Trust & Sovereignty
Sutradhar reads across your accounts to surface what matters, without ever storing your emails, documents, or calendar events.
Sovereign by architecture, not just by promiseData minimization isn't a policy we wrote. It's how Sutradhar is built.
You grant read-only access, one area of your life at a time (consent-gated). Sutradhar can't send, change, or delete anything.
It reads your accounts where they live. Your content is never copied into our systems.
It extracts only the minimal metadata it needs to reason (never the content) and forms a finding: a heads-up worth your attention, like a renewal, a price increase, or a deadline you might miss.
You get the finding, traceable to the exact source items in your own account. The originals stay put.
Minimal metadata means a subject line, a filename, a date, or an institution name, never the body of a message or the contents of a file.
Once you sign up, these levers are yours; Sutradhar behaves the way you set them.
Connect or disconnect Google or Microsoft accounts anytime (read-only), and choose which life domains (finances, health, work, travel, home, and so on) it attends to. Connecting an account is never blanket permission.
Set its autonomy: let it organize on its own, or have it propose and wait for your OK. Anything that touches the outside world always asks first.
Turn the searchable, pointer-only document index (Vault) on or off, with a separate opt-in for indexing images.
Set the time windows: how far back it reads email, how far ahead it scans your calendar, how much document history to include.
Tell it to leave specific senders or things alone; they're filtered out before it ever reasons over them.
Nothing leaves you by default. You share a document or a plan only through an explicit, revocable grant (Circles).
And you can always pull back: deactivate what it watches, or disconnect an account to stop the flow.
Straight answers about what we do and don't do with your information.
No, never their content. They stay in your Google or Microsoft account. Sutradhar reads them in place and keeps only the minimal metadata needed to form a finding, plus a pointer back to the original.
Only minimal metadata (for example, "a statement dated April from Institution X") is sent to the AI to reason over. The body of an email or the contents of a file are never sent. Our AI provider (Anthropic) does not train its models on data sent through its API.
No. It connects with read-only permissions: it physically cannot send an email, move a file, or alter a calendar. Anything that would touch the outside world routes to you for explicit approval first.
Only four things: your encrypted access tokens; your findings and the minimal metadata behind them; pointers to your source items; and an immutable audit log of every action Sutradhar takes. Your emails, documents, and calendar content are not among them.
On Render (SOC 2 Type 2, ISO 27001), which runs on Amazon Web Services and Google Cloud. Data is encrypted in transit and at rest, and access tokens are additionally encrypted with a key held only by the application. Provider access is least-privilege and audited. Subprocessors: Render, AWS, Google Cloud, Cloudflare, and Anthropic (AI).
Yes. You grant access one domain at a time; connecting an account is not blanket permission. You can deactivate what Sutradhar watches, and revoke access and delete your data whenever you want. You control what flows.
Most "AI for your inbox or your life" tools copy your data into their cloud, indexing your emails and files into their own databases, sometimes to train on. Sutradhar doesn't. It indexes in place, keeps pointers instead of content, sends only metadata to the AI, and holds read-only access. The data minimization is built into the architecture, not bolted on as a policy.
The evidence stays yours, in place. Sutradhar helps you see across your life without asking you to surrender it.
It holds the threads so you can hold your life.