Emerge

Privacy Policy

Last updated: 2026-09-14

This Privacy Policy describes how Emerge (the "Service") handles information. Unlike Emerge's WordPress plugins and Google Workspace add-on, which run inside your own site or Google account, Emerge is a hosted, multi-tenant application: you create an account, connect one or more email-sending accounts you own, and Emerge stores your contacts, message templates, campaign content, and delivery records on its own servers in order to send and track email on your behalf.

1. Information we collect

Account information

When you sign up, we collect an email address (for a magic-link sign-in) or receive your name and email address from Google or Microsoft if you sign in with one of those providers. We do not receive your password for either provider.

Connected sender credentials

When you connect a sending account (Gmail, Microsoft 365, Amazon SES, SMTP, or an ESP API key), we store the resulting OAuth tokens, API key, or SMTP credentials, encrypted at rest, so the Service can send email through that account on your behalf and check its delivery status.

Contacts and content you provide

Your contact list (email addresses and any profile fields you add or import), tags and segments, message templates, and campaign/automation configuration are stored so the Service can render and send your email. This data belongs to you and is used only to provide the Service to your account.

Delivery and engagement data

For each message we send on your behalf, we record its delivery status and, where tracking is active, whether and when it was opened or a link in it was clicked, including the requesting IP address and user-agent at the time. We also record bounce and spam-complaint feedback reported by your connected sending provider, which we use to automatically stop sending to an address that is no good.

2. Google user data and OAuth scopes

Emerge uses Google Sign-In and Google's Gmail API. The same Google Cloud OAuth client is used for both signing in to Emerge and connecting a Gmail sending account, so it requests the scopes needed for either, depending on which flow you use. The sections below describe each scope, the specific data it grants access to, and exactly how Emerge uses, stores, and shares it. Unlike Emerge's WordPress plugin (a stateless OAuth broker that never stores a token), Emerge stores the resulting tokens itself, encrypted at rest, and calls the Google API directly from its own backend.

openid

Google's description: Associate you with your personal info on Google.

When requested: Both signing in to Emerge and connecting a Gmail sending account.

How we use it: To identify the authenticated Google account — creating or matching it to your Emerge account when signing in, or to the sending account you're connecting. The resulting identifier is stored with your account/sender record; it is not shared with any third party.

https://www.googleapis.com/auth/userinfo.email

Google's description: See your primary Google Account email address.

When requested: Both flows.

How we use it: As your Emerge account's sign-in identity, or to label a connected Gmail sender in the dashboard (for example, "Connected: alice@example.com") and as its default From address. Not shared with any third party.

https://www.googleapis.com/auth/userinfo.profile

Google's description: See your personal info, including any personal info you've made publicly available.

When requested: Signing in to Emerge only.

How we use it: To show your name in the Emerge dashboard. Not shared with any third party.

https://www.googleapis.com/auth/gmail.send

Google's description: Send email on your behalf.

When requested: Connecting a Gmail sending account only.

What it grants: Permission to call the Gmail API's users.messages.send method as the authenticated user. This scope is write-only — it does not allow reading, searching, or modifying existing messages, drafts, labels, threads, or mailbox settings.

How we use it: Emerge's backend calls users.messages.send directly to deliver the campaigns, automations, and transactional messages you compose in the dashboard, through your own connected Gmail account. We never read your mailbox. The resulting access and refresh tokens are stored encrypted at rest in our database (see Security) and used only to send mail you've initiated; they are not shared with any third party. We do not request gmail.readonly, gmail.modify, or any other Gmail scope.

Limited Use compliance

Emerge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

3. Microsoft account data and scopes

Similarly, Emerge uses a single Microsoft Entra ID OAuth client for both signing in and connecting a Microsoft 365/Outlook sending account.

openid, profile, email

When requested: Both flows.

How we use it: To identify the authenticated Microsoft account for sign-in, or to label a connected sender with its display name and email address.

User.Read

When requested: Both flows.

How we use it: To read your basic Microsoft Graph profile (name, email) for the same labeling purpose as above. We do not read any other Microsoft Graph resource.

offline_access

When requested: Connecting a Microsoft sending account only.

How we use it: To obtain a refresh token so Emerge can keep sending on your behalf without asking you to re-authenticate for every message. Stored encrypted at rest, same as a Gmail token.

Mail.Send

When requested: Connecting a Microsoft sending account only.

How we use it: To call Microsoft Graph's sendMail on your behalf, to deliver the campaigns, automations, and transactional messages you compose — the same role as Gmail's gmail.send above. We do not request any Microsoft Graph mail-reading scope.

4. How we use information

We do not sell your data or your contacts' data, and we do not use it to serve advertising.

5. How information is shared

We share information only as needed to provide the Service:

We do not otherwise share your account data, contacts, or content with third parties.

6. Cookies and sessions

The Service uses a session cookie to keep you signed in. We do not use third-party advertising or tracking cookies on the Service's own dashboard. Open/click tracking on the email you send is described in Section 1 above and is separate from cookies on this site.

7. Data retention

We retain your account, contacts, templates, campaign records, and delivery events for as long as your account is active, so you can see your sending history and reporting. If you close your account, we delete or anonymize this data within a reasonable period, except where we're required to retain it (e.g. for legal or security purposes).

8. Your rights

Depending on where you're located, you may have rights to access, correct, export, or delete the personal data we hold about you or your contacts. You can export or delete your contacts directly from the dashboard, or contact us at support@redigit.net for account-level requests, including full account deletion.

If you use Emerge to email your own contacts, you are the data controller for that data, and Emerge acts as a data processor on your instructions — you're responsible for having a lawful basis to hold and email those contacts.

You can revoke Emerge's access to your Google or Microsoft account at any time from Google Account permissions or Microsoft account permissions, in addition to disconnecting the sender from the Emerge dashboard.

9. Security

Sender credentials (OAuth tokens, API keys, SMTP passwords) are encrypted at rest. All traffic to and from the Service travels over encrypted HTTPS/TLS. Access to production systems is limited to authorized personnel for development, support, and security purposes.

10. Children

The Service is intended for business use by adults and is not directed to children under 13.

11. Changes to this policy

We may update this policy from time to time, especially while the Service is in early access and still taking shape. Material changes will be reflected by updating the "Last updated" date above, and where appropriate, by emailing registered accounts.

12. Contact

Questions about this policy, or a data access/export/deletion request, can be sent to support@redigit.net.