BlindSpot logo BlindSpot

Your business stays your business.

BlindSpot looks for the promises you make in your email, a photo or screenshot, or something you type in, so it can remind you before they slip. Here's exactly what that means, no jargon, nothing glossed over.

Your info is protected
We never sell your data
We never send email as you
You're always in control

What that means in plain terms

Read-only

We can't send an email, reply to a customer, or delete anything in your inbox.

Never sold

No ad networks, no data brokers. Nothing about your business is ever sold.

Only what you connect

You choose the inbox, what you send in. Nothing else.

Delete anytime

Disconnect a mailbox or delete your account in one step. No support ticket required.

Want the specifics, like encryption, database isolation, and every vendor involved? Keep reading below.

How we protect your information

In transit: every connection this app makes, to your browser, to your email provider, and to every other service it talks to, runs over HTTPS/TLS. Every time, no exceptions.

At rest: our infrastructure providers encrypt the underlying disks by default, on encrypted cloud infrastructure. Row-level security also means the database itself physically refuses to return another account's rows. That isolation applies independent of encryption.

An extra layer, on top of the above, live today: mailbox connection credentials (OAuth tokens, or an app-specific password for IMAP providers) are encrypted with their own key (AES-256-GCM) before they're ever written to the database. Separately, the commitment text we store, summary, reference excerpt, and any extracted key info, is encrypted at the database layer itself via an insert/update trigger, so it's ciphertext at rest regardless of which part of the app wrote it.

Your data is walled off from everyone else's

This isn't just an app-level check we could get wrong. It's enforced at the database itself via row-level security (RLS). Every account's commitments are tagged with that account's ID, and the database is configured to refuse to return rows that don't belong to whoever's logged in, so a bug in the application code alone can't leak your data to another account. The database is the thing saying no.

Who helps us run BlindSpot

Every company that touches any of your data, and why.
Your email provider
BlindSpot only reads the mail you've authorized from Gmail, Outlook, Yahoo, or iCloud — nothing more.
OpenAI
Briefly reads flagged content, like an email or a photo or screenshot's text, to identify the commitment, then forgets it.
Supabase
Hosts BlindSpot's database and handles sign-in.
OneSignal & Resend
Deliver your push and email reminders. Only ever see a title and status, never your raw email.
Zapier
Runs a few scheduled checks on already-processed reminder data to decide when to alert you.
Your business data is never used to train OpenAI's models.
No ad networks. No data brokers. Nothing is sold, ever.

You're always in control

Disconnect a single mailbox. Remove one connected inbox without touching the rest of your account. BlindSpot stops reading it right away, and commitments already found stay in your list.

Delete your account. One confirmation, and everything is erased: every commitment, every connection, your login. Immediate and permanent, no undo.

Both live in Settings, no support ticket required.

Get started Takes about a minute to connect your inbox.