Docs/ Privacy & security

Privacy & data handling

Zero-retention AI, no training on your mail, metadata-light by design.

Aiemaily is designed so that your email never becomes someone else’s training data or ends up in a shared cloud cache. Here’s exactly what touches the network, what stays local, and how we keep it that way.

What lives where

Message bodies are stored in encrypted object storage and cached locally on your device. They are never held in a shared cloud cache accessible across accounts. What the server works with day-to-day is thread metadata — sender, subject, dates, labels — plus AI-generated summaries that you can inspect and delete.

Full message text is only touched during two operations: initial mailbox sync and AI-powered actions (drafting, triaging, summarising). Both are metered and written to the audit log.

No training on your mail

We never use your email content to train, fine-tune, or evaluate any model — ours or a third party’s. Cloud inference runs zero-retention: the model provider receives the prompt and returns a result; nothing is stored on their side beyond the request lifetime.

AI inference: zero-retention by design

All LLM calls are routed through OpenRouter, a single gateway that lets us pick the right model for each task without giving any one provider a persistent copy of your data. We configure every request for zero retention, meaning the provider must not log or store the prompt or completion.

When you supply a BYOK key, inference runs on your own provider account under your own terms — Aiemaily never sees the raw response in plaintext beyond the isolated worker that handles the call.

Data typeLocationWho can read it
Message bodiesEncrypted object storage + local device cacheYou only (server decrypts for sync/AI ops)
Thread metadataServer databaseYou only (object-level auth on every row)
AI summariesServer databaseYou only (deletable on request)
OAuth / IMAP credentialsEnvelope-encrypted; isolated worker onlyNever readable in plaintext outside the worker
Audit logServer (append-only)You — and Aiemaily for support with consent

Metadata minimisation

The server stores the minimum metadata needed to power the inbox view and AI triage: thread IDs, sender addresses, subject lines, timestamps, and label assignments. It does not store analytics events tied to individual messages, advertising identifiers, or cross-account behavioural profiles.

IP addresses are retained only in security logs (brute-force, anomaly detection) and are purged on a rolling 30-day window.

Audit trail

Every AI-initiated action — summary generated, draft created, label applied — is written to an immutable audit log scoped to your account. You can review the full log in Settings → Activity. Actions taken in Autopilot mode include the source email ID that triggered them, so you can always trace why something happened.

SOC 2 on the roadmap

Formal SOC 2 Type II certification is planned for later this year. In the meantime, the controls described here are live and auditable.

Frequently asked

Ready to try it?

Start free