Security
How Hedwig protects the mail and calendars you connect. This page describes what the code does today.
Encryption
Google access and refresh tokens are encrypted with AES-256-GCM using a key held only in Hedwig's server environment.
Each token is encrypted with a fresh random 96-bit nonce and carries an authentication tag, so a changed value fails to decrypt. The key can be rotated without signing anyone out.
Tokens live in a table that no user session can read, even as ciphertext. Only Hedwig's server code can read them.
All traffic between your browser, Hedwig, Supabase, and Google uses TLS.
Supabase encrypts the database at rest with AES-256. Message text is protected by that disk encryption and by row-level security rather than encrypted again by Hedwig, so threads open quickly and search can read them.
What is stored
Message metadata, and message text for the last 180 days; calendar events; contacts; Gmail labels and signatures; embeddings of synced messages when semantic search is on; and your settings.
What is never stored
- Your Google password. You sign in on Google's own page, and Hedwig never sees it.
- Card or payment details. Hedwig doesn't take payment.
- Attachment files. Hedwig fetches an attachment from Gmail when you open it and doesn't keep it. Calendar invites are read so they can be shown as an invite.
- The full value of an MCP token. Only its SHA-256 hash is kept.
Retention and deletion
Hedwig keeps the last 180 days of mail from when you connect an account, then new mail as it arrives.
Disconnecting an account deletes its data from the database immediately. Copies in encrypted database backups expire within 7 days. Deleting your Hedwig account does the same for everything.
Who can see your data
Every row Hedwig stores carries the ID of the user it belongs to, and Postgres row-level security checks it on every query, so one person's session can't read another's data.
Mail and calendar data are read-only to your browser. Changes go through Hedwig's server, which makes them in Google first.
Apps you connect through the MCP sign in screen get only the permissions shown there. They can't send mail, and you can disconnect any of them in Settings, MCP.
No person at Hedwig reads your mail unless you ask us to for support, it's needed for security, or the law requires it.
Notifications from Google
Gmail change notices arrive through Google Cloud Pub/Sub. Hedwig accepts one only if it carries an OIDC token signed by Google, issued to Hedwig's own service account, for Hedwig's audience.
Calendar notices must carry the secret channel token Hedwig created for that calendar and its matching resource ID. Anything else is rejected.
A notice only starts a sync. Hedwig then fetches the data from Google itself.
Scheduled jobs must present a secret, which is compared in constant time.
Mail you read and send
Hedwig never adds tracking pixels or rewrites links in mail you send.
Remote images stay blocked until you allow a sender, so senders can't tell when you open their mail.
Dictation
Speech is recognized on your device, and the audio never leaves your browser.
The speech model downloads once from Hugging Face, then your browser keeps it.
When "Clean up dictation" is on, the transcript goes to Anthropic's API with the thread's participant names, email addresses and subject, up to 40 contact names, and your own name. Hedwig doesn't store any of it. Under its API terms, Anthropic doesn't train its models on this data.
Report a vulnerability
Report a vulnerability to edwardhkim2025@gmail.com. We reply within two working days.
Include the steps to reproduce it. Don't access other people's data or degrade the service while testing.
Audits
Hedwig hasn't had a SOC 2 audit or Google's CASA security assessment yet. CASA is part of the Google verification Hedwig needs before it can open to more than 100 people. Until then, this page lists what the code does, so you can judge it yourself.