Skip to content
10-8
DemoChecksPricingAfter the replyYour dayData
Get the extension

Effective 31 August 2026

Privacy policy

1. The short version

10-8 helps a freight broker read incoming quote requests, price them and answer them. This page says what mail and data reach us, what we keep, how long we keep it, which other companies handle it, and what you can ask us to do.

10-8 is a private pilot. Access is by invitation, it is free, and it is pre-release software that is still being built and still changing. You are an early tester rather than a paying customer, and this page describes what happens to your data today.

We read the mail that arrives in a connected Gmail mailbox, and we never write to it: nothing is sent, filed, labeled or marked read from your account.

Nothing is filtered out on what a message says. Mail is stored first and worked out afterwards: nothing reads a message to decide whether it is a quote request before there is a record of it. The one thing that can hold mail back at the door is an hourly ceiling on how much we take from one account at a time, and mail held back by it is left where it is rather than thrown away.

A message that turns out not to be a freight quote request is set aside for you to see, with a reason attached. It is not quoted, and it is not thrown away.

We keep the original text of every message we process, encrypted, and nothing deletes it on a timer. The scrubbed text of each negotiation message is kept permanently, on purpose, because a freight broker has to keep transaction records.

We do not sell your data, we do not use it for advertising, and we do not train models on it. A short list of other companies handles parts of it so the service can run, and every one of them is named below.

2. Who runs 10-8, and how to reach us

10-8 Broker Copilot is a Chrome extension and a hosted service for freight brokers, published at ten-eight.ai.

10-8 is run by one person, not by a company. It is run by an individual entrepreneur registered in Georgia — the country in the Caucasus, not the American state of the same name — which is the Georgian form of a registered sole proprietorship, and that registered individual is the party you are dealing with when you use 10-8.

The individual entrepreneur behind 10-8 is Konstantin Bondarev.

The way to reach us is one email address: [email protected]. It reaches the person who runs 10-8, and there is no phone line and no ticket system behind it.

Write to that address with any question about this page, about what we hold on you, or about removing it. It is the only route for the requests described below; nothing in the product does any of them for you at the press of a button.

Our own service and its database run in the United States, in Amazon Web Services' us-east-1 region. The other companies named further down run their own systems, and your data may be handled outside the United States by them.

The terms that govern your use of 10-8 are published on this website at ten-eight.ai/terms, and the two pages are meant to be read together.

3. How your mail reaches 10-8

Mail reaches 10-8 through exactly two doors, and you choose which one.

The first door is a Gmail connection. You grant it through Google, and a service of ours checks the mailbox every 60 seconds for new mail.

Be clear about how much that connection sees. Only the very first check is limited to unread mail in your inbox. Every check after that asks Google for everything newly added to the mailbox, whether it is read or unread, in the inbox or not, under any label, including mail you sent yourself, and for each new message we also pull the whole conversation thread it belongs to.

The second door is a forwarding address. Connect nothing, set one rule in whatever mail program you already use, and forward only the requests you want us to see to your own address at inbox.ten-eight.ai.

There is no content filter in front of either door. Whatever comes through is stored first and classified afterwards, and the hourly ceiling on how much we take from one account at a time is the only thing that can turn a message away before that.

There is a third way load details can reach us, and it is not mail. If you install the extension, it can read load details off a freight portal, load board or TMS page you have open and send them to us. Section 9 says exactly which sites that can happen on and what it takes off the page.

4. What the Gmail connection lets us do, and what it does not

Connecting Gmail asks Google for exactly four permissions: openid, email, gmail.readonly and gmail.send.

The openid and email permissions identify the mailbox. On this route we read one field from Google, the mailbox address, and nothing else: no name, no picture, no Google account identifier.

The gmail.readonly permission is what lets us read the mail. It is what makes the checking work without you keeping a browser tab open.

The gmail.send permission is requested at the Google screen and never used. No part of 10-8 calls Google's send interface, and every quote we send goes out through our own mail provider from a 10-8 address.

Signing in to 10-8 with Google is a separate step from connecting a mailbox, and it is its own Google screen asking for three permissions of its own: openid, profile and email. From that step we keep your first and last name and the link to your Google profile picture, and your name is what signs the quote emails we compose for you.

Those two screens are the whole of it. We take no other Google data: no Google password, no Calendar, no Drive, and nothing beyond the permissions the two screens above ask you for.

5. What we store

Your account record: your email address, display name, company name, phone number and MC number, plus the name and picture link taken from your Google profile.

The Gmail connection record: the connected mailbox address in plain form, the Google access and refresh tokens as encrypted data, the list of permissions you granted, and a marker for how far through the mailbox we have read.

A record for every message that arrives, written before anything is classified. It holds the subject line, the sender's full address and domain, the shipper's domain, the pickup date and the origin and destination postal codes, in plain form.

The mail envelope itself, also in plain form: subject, from, to and cc addresses, message and thread identifiers, reply and reference headers, date, labels and mail provider.

Shipper contact details attached to the load: name, email address, phone number, and the part each cc'd person played. The version of this page we are replacing said we store the shipper's domain but not individual contact names. That was wrong, and this line replaces it.

The original text of the message, encrypted, one record per load. The key that opens each one is itself stored wrapped, and every attempt to open one, allowed or refused, with who asked, why and when, is written to a log that belongs to your account.

A permanent, add-only archive of the body of every negotiation message, inbound and outbound, with personal details replaced by placeholder tokens. No account-level connection to the database can rewrite or remove an entry in it, because the permission to do either has been withdrawn at the database itself.

The freight facts we pull out of the message: origin and destination cities and postal codes, equipment type, weight, commodity, pickup and delivery dates, the rates quoted and the market figures behind them.

Files attached to mail that arrives at your forwarding address, and only when the sender passes the standard sender checks: an unverified sender's attachment is quarantined and never stored. The file itself goes to our storage, and the database keeps only a fingerprint of it and where it lives, never the bytes and never the filename.

Files attached to mail in a connected Gmail mailbox are not downloaded at all. We see only the file's name, type and size.

Load details the extension reads off a freight portal, load board or TMS page you have open, when it finds them: the text of the part of the page it read, the address of the page, and the site's domain. From there it is handled exactly like a request that arrived by mail.

Market provider credentials, if you use one. These are handed to us out of band and stored by us, encrypted, tied to a single organization, with no way to read them back in plain form. An earlier version of this page said such credentials never leave your browser; that stopped being true, and this line replaces it.

Your notification settings: your quiet hours, your time zone, which alerts you want and how urgent each one is to you. If you switch Telegram notifications on, that record also holds the Telegram chat id and, if you supply one, the bot token that goes with it — both as ordinary text rather than encrypted.

Your web request carries your IP address, as every web request does. The service itself uses it only as a counter key held in memory, to stop one source flooding it, and writes it to no log of ours and to no table in the database. The web server in front of the service keeps an ordinary access log of the addresses that connect to it, and Cloudflare, which terminates the connection, keeps its own records.

6. How long we keep it

This is the honest version, and it differs from what this page used to say. The old text promised that raw email content was deleted within 24 hours. Nothing in 10-8 deletes it, not in 24 hours and not ever, and we will not publish a window that no part of the system enforces.

The encrypted original text of your mail: no time-based deletion. It goes when the load record or the account record it hangs from goes, and not before.

The archive of negotiation message bodies: permanent, by design. Federal rules make a broker keep a record of each transaction, so this archive is deliberately left out of every cleanup job we run, and no job may be pointed at it.

The freight facts pulled out of your mail, and the message records written when mail arrives: no time-based deletion.

Quote version history: we keep the 50 most recent versions of each load and drop the rest. That sweep runs when the service starts and every 24 hours after.

Attachments: nothing deletes them on a timer today. An automatic expiry is planned but it is not switched on, and we will not describe it as though it were.

The Gmail connection: disconnecting withdraws our access at Google and stops the reading immediately, but it does not erase the record. The encrypted tokens and the mailbox address stay in your account record until the account record itself is removed.

Anything pasted into the demo on this website: 30 days at the outside, enforced by the database on every row, and swept every hour.

The pilot waiting list: your email address stays until you ask us to remove it, or until twelve months after the pilot ends. We do that by hand, and there is no job that does it for us.

Database backups: 7 days. Anything removed from the live system is still present in a backup until that window passes.

So when we say something is deleted, we mean this and nothing more: it is gone from the running system immediately and irreversibly, and it is gone absolutely once backup retention has lapsed, 7 days later.

7. How your data is protected

Everything we encrypt is encrypted with AES-256-GCM, and each record is bound to the account and the run it belongs to, so encrypted data cannot be replayed into somebody else's context.

The keys live in AWS Systems Manager Parameter Store as encrypted parameters, and are written at start-up to memory-backed files the service alone can read. An earlier version of this page named AWS Secrets Manager; that path was never built, and the service refuses to start if anyone points it there.

Every table in the database has row-level security switched on, all 47 of them with none missing, and a broker's request runs under an identity that can reach only that broker's own rows.

Here is the honest limit of that. Our own internal processes run with elevated access, and we hold the keys that open the encrypted records. Encryption protects your data from anyone who gets at the storage; it does not mean 10-8 cannot read what 10-8 stores.

Before any model or any later stage sees the text of your mail, a scrubber running on our own machines replaces names, addresses, phone numbers and company names with placeholder tokens, and cuts card numbers and similar identifiers out entirely. If a token still shows up in an extracted value, that value is dropped and the load goes to you for review instead of being trusted.

Traffic to the service is encrypted in transit. It is terminated at Cloudflare, so the exact minimum version in force is a setting there rather than something this software chooses.

If we find that your data has been taken or exposed, we will tell you at the address on your account, tell you what we know and what we are doing about it, and do whatever the law then requires of us. That is a commitment about what the people here will do, not a description of an alarm that goes off by itself.

8. Other companies that handle your data

The list below is complete for what runs today. The version of this page it replaces named two companies and left out every one that actually receives the content of your mail.

OpenAI. The scrubbed text of your message, with names, addresses and phone numbers already replaced by tokens, is sent to OpenAI's models to structure the request and draft prose. The original text is never sent.

Google Maps. Origin and destination place names taken from the message are sent to Google's geocoding and distance services to work out the lane and the mileage.

SendGrid. It receives mail forwarded to your 10-8 address, and it carries every quote, counter and decline we send out.

Amazon Web Services. It hosts the service and the database, holds the keys, and receives operating counters that carry no message content and no addresses.

Cloudflare. It terminates the encrypted connection in front of the service, serves this website, and runs our domain's name records. On the demo it also runs a bot check that receives the visitor's IP address.

Supabase. It issues and verifies the sign-in tokens. It is not our database: an earlier version of this page said it was, and that stopped being true when the service moved to a Postgres database inside Amazon Web Services.

Telegram, but only if you switch it on. 10-8 can tell you about a load through Telegram's bot service. It is off until you turn it on yourself, and when it is on the message we hand Telegram is a short summary — the lane, the equipment, the rate, the risk level, the flags raised, or a line saying what happened to a load. It is never the body of the shipper's email.

No load board receives your data. The market figures in the pilot come from an internal test source rather than a live market provider, and there is no live load-board connection in the software today.

Error reporting through Sentry is built into both the service and the extension but is switched off. No reporting address is set in anything we ship, and without one the reporter does not start.

Model tracing through LangSmith is not switched on either, and the pipeline is built so a tracer could not carry unscrubbed text out even if one were added: every run substitutes a redacting tracer, and a build check fails if any run is missing it.

We will also hand over data if the law requires it, on a court order or other lawful demand, or to protect our rights or those of our users.

9. What stays in your browser, and what leaves it

The extension keeps a small amount of state on your machine and nothing else: your 10-8 sign-in tokens and when they expire, a transport preference, notification quiet hours, a queue of pending notifications, which loads it is watching, and the badge count.

No message body, no shipper contact and no market provider credential is among them.

What the extension does send us is this. On a fixed list of sites written into the code — shipper portals, load boards and the two TMS platforms — it watches the page for load details, and when it finds them it sends the text it read, the address of the page and the site's domain to 10-8, where they are handled like a request that arrived by mail. That is the only thing it ever takes off a page.

The extension never reads your webmail. No webmail site is on that list, so nothing of ours runs on a Gmail page or on any other mail page, and nothing of ours reads one.

Be clear about what Chrome asks you for, though, because it is broader than that list. The extension requests access to all websites, since the part that fills in a TMS form has to work on whatever page you have open, so Chrome will warn you at install that it can read and change data on every site you visit. What holds it to freight sites is the fixed list above, written into the code and checked by a test against the shipped extension — not the permission Chrome grants.

It watches whether you are still signed in to three market sites by looking at the status code their pages return, and it never reads their cookies. It asks for no cookie permission at all.

This marketing website sets no analytics, no tracking pixel and no cookie of its own. The only thing it writes into your browser is your choice of light or dark theme.

10. Where your quotes go when they are sent

Quotes do not go out from your mailbox. They go out through SendGrid from a 10-8 address, with replies pointed back at your own 10-8 forwarding address, so a shipper's answer returns through the same door.

Nothing is sent without you pressing send. The part of the system that would send a reply on its own has not been built: a load that the rules would let through simply stops and waits for you.

During the pilot an organization starts in a mode where approved quotes are delivered to a 10-8 safety mailbox instead of the shipper, stamped so they cannot be mistaken for a real quote. Live delivery is switched on deliberately, one organization at a time, and any failure resolves back to not emailing a real shipper.

Which of the two happened is recorded against every quote we send, so it is a fact in the database rather than a matter of memory.

11. The demo on this website

If the demo is running on this website, you can paste an email into it without an account and without signing anything. Here is exactly what happens to it.

It runs four real stages of the same pipeline over your text, the scrubber, the field extraction, the geography lookup and the safety checks, with the model legs switched off, so an anonymous paste makes no model calls at all. Google's geocoding is the one outside service it still uses.

It cannot touch anything of yours or of any customer's. It does not run the parts that decide, send or file anything, it writes no load record, no message record, no encrypted original and no archive entry, and it issues no credential.

What you paste is kept, as encrypted data, for at most 30 days. The 30-day ceiling is enforced by the database on every row, and a sweep runs every hour, so a run is gone within an hour of expiring.

The stored record holds the pasted text, the scrubbed text, the extracted load, the checks, the geography result, the simulated pricing and the run document, all inside one encrypted blob. There is no readable content column on that table and none may be added.

Deletion is done by destroying the key. Each run gets its own random key, only the wrapped copy is stored, and the sweep destroys that copy first and then the encrypted data, in a single step. Once the key copy is gone the data cannot be recovered from the running system, and it is gone absolutely once backup retention has lapsed, 7 days later.

No signed-in broker can reach a stranger's demo run, and no stranger can reach another's. The rule on those tables grants nobody, and only our own internal service reaches them.

The prices the demo shows you are simulated. The code that produces them cannot reach a market provider at all, because it does not import one, does not call one and does not read the setting that would pick one, and every figure it returns is marked as simulated.

There is no way for a visitor to ask for a demo run to be erased early. It expires on its own within 30 days.

If you join the pilot waiting list, that is a separate record holding only your email address, where you signed up from, and when. It carries no run identifier and no copy of anything you pasted.

12. What we never do with your data

We do not sell or rent your data.

We do not use it for advertising of any kind, including retargeting and personalized advertising.

We do not train models on it. Nothing in the system writes your text to a training store, and the one path that could have carried unscrubbed text out to a tracing service is closed by construction and checked by a build gate.

What we learn from your own edits, which quotes you accepted, changed or rejected, is used to improve your own suggestions and is grouped strictly by your account. There is no cross-customer pooling and no shared training set.

People at 10-8 do not read the content of your mail except for security reasons, to comply with the law, or with your explicit permission. Every time an original message is opened from the encrypted store, allowed or refused, that is written to a log that belongs to your account.

13. Your choices, and how to use them

You can cut our access to your mailbox at any time, from your own Google account at myaccount.google.com/permissions, or by disconnecting inside 10-8. Either one stops the reading immediately.

You can use 10-8 without connecting a mailbox at all. Forward only the requests you choose to your own 10-8 address, and no other mail of yours reaches us.

You can ask for a copy of what we hold on you, ask us to correct something in it, or ask us to delete your account and its data, by writing to [email protected]. All three are done by hand. There is no export button and no delete button in the product, and we will not promise you a turnaround the system does not enforce.

You can turn Telegram notifications off, or leave them off, and nothing about your loads goes to Telegram.

Two limits on deletion, stated plainly. The archive of negotiation message bodies is permanent by design because of the broker record-keeping duty, so deleting an account cannot mean that every trace goes. And anything deleted stays in a database backup for up to 7 days after.

The version of this page we are replacing promised that account data would be deleted within 30 days of a request, and offered an opt-out from optional data collection. Neither existed. There is no deletion job with a clock on it, and there is no opt-out setting anywhere in the product, so both promises are gone from this page rather than restated in softer words.

14. The law that applies to your data, and how to complain

10-8 is run from Georgia, so Georgian data protection law is the law that applies to what we do with your data: the Law of Georgia on Personal Data Protection, which came into force on 1 March 2024 and follows the European model closely for private businesses.

Your data does not stay in Georgia. Our service and its database run in Amazon Web Services' us-east-1 region in the United States, and the other companies named above run their own systems in their own places, so using 10-8 means your data is sent out of Georgia and handled abroad. We are telling you that plainly rather than leaving you to work it out from the hosting.

If you think we have handled your data wrongly, write to [email protected] first and give us the chance to fix it. If that does not settle it, you can complain to the Personal Data Protection Service of Georgia, which is the state body that supervises data protection there.

We have no data protection officer, and we are not pretending to. Georgian law requires one only of public institutions, banks, insurers and medical institutions, and 10-8 is none of those, so your questions go to the address above rather than to an officer we do not have.

Which law governs the agreement between us, and which courts a dispute would go to, is a separate question. It is answered on our terms page rather than here.

15. Children

10-8 is a professional tool for freight brokers. We do not knowingly collect data from anyone under 18.

16. Changes to this page

When this page changes in a way that matters, we will publish the new version here and change the date at the top of it.

Because the pilot is invitation-only, we know who every participant is, so we will also email everyone taking part when this page changes in a way that matters. That is a person sending mail, not a notice the product raises: there is no in-product notice screen and no record of who accepted which version.

The date at the top of this page is the date this version took effect.

17. Google API Services User Data Policy

10-8 Broker Copilot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We use Google user data only to provide and improve the features described on this page.

We do not use Google user data for advertising of any kind, including retargeting and personalized advertising.

We do not sell or rent Google user data, and we pass it only to the companies named in the list above, each of which handles it only so the service can run.

We do not use Google user data to develop, train or improve general models. No part of 10-8 writes your text to a training store, and what reaches our model provider is the scrubbed text of your own request, sent to answer that request.

People at 10-8 do not read the content of your Gmail except for security reasons, to comply with the law, or with your explicit permission, and every time an original message is opened from the encrypted store that is recorded.

DemoChecksPricingAfter the replyYour dayDataPrivacyTerms

Rates shown in the demo on this page are simulated.