1What Garden is
Garden provides inboxes and a permission layer that let you — and, where you choose to authorise one, an AI agent — act on your communications under a shared, auditable set of rules. Garden is a standalone product. It is not a layer on top of Gmail, Outlook or any other mailbox provider, and it does not ask for access to any existing mailbox you have elsewhere.
The mechanisms this Policy refers to:
- Single-linked inbox. Each inbox you create is bound to a known sender through its Sender Registry — up to three sender addresses today, with more possible in future.
- The garden gate. Every inbound message passes through the gate before it reaches you. The gate checks two things: whether the sender address matches a Sender Registry entry for that inbox, and whether the message passes the SPF, DKIM and DMARC authentication checks reported by our inbound mail provider. It then acts as follows. A message from a registered address is delivered to your inbox — with one exception: if that sender's mail has previously passed authentication and a message from it now fails, the gate treats the message as likely phishing and deletes it immediately. If a registered sender has never passed authentication (some smaller services still run older mail systems), its messages continue to be delivered, because the address you registered is still the legitimate one; for such senders the gate cannot tell a forged message from a real one, and you should register them only if you accept that. A message from an unregistered address at the same domain as a registered sender (for example, a new address at a service you have registered) is quarantined: held out of your inbox and visible in your quarantine view for 14 days. You can read it there, and if you decide it is legitimate your only action is to approve the sender, which adds that address to the inbox's Sender Registry and moves the message into your inbox; otherwise it is deleted automatically when the 14 days end. A message from an address at any other domain is deleted immediately and is never shown to you. A message that our inbound mail provider identifies as spam or malware is deleted immediately.
- Grants and scopes. A grant is the permission you issue to a sponsor to act on an inbox. Its scope is the set of inboxes and actions it covers.
- Sponsor. An AI agent that you connect to your Garden inboxes through Garden's MCP server. Only AI agents can be sponsors; you cannot invite another person to act on your inbox.
- Autonomy levels L1–L4. How much a sponsor may do on its own within a grant, from read-only (L1) to sending to any recipient (L4). The levels are defined in Section 5 of our Terms and Conditions.
- Receipts and the activity ledger. A record of what an authorised sponsor did on your inboxes and of your approvals, rejections and instructions to it. The ledger records agent activity; it is not a log of everything that happens in your account.
2Information we collect
2.1 Information you give us
- Account information: your name, the email address you use to contact us and receive account notices, and your password, which we store only as a salted hash.
- Sender Registry entries: the sender addresses you bind to each inbox.
- Grant configuration: the scopes, autonomy levels and limits you set for your sponsor.
- Billing information, if you subscribe to a paid tier. Payments are taken by Stripe or Razorpay; we receive confirmation of payment, the last four digits of your card and your billing country, never your full card number.
- Messages you send us — support requests, feedback, security reports.
2.2 Information Garden generates or observes
- Message content: the bodies, attachments and drafts of messages delivered to or sent from your Garden inboxes, including content produced by a sponsor acting under a grant. We store this content, encrypted, so that your inboxes work. Our database holds only metadata, limited header information and a reference to the stored message; the message itself is held in encrypted object storage.
- Message metadata and authentication results: headers, sender and recipient addresses, timestamps, routing information, and the SPF, DKIM and DMARC results and spam and malware verdicts reported by our inbound mail provider. The gate uses these to decide whether a message reaches you.
- Gate decision records: for each inbound message, the sender, the authentication result and what the gate did with it. When a message is deleted at the gate or after quarantine, only this metadata remains; the content is gone. We keep these records for 12 months.
- Activity ledger and receipts: grants issued, scopes exercised, actions your sponsor took, your approvals and rejections, and undo events.
- MCP connection data: when your account's MCP token is used, by which agent, and what it did.
- Device and usage data: IP address, browser type and log data generated when you use the Garden web app, browser extension or MCP server.
2.3 What we do not do with your content
Garden's own systems process the envelope and header information of your messages, not their bodies or attachments. Garden does not read, index or analyse the content of your messages, does not use it for advertising or profiling of any kind, and does not use it to train AI models. Two exceptions, so that you have the full picture:
- Our inbound mail provider, Amazon SES, performs automated spam and malware scanning on every message received and returns a message-level verdict together with SPF, DKIM and DMARC authentication results, which Garden records and acts on. This is AWS's provider-level scanning, not a Garden system. It does not guarantee that every attachment is separately scanned or that all malicious content will be detected.
- When you have issued a grant, Garden transmits content within that grant's scope to the sponsor you authorised, on your instruction. What happens to it after that is described in Section 4.
Garden's gate decisions are made on sender address and authentication results, not on message content. Where the gate acts on a spam or malware verdict, it acts on the verdict our provider supplies; Garden does not itself examine the content.
2.4 People who send you mail
Messages arriving in your inboxes contain information about the people and services that sent them — at minimum a sender address and headers, and whatever the sender wrote. We process senders' addresses and headers to run the gate, and we store their messages as your message content, for you. We do not build profiles of senders, contact them, or use their information for any purpose of our own. If you are a sender who wants to know what Garden holds about you, write to privacy@mysecure.garden.
3How and why we use information
The table sets out each purpose, the information involved and the legal basis we rely on.
| What we use information for | Information involved | Legal basis (GDPR / UK GDPR) | Legal basis (India DPDP Act) |
|---|---|---|---|
| Operating your inboxes, Sender Registry and the garden gate, including quarantine and deletion decisions | Account data, Sender Registry, message metadata and authentication results, message content (storage and delivery only) | Performance of our contract with you (Art. 6(1)(b)) | Consent given when you create your account (s.6) |
| Enforcing the grants you configure and transmitting content within scope to your sponsor | Grant configuration, message content within scope, MCP connection data | Performance of contract; your instruction when you issue the grant | Consent, given per grant and withdrawn by revoking it |
| Generating receipts and maintaining your activity ledger | Ledger records | Performance of contract | Consent |
| Providing account access, billing and support | Account data, billing data, support correspondence | Performance of contract; legal obligation for tax records (Art. 6(1)(c)) | Consent; legitimate use for compliance with law (s.7) |
| Keeping the Service secure, preventing abuse and protecting deliverability for all account holders | Device and usage data, logs, gate decision records | Our legitimate interests, and those of other account holders, in a secure service (Art. 6(1)(f)); we have assessed that these do not override your rights | Legitimate use (s.7) |
| Complying with law and responding to lawful requests | Whatever the obligation requires | Legal obligation (Art. 6(1)(c)) | Legitimate use (s.7) |
| Improving the Service | Aggregated or de-identified usage data only — never message content. De-identified means data from which you cannot reasonably be identified; we do not try to re-identify it | Legitimate interests | Legitimate use |
| Telling you about Garden features and changes | Your account email address | Legitimate interests for messages about your account; consent for marketing, which you can withdraw at any time using the link in the message | Consent |
We do not sell personal information and we do not share it for advertising.
4Where your data is stored, and when it leaves that region
Your choice of residency. When you create your account you choose where your data is stored: India or the European Union. Your message content, metadata, activity ledger and account data are stored in an AWS region in the country or union you selected, and nowhere else. We do not move your data to a different region without your consent, except where a legal obligation requires it, and we will tell you before any such move where the law allows.
Access from India. Garden's team operates from India. Where a member of our team needs to access EU-resident data to operate, secure or troubleshoot the Service, that access is made from India under the European Commission's Standard Contractual Clauses, and is limited to specifically approved personnel as described in Section 9.
The AI tier. Garden does not run, select or contract with AI model providers. If you use the AI tier, you connect your own AI agent, running on the model provider of your choice, to your Garden inboxes through Garden's MCP server. When that agent acts under a grant you have issued, Garden transmits the content within the grant's scope to your agent on your instruction; your agent and its model provider then process it under that provider's terms, which you accept directly with them. Because you choose the provider, content your agent retrieves may be processed outside the residency you selected for Garden — including in the United States, China or any other country where your provider operates. You choose the provider; Garden does not control where it processes your content. Garden stores your content, enforces the scope and autonomy level you set, and records every agent action in your activity ledger; it does not read, analyse or generate from your content and does not use it to train any model.
Payments, analytics and the website. Stripe, Razorpay, Pirsch and Vercel (Section 5) operate in their own locations, outside your residency choice. Your message content never passes through them.
5Sub-processors and other recipients
We use the following providers to operate the Service. Each is bound by a data processing agreement.
| Category | Provider | Location | Purpose |
|---|---|---|---|
| Cloud hosting, storage and queues | Amazon Web Services | India or the European Union, per your residency choice | Running the Service; storing your messages and data |
| Inbound mail, spam and malware verdicts, authentication results | Amazon SES | Same region as above | Receiving mail to your inboxes |
| Outbound mail and account email | Amazon SES | Same region as above | Sending mail from your inboxes; sending you account notices |
| Payment processing | Stripe; Razorpay | Per the processor's own terms | Billing for paid tiers |
| Website analytics | Pirsch | Germany | Cookieless, aggregated visit statistics |
| Marketing website hosting | Vercel | Per Vercel's terms | Serving mysecure.garden |
This table is the authoritative list of our sub-processors and we keep it current here in this Policy. We will email account holders at least 30 days before adding a provider that handles message content or account data. Your AI agent and its model provider are not our sub-processors: you choose them and contract with them directly (Section 4).
6How long we keep information
| Information | Kept for | Why |
|---|---|---|
| Message content (bodies, attachments, drafts) | 30 days from receipt, then deleted automatically — unless you preserve a message, in which case until you delete it or close your account | Data minimisation by design |
| Quarantined messages | 14 days, then deleted | Your review window |
| Account data and Sender Registry | While your account is open; account registration information for 180 days after closure | Operating the Service; Indian intermediary rules |
| Activity ledger and receipts | 12 months by default; on paid plans you can configure a longer period | Audit and undo |
| Gate decision records (sender, authentication result, outcome — no content) | 12 months | Security and abuse investigation |
| Security and access logs | 180 days | CERT-In Directions; security investigations |
| Billing records | As long as tax and company law requires (currently up to 8 years in India) | Legal obligation |
| Support correspondence | 24 months after your request is resolved | Service quality; resolving disputes |
| Website analytics | Aggregated only; no personal data retained by Garden | — |
7Your rights
Wherever you live, you can ask us to:
- give you access to the personal data we hold about you, and a copy of your preserved messages and activity ledger in a machine-readable format;
- correct data that is inaccurate;
- delete your data, subject to the legal retention periods in Section 6;
- stop or restrict particular processing, or object to processing based on our legitimate interests;
- withdraw consent — for AI-tier processing, by revoking the grant; for marketing, by using the link in any message.
Write to privacy@mysecure.garden. We will respond within one month; for complex requests we may take up to two further months and will tell you if so. We may ask you to confirm your identity first.
Complaints. You can complain to your local data protection authority — in India, the Data Protection Board of India; in the EU, the authority of the country where you live; in the UK, the Information Commissioner's Office. We would appreciate the chance to resolve your concern first.
If you live in the United States. We do not sell your personal information and do not share it for cross-context behavioural advertising. We honour Global Privacy Control signals where the law gives you an opt-out. The categories of personal information we collect are those in Section 2; we do not collect sensitive personal information other than the content of the messages you choose to receive through Garden. To exercise rights under a US state privacy law, contact privacy@mysecure.garden.
If you live elsewhere. The rights above are available to you, and if your local law gives you further rights we will honour those too. Contact us and we will tell you how.
8Deleting your data and closing your account
You can close your account at any time from account settings. When you do, we delete your messages, Sender Registry, grants and activity ledger within 30 days. We keep only what the law requires us to keep — account registration information for 180 days under Indian intermediary rules, billing records for the period tax and company law requires, and security logs for 180 days — and delete each as soon as its period ends. Before closing your account, you can ask us at privacy@mysecure.garden for a copy of your preserved messages and your activity ledger in a machine-readable format; we will provide it within 30 days.
9Security
We use technical and organisational measures appropriate to the sensitivity of the data we hold. Specifically:
- Messages are stored in a private, encrypted object store (AWS-managed AES-256); queue messages and databases are encrypted at rest with AWS-managed encryption; connections between our services and databases use certificate- and hostname-verified TLS.
- Inbound delivery requires TLS: our inbound mail provider is configured to accept mail only over an encrypted connection, so a sending server that cannot negotiate TLS cannot deliver to a Garden inbox.
- Every message passes the garden gate's sender and authentication checks, and our inbound provider's spam and malware scanning, before it reaches you (Section 1).
Who can see your messages. There is no Garden administration interface or ordinary product route through which staff can read your stored messages. A small number of specifically approved personnel with privileged access to our infrastructure could technically retrieve stored messages, and may do so only where necessary to operate, secure or troubleshoot the Service or to comply with a legal obligation, and every such access is logged. Our infrastructure provider, AWS, could likewise access stored data in principle. Garden is not an end-to-end encrypted email service: it does not offer client-side encryption, OpenPGP or keys that only you hold.
If something goes wrong. If a security incident affects your personal data we will tell you without undue delay, and in any case within the periods the law requires — in the EU, the supervisory authority within 72 hours where required; in India, the Data Protection Board and every affected account holder — by email to your account address and by a notice in the product. No system is completely secure, and we cannot promise that ours is.
10Website visitors and the browser extension
Our website is hosted by Vercel and uses Pirsch for analytics. Pirsch sets no cookies, stores no identifier on your device, and reports only aggregated visit statistics to us. The Garden web app stores a session token in your browser so you stay signed in; it is strictly necessary for the app to work.
11Automated decisions
The garden gate makes automated decisions about whether a message reaches your inbox, based on the rules in Section 1. These decisions do not produce legal or similarly significant effects on you. You can review quarantined messages in your quarantine view and approve a sender from there; messages deleted at the gate are not recoverable.
12Government and legal requests
We disclose personal data to law-enforcement or other authorities only when legally compelled to, after reviewing the request, and we tell you about the request unless the law forbids it or the request concerns an imminent risk to life or safety. We intend to publish an annual count of requests received once we begin receiving them.
13Business transfers
If Garden is involved in a financing, merger, acquisition, reorganisation or sale of assets, your information may be transferred as part of that transaction. We will tell you before your information becomes subject to a different privacy policy, and the recipient will be bound by this one until then.
14Children
Garden is not directed to anyone under 18, and we do not knowingly collect personal data from anyone under 18. If we learn that we have, we will close the account and delete the data.
15Team accounts
Garden is currently offered to individual account holders. When team accounts become available, we will publish a Data Processing Addendum for organisations and update this Policy.
16Who we are and how to reach us
Char Vagh (OPC) Private Limited, CIN: U62099MH2026OPC468326, registered office: 11, First Floor, Kasturba Nagar, Nagpur, Maharashtra, India.
Privacy contact: privacy@mysecure.garden · Legal: legal@mysecure.garden · Security reports: security@mysecure.garden
Grievance Officer (India): Amogh Meshram, Co-founder, at the registered office above; grievance@mysecure.garden. We acknowledge complaints within 24 hours and resolve them within 15 days.
EU representative under GDPR Art. 27: Amogh Meshram, Weinsbergweg 4A, 10119, Berlin, Germany.
17Changes to this Policy
We may update this Policy from time to time. We will email account holders and show a notice in the product at least 30 days before a material change takes effect. The date at the top tells you when the current version took effect.
Write to privacy@mysecure.garden. Our Grievance Officer and EU representative are named in Section 16.