birdmouth
Privacy Policy
Effective July 15, 2026
birdmouth is purchasing software for residential builders, operated by Birdmouth LLC (“birdmouth,” “we,” “us,” or “our”). Suppliers email quotes, orders, invoices, and delivery updates to your birdmouth address (or you connect an inbox you control), and birdmouth organizes them by project so your team can review what matters. This policy explains what information birdmouth collects, how it is used, stored, and shared, and the choices you have — including exactly how we handle data from your Google account if you connect Gmail.
Who and what this policy covers
This policy covers birdmouth’s websites, applications, inbound email addresses, integrations, AI-assisted features, and related services (together, the Service). It applies to information about the people who interact with the Service: visitors to our sites, the companies and people who create accounts (each a Customer), the people a Customer allows into its account (Authorized Users), supplier representatives and other people whose information appears in the emails and documents a Customer brings into birdmouth, people who contact us for support, and recipients of messages sent or forwarded through the Service.
A few terms used throughout: Customer Contentmeans the emails, documents, attachments, project and supplier records, purchasing records, messages, and other content submitted to or processed through a Customer’s account. Google User Data means information birdmouth receives from Google APIs, including Gmail data, if you choose to connect a Google account.
For Customer Content, birdmouth processes information on the Customer’s instructions — the point of the product is to store and organize what you send in. For account administration, security, billing, legal compliance, and operating the Service, birdmouth determines its own limited purposes, described below. If you use birdmouth through your employer’s account, your company controls that account and its Customer Content.
Information we collect
Account and profile information.Your name, email address, role, trade, and ZIP code if you provide them; your company’s name; and team information such as who belongs to the company account and their roles and permissions. Sign-in is by one-time email code; birdmouth never sees or stores a password.
Purchasing emails and documents.Emails (including sender, recipients, subject, body, and message metadata) and attachments sent, CC’d, or forwarded to your birdmouth inbound address, and — if you connect Gmail — supplier emails imported from your inbox as described below. This is the product: birdmouth stores these so it can organize them for you.
Information extracted from documents.Details birdmouth’s software reads out of your documents to organize them — for example document type, supplier, project, amounts, dates, and line items — along with your corrections, confirmations, statuses, and the relationships among your projects, suppliers, quotes, orders, invoices, and delivery updates. Extracted data is stored alongside, never instead of, the original file.
Integration settings. If you connect Gmail: the connected address, OAuth tokens (encrypted at rest), your import settings such as selected senders, domains, labels, and date ranges, and import history.
Billing and subscription information. If and when birdmouth offers paid plans, we will collect plan and billing records. Full payment-card details would be handled by a payment processor, not stored by birdmouth; we will update this policy before introducing payments.
Support communications and feedback. Messages you send us and any feedback you choose to share.
Technical and usage data.Device, browser, IP address, access times, pages and features used, error records, security events, and diagnostic logs needed to run and secure the Service. birdmouth uses cookies and similar technologies for sign-in and abuse prevention (including Cloudflare’s bot check on the login screen). birdmouth does not use advertising trackers or session-replay tools and does not sell data; if we introduce product analytics, we will update this policy first.
How we use information
We use the information above to:
- provide and administer accounts, teams, and permissions;
- receive, import, organize, classify, extract, match, search, display, and — at your direction — forward Customer Content;
- connect records to projects, suppliers, requests, quotes, orders, invoices, and delivery updates, and show your team what needs review;
- provide AI-assisted suggestions and record your corrections;
- authenticate users and enforce access controls;
- handle billing and subscription administration, if you are on a paid plan;
- respond to support requests and send service communications;
- protect the Service: security, abuse prevention, debugging, reliability, and incident response;
- comply with legal obligations and enforce our agreements; and
- improve the Service’s user-facing functionality using appropriately limited operational and usage information, and create aggregated or deidentified information that does not identify a customer or person.
Google User Data is subject to the stricter limits in the next section, which control if anything here appears broader.
Google user data (Gmail import)
Connecting Gmail is optional. If you connect a Google account, birdmouth requests read-only permission to access messages in that account (the gmail.readonly scope) plus your email address to label the connection. Although this permission technically allows broad read access to the mailbox, birdmouth uses it only in the two narrow ways described below, and it cannot be used to send, modify, or delete anything in your mailbox.
What we actually access. First, to suggest suppliers, birdmouth examines sender and message-header information only — it does not retrieve message bodies for this step. Second, when you select import criteria (supplier senders or domains, optionally narrowed to a Gmail label and a date range), birdmouth retrieves and imports the messages and attachments matching those criteria. Message bodies and attachments that do not match your import criteria are not intentionally retrieved or stored by birdmouth.
How we use it, including AI processing.Imported messages and attachments are treated exactly like email sent to your birdmouth address: stored for your company, classified (quote, order, invoice, delivery update), key fields extracted, and organized by project and supplier for your team to review. When an imported message or attachment is processed by birdmouth’s AI features, the relevant content is transmitted to birdmouth’s AI service provider (currently Anthropic) solely for document classification, extraction, matching, and related user-facing functionality, as described in “How birdmouth uses AI” below. Any provider receiving Google User Data may use it only to provide or secure this disclosed functionality.
How we store and protect it. Imported data is stored in access-controlled databases and private file storage, isolated per company. The Google sign-in tokens that authorize the connection are encrypted at rest (AES-256) and are never exposed to your browser or other users.
What we never do with Google User Data. We do not sell it. We do not use it for advertising. We do not use it, and do not permit our service providers to use it, to develop, improve, or train generalized artificial-intelligence or machine-learning models. Humans at birdmouth do not read it except with your permission (for example, a support request), when necessary for security or abuse investigation, or where required by law.
Reviewed imports.If you opt in to a reviewed import — an optional step offered when you connect Gmail — members of the birdmouth team read the imported documents and birdmouth’s interpretation of them to check and correct how each one was read, organized, and filed before it reaches your workspace, and to improve the accuracy of how birdmouth reads your suppliers’ documents going forward. This review happens only for imports where you chose it, and is always described at the point where you make that choice.
Disconnecting.You can disconnect Gmail at any time in birdmouth’s settings. Disconnecting deletes the stored tokens from our systems and, when no other birdmouth workspace remains connected to the same Google account, also asks Google to revoke birdmouth’s access. You can also revoke access yourself from your Google account permissions. Messages and documents already imported stay in your birdmouth account — where they are governed by this policy like any other Customer Content — until you delete them or your account.
Material changes. If we ever materially change how birdmouth uses Google User Data, we will tell you and obtain your renewed consent before the new use begins — we will not rely on continued use alone.
birdmouth’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How birdmouth uses AI
birdmouth uses AI service providers (currently Anthropic’s Claude) to classify your purchasing documents and extract fields like totals, dates, and project references. Content is transmitted to the provider solely to provide these features for your account. birdmouth does not permit its AI service providers to use Customer Content to train generalized AI models, except where a customer knowingly and expressly opts into a separate feature that clearly discloses such use — no such feature exists today. AI results are always shown to you for review and correction, and birdmouth records whether each value came from AI or from a person. If we change AI providers, the same limits will apply to the replacement.
Service providers
We use service providers to host, secure, support, and operate the Service on our behalf. Current material providers:
- Supabase — database, authentication, and file storage
- Vercel — application hosting
- Postmark — receiving your inbound email address and sending birdmouth email
- Anthropic — AI document classification and extraction
- Cloudflare — DNS, network security, and bot protection on sign-in
- Google — Gmail API, only if you connect Gmail
Each provider processes data only to provide its service to us. We may add or replace providers (for example, a payment processor if we introduce paid plans, or error monitoring) as the Service develops, and will hold any replacement to equivalent contractual and privacy obligations and keep this list current. birdmouth does not sell your data or share it with advertisers or data brokers.
How information is shared
Within your company.Your company’s data is visible to members of your company account according to their access. Company owners and administrators can manage the account: they may invite or remove users, see company content and activity, control integrations and import settings, and request export or deletion of company data. If you join a company’s account, the company — not birdmouth — decides who administers it.
Recipients you choose.If you forward or send content through birdmouth (for example, forwarding a supplier message to your team’s email), that content goes to the recipient you chose.
Otherwise.Beyond the service providers above, we disclose information only: to professional advisers bound by confidentiality; when reasonably necessary to comply with law, legal process, or a governmental request, or to protect the rights, safety, or security of birdmouth, our customers, or others; or to a successor in a merger, acquisition, financing, reorganization, or sale of assets, subject to this policy and any required notice or consent. Transfers of Google User Data are further limited to providing or securing the functionality disclosed above, complying with law, or other uses permitted by Google’s policy and authorized by you.
Where data is processed
birdmouth primarily hosts and processes data in the United States. Our service providers may process data in other jurisdictions as part of operating their global infrastructure. Wherever data is processed, this policy applies.
Security
We maintain administrative, technical, and organizational safeguards appropriate to the data we handle. Data is encrypted in transit (TLS) and stored in access-controlled systems with per-company isolation enforced at the database level. OAuth tokens are additionally encrypted at rest. Files live in private storage and are served only through short-lived, authenticated links. No system is perfectly secure, but security is reviewed regularly and issues are addressed promptly. If a security incident affects your information in a way that requires notice, we will notify affected customers or individuals as required by applicable law.
Retention and deletion
birdmouth keeps Customer Content for as long as your account is active, so your purchasing history stays organized and searchable. Other categories are kept only as long as they are needed: authentication and security logs for a limited operational period; support communications for as long as useful to help you; billing and tax records for as long as the law requires; and OAuth tokens only while the connection is active — disconnecting Gmail deletes the stored tokens right away.
To delete specific documents or your entire account and its data, contact us at support@birdmouth.io. We begin processing verified deletion requests promptly and ordinarily remove active copies within 30 days. Limited copies may remain temporarily in encrypted backups, security logs, or service-provider systems until their normal retention periods expire, or longer where retention is required for legal compliance, fraud prevention, dispute resolution, or security. Deidentified or aggregated information that no longer identifies you or your company may be retained.
Your rights and choices
You can access and correct your account information in the app, control your company’s integrations, and disconnect Gmail at any time. Depending on where you live, you may have legal rights to request access to, correction, deletion, portability, or restriction of your personal information. Send requests to support@birdmouth.io; we will verify the request (usually by confirming control of the account email), honor it as applicable law requires, and we accept requests from authorized agents where the law provides for them. We honor reasonable requests regardless of where you are. If your information is in another company’s account as part of their Customer Content, we may refer the request to that company, which controls the account.
Children
birdmouth is business software for construction professionals. It is not directed to children, we do not knowingly collect personal information from children, and our Terms of Service require users to be adults.
Changes to this policy
If this policy changes, the updated version will be posted here with a new effective date, and material changes will be announced to account owners by email. Material changes to how we use Google User Data additionally require your renewed consent, as described above.
Contact
Privacy questions, requests, and general support: support@birdmouth.io.
See also: Terms of Service