Pactly stored about you. It never includes OAuth tokens or encryption secrets.
Revocation — disconnect Google access
Three ways, fastest first:
- In Pactly: delete your account (revokes every linked Google grant, then erases your data) or unlink an individual account.
- In your Google Account: myaccount.google.com/permissions → remove Pactly. This ends Pactly's access immediately, independent of anything in the app.
- Expired grants: if Google reports a grant as dead, Pactly flags the account, pauses its syncing, and shows a persistent Reconnect banner — it never keeps retrying a dead token.
What we don't claim
Pactly has not undergone a third-party security audit or penetration test, and holds no compliance certifications (SOC 2, ISO 27001). Token encryption keys are currently held as environment secrets on the application host; moving key management to a dedicated KMS is on the roadmap. This page will be updated if that changes.