← Back to Bear
Privacy Policy
Last Updated: February 3, 2026
This Privacy Policy describes how Bear ("we," "us," or "our"), operated by Bear Labs Inc., collects, uses, stores, and shares information when you use our services at bear.flights (the "Service").
Google Account Data
When you connect your Google account to our Service, we access the following information:
- Email address and basic profile information (name, profile picture) for account identification and authentication
- Gmail message content (limited scope) to provide our core service features
How We Access Gmail Data
We request permission to read a portion of your Gmail messages. This access is used solely to analyze email content and generate insights for you. We do not access your entire mailbox—only the messages necessary to provide the Service.
We use the information we collect to:
- Authenticate your identity and manage your account
- Process and analyze your emails to generate personalized insights
- Improve and develop our Service
- Communicate with you about your account or the Service
Data Storage and Retention
Email Content
- Original email content is not permanently stored. Email data is processed in real-time and cached temporarily during your active session only.
- Once processing is complete, the original email content is discarded from our systems.
Derived Insights
- We store insights, summaries, and other derived data generated from your emails.
- This derived data does not contain the original email content but represents processed information and patterns.
- Derived data is retained until you delete your account.
Account Data
- Your account information (email address, profile data) is retained until you delete your account.
Third-Party Services
AI and Machine Learning Providers
To provide our email analysis features, we share email content with third-party AI/LLM service providers for processing. These providers:
- Process data according to their own privacy policies and data handling practices
- Are contractually obligated to use data only for providing services to us
- Do not retain your data beyond what is necessary for processing
We currently use AI services that may include providers such as Anthropic and OpenAI.
Other Service Providers
We may use additional service providers for:
- Cloud hosting and infrastructure
- Analytics (aggregated, non-personal data only)
Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit (TLS/SSL)
- Secure authentication mechanisms
- Access controls limiting who can access user data
Your Rights and Choices
Access and Deletion
You may:
- Request access to the personal data we hold about you
- Request deletion of your account and associated data
- Revoke Google access at any time through your Google Account permissions
To delete your account or request your data, contact us at privacy@bear.flights.
Revoking Access
You can disconnect your Google account from our Service at any time. When you revoke access:
- We will no longer be able to access your Gmail data
- Previously generated insights will remain until you request deletion
- You can request complete data deletion by contacting us
Data Sharing
We do not sell your personal information. We share data only as described in this policy:
- With AI/LLM providers for email processing (as described above)
- With service providers who assist in operating our Service
- If required by law or to protect our legal rights
Children's Privacy
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date.
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@bear.flights
Google API Services User Data Policy Compliance
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only use Google user data to provide and improve user-facing features
- We do not transfer Google user data to third parties except as necessary to provide the Service, as required by law, or with user consent
- We do not use Google user data for advertising purposes
- A human only reads Google user data if authorized by the user for support purposes, required for security/legal compliance, or the data is aggregated and anonymized