Privacy

Last updated 24 September 2026

ForwardThis reads emails you send it and acts on them in other services on your behalf. That means it handles your email content, and this page says exactly what happens to it.

Who we are

ForwardThis is operated by Back of House Systems Ltd, a company registered in the United Kingdom. For UK GDPR and EU GDPR we are the data controller for your account, and a data processor for the message content you send us to act on. Contact: privacy@forwardthis.io.

What we collect

  • Account details. Your email address, your name if your sign-in provider gives us one, and the addresses you verify as allowed to send commands.
  • Demo use. If you try the demo on our homepage, we record the address you emailed it from, when you used it, which kinds of app the suggestions involved, and - for the result page only, deleted within 24 hours - the subject line. Never the body of the email itself. After the demo we may send occasional product emails. Every one carries an unsubscribe link, and you can decline them on the demo itself.
  • Product emails. Once you have an account we send occasional emails about using ForwardThis, such as help getting set up or a warning before you run out of actions. Every one carries an unsubscribe link. Unsubscribing does not stop the emails that are part of the service: sign-in codes, replies about your own requests and billing receipts.
  • Messages you send us. The full raw email, including attachments, for as long as it takes to do the work - see retention below.
  • A record of what was done. The action taken, which app, links to what was created or changed, and where each value came from. The subject line of your message, encrypted.
  • Preferences we infer. Structured defaults only, such as “invoices go in this folder”. Never message text.
  • Connection records. Which apps you connected and what permissions were granted. Not the credentials themselves.
  • Security and audit events. Sign-ins, connections, pauses, and changes to billing.

Analytics cookies are set only if you accept them in the cookie banner, and our emails contain no tracking pixels or external images. If you accept, Google Analytics and DataFast set cookies that help us understand how people find and use the site. If you decline, or never answer, no analytics cookies are set at all: Google Analytics runs in its cookieless mode and receives only anonymous page views, and DataFast does not load. You can change your choice at any time with the Cookie choices link in the footer. Independently of that choice, our public pages use Cloudflare Web Analytics, which sets no cookies and does not fingerprint you, and one advertising attribution pixel - Fastlane's, for our social posts - which sets no cookies but does store an identifier in your browser so we can tell which posts brought people here. All of these run on the public site only.

When you create an account or try the demo, we record which of our pages you did it from, so we can tell which pages are useful. If you accepted analytics cookies, we also record the first page of your visit and the site or search engine that sent you there. That is kept in a first-party cookie for up to 30 days, and deleted if you later decline. We store it with your account or, if you only tried the demo, with the address you sent it from. It is never stored with the content of your email.

The signed-in app carries no analytics of any kind. No page tracking, no product analytics, and no session recording - nothing watches you use it. That is a deliberate limit rather than an oversight: a recording of the app would capture the contents of your work, and we would rather not be able to see it than promise not to look.

How long we keep it

  • Raw email and attachments: 24 hours after the work succeeds. Up to 72 hours if it failed, so it can be retried or diagnosed. If a request is waiting on you - an approval or a question - the original is kept until you answer, and never more than 7 days. Then deleted. While it exists, you can read it back from the request's page; after that, you can't, and neither can we.
  • Undo snapshots: 24 hours, encrypted, deleted when Undo expires or is used.
  • Activity records: 90 days. These hold action details, an encrypted subject line, and the text of replies you send us in the course of a request (an answer to a question, a correction) - never the body of an email you forwarded, and never a copy of an attachment.
  • Preferences and standing rules: until you delete them.
  • Demo contact details: the address you tried the demo from is kept so we can honour your follow-up choice, and deleted on request.
  • Account and security records: while your account exists, and briefly after, where we need them for security or legal reasons.

Deletion is enforced by a scheduled job, not by a policy someone has to remember.

Who else processes it

These providers handle data on our behalf. We do not sell data to anyone. A few of them exist for advertising attribution, and what they receive is limited to the fact of a visit - never your email, your instructions or anything from the app.

  • Cloudflare - hosting, database, file storage, email delivery and cookieless web analytics. Processes everything.
  • OpenRouter - routes requests to the AI models that read your instruction and work out what you meant. Production traffic uses a reviewed list of models with zero-data-retention terms where the provider offers them.
  • Pipedream - holds the authorisation for the apps you connect, and makes the calls to them. Your app credentials live there, not with us.
  • Polar - payments. Polar is the merchant of record and handles card details and tax. We never see a card number.
  • Loops - product emails to account holders and to people who tried the demo. Receives your email address, your plan and how many actions you have used, and for the demo, the apps and suggestions it showed you.
  • Google - web analytics on the public site. Cookieless unless you accept analytics cookies in the banner, and it never runs on the signed-in app.
  • DataFast - web analytics on the public site. Loads only if you accept analytics cookies in the banner, and never runs on the signed-in app.
  • Fastlane - attribution for our social media posts, via a pixel on the public site that records page visits and which post they followed. Never on the signed-in app, and never anything you send us.

Some of these operate outside the UK and EEA. Transfers rely on the providers' standard contractual clauses.

AI processing

Your instruction and the relevant parts of the message are sent to a language model to work out which action you want. The model proposes; it never decides what is safe. Whether something needs your confirmation is decided by our own code from the type of action, and a model output cannot lower that.

Content inside a forwarded email is treated as data and never as an instruction, which is a security property as much as a privacy one.

Your rights

You can ask for a copy of your data, ask us to correct or delete it, object to processing, or ask for it in a portable form. Much of this you can do yourself: Memory lists everything we have inferred and lets you delete it, Connectors lets you disconnect an app, and Settings lets you pause all processing or delete your account outright - billing is cancelled and everything is removed immediately.

Email privacy@forwardthis.io for anything else. We respond within 30 days. If you are unhappy with the response you can complain to the UK Information Commissioner's Office at ico.org.uk.

Security

Message subjects and undo snapshots are encrypted with keys we hold separately from the database. Links in our emails are single-use, expire, and cannot do anything by being loaded - only by being clicked deliberately, which is why an email scanner opening one is harmless.

Changes

If this policy changes in a way that affects what we do with your data, we will email you before it takes effect.