How Cert Surfer handles your data
Plain version, in the order things actually happen.
Version 2026-09-07
01We read the mailbox you connect
We look for messages that appear to be certificate requests. To find and reply to them we need read and write access to your mail, including the ability to label and archive a thread once it is handled.
02We do not keep your email
Message bodies and subjects are not stored on our servers. We keep our reading of a request — the holder, the coverage, the job site — plus the identifiers needed to fetch the conversation again. Opening a thread re-fetches it from your mailbox each time.
03No model sees your email
Email is parsed by a deterministic rules engine that makes no network calls. Your messages are never sent to OpenAI, Anthropic, or any other AI provider.
04Policy documents you upload may be sent to OpenAI
When you upload a declarations page or a prior certificate, we first read it with a local parser. If that leaves required fields blank, the document text is sent to OpenAI to complete the extraction. Nothing else is sent, and this step never runs on email.
05We store what we produce
Your account book, issued certificates, request queue, signature, and usage counts are stored so the product works and so you have a record of what went out in your name.
06Nothing sends without a person
Certificates are drafted for you. A certificate leaves your mailbox when someone at your agency approves it.
07You can revoke at any time
Disconnecting the mailbox, or revoking access in your Google or Microsoft account, immediately ends our ability to read or send. Because we never stored the mail, that also ends our access to its contents.
08You are responsible for what you issue
A certificate of insurance is a legal document. We assemble it from the policy data you give us and the request as written; confirming that it is accurate before it goes out is the agency’s call, not ours.
The access we ask for
- gmail.modify
- Find certificate requests, draft the reply in the same thread, and label a thread once it is handled. Does not permit deleting mail.
- gmail.send
- Send the reply your team approved.
- userinfo.email
- Show you which mailbox is connected.
Microsoft
- Mail.Read
- Find certificate requests.
- Mail.ReadWrite
- Draft the reply and file the thread once handled.
- Mail.Send
- Send the reply your team approved.
- MailboxSettings.Read
- Use your mailbox’s own time zone on the certificate.
- offline_access
- Keep the connection alive so you re-authorise rarely.
We do not request https://mail.google.com/. It differs from the above only by allowing permanent deletion, and nothing here deletes mail.
Turning it off
Disconnect the mailbox in your console, or revoke Cert Surfer at Google account permissions or My Apps. Access ends immediately. Because message contents were never stored, so does our access to them.
Questions: sales@salience.solutions. See also our privacy policy and terms.