Privacy Policy
Last updated: June 18, 2026
This Privacy Policy explains how AI Emaily ("AI Emaily", "we", "us", or "our") collects, uses, shares, and protects information when you use our website at aiemaily.com, our web application, and our macOS, iOS, Android, and desktop applications (together, the "Services"). AI Emaily is an AI-native email client with an autonomous assistant; we designed it to be private by architecture, and this policy describes how that works in plain terms.
By using the Services you agree to the practices described here. If you do not agree, please do not use the Services. This policy works alongside our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.
Who is responsible for your data
AI Emaily is the controller of personal data processed through the Services. For email, calendar, and contact content you connect, you are the controller and AI Emaily acts as your processor, handling that content only on your instructions and as needed to provide the Services. If you have questions or wish to exercise your rights, contact us at [email protected].
Information we collect
We collect the following categories of information.
Information you provide
- Account & profile: name, email address, password (stored only as a salted hash) or single-sign-on identifier, profile photo, language, time zone, and preferences.
- Billing: plan, subscription status, and the last four digits and brand of your card. Full card numbers are collected and processed by our payment processor — they never touch our servers.
- Support & communications: messages you send us, survey responses, waitlist sign-ups, and newsletter subscriptions.
Email and connected-account data
- Mailbox content: the messages, headers, attachments, drafts, labels/folders, and threads in the mailboxes you connect, so the product can sync, search, summarize, draft, and act on your behalf.
- Calendar & contacts: if you connect them, calendar events and contact records used for scheduling and addressing.
- Authorization tokens: OAuth access and refresh tokens (or, for IMAP/SMTP, the credentials you enter) needed to connect to your provider. These are envelope-encrypted and never logged.
Information collected automatically
- Device & app data: device type, operating system and version, app version, browser type, and — on mobile and desktop apps — a device identifier and push-notification token.
- Usage & log data: features used, actions taken, AI credits consumed, IP address, timestamps, crash reports, and diagnostic logs.
- Cookies & analytics: see Cookies and tracking technologies below.
How we use information
We use information to:
- provide, operate, secure, and maintain the Services across every platform;
- sync your mail; generate summaries, drafts, and replies; run the autonomous agent within the authority you grant (Manual, Copilot, or Autopilot); and surface reminders and your daily brief;
- process payments, manage subscriptions, and prevent fraud and abuse;
- provide support, respond to requests, and send service and (with consent where required) marketing emails;
- analyze aggregate usage to improve and develop features;
- comply with legal obligations and enforce our Terms.
We do not sell your personal information, and we do not show you third-party advertising. We do not use the content of your email to build advertising profiles.
AI processing of your email
AI features are central to AI Emaily, so we are explicit about how they work:
- No training on your mail. We never use the content of your email, calendar, or contacts to train, fine-tune, or improve generalized AI/ML models — ours or any provider's.
- Zero-retention inference. Cloud AI runs through our model gateway under zero-data-retention terms: prompts and outputs are processed to generate your result and are not retained by the model provider.
- On-device & BYOK options. You can run sensitive triage and drafting on an on-device model, or bring your own model key (BYOK). BYOK keys are envelope-encrypted and decrypted only inside an isolated worker — never client-side and never logged.
- You stay in control. In Copilot, a human approves before any send. Autopilot acts only within the rules you configure and provides undo plus a full audit trail. Email content is treated as untrusted input and is constrained by an action allow-list.
Google API Services — Limited Use disclosure
When you connect a Google account (Gmail, Google Calendar, or Google Contacts), AI Emaily's use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- we request the minimum OAuth scopes needed for the features you use;
- we use Google user data only to provide and improve the user-facing features you engage with — not for serving ads;
- we do not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with appropriate notice;
- we do not allow humans to read your Google data unless we have your affirmative consent for specific messages, it is necessary for security or to comply with law, the data is aggregated and anonymized for internal operations, or you have asked us to and we are providing support; and
- we do not use Google Workspace APIs or Gmail data to develop, improve, or train generalized AI and/or ML models.
Microsoft and other email providers
When you connect a Microsoft account (Outlook / Microsoft 365 via Microsoft Graph), or any IMAP/SMTP mailbox, we access only the data needed to provide the Services and handle it on the same minimization, encryption, and no-training basis described above. Your use of those accounts also remains subject to your provider's own terms and privacy policy. You can disconnect any mailbox at any time, which revokes our ongoing access.
How we share information
We share information only in these limited situations:
- Service providers (sub-processors). Vetted vendors that host infrastructure, process payments, route AI inference, and deliver email/notifications, acting under contract and only on our instructions.
- At your direction. When you connect an integration (e.g. Slack, Telegram, Discord, or your email provider) or ask the agent to send mail on your behalf.
- Legal & safety. When required by law, valid legal process, or to protect the rights, safety, and security of users, the public, or AI Emaily.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, with notice to you and continued protection of your data.
A current list of the vendors we use is on our Sub-processors page. Business customers can also review our Data Processing Agreement.
International data transfers
We may process and store information in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and equivalent mechanisms. A copy of the relevant safeguards is available on request.
Data retention
We retain personal data only as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. When you delete content or close your account, we delete or anonymize the associated data within a commercially reasonable period, except where retention is legally required. Message bodies are stored in encrypted object storage and removed when the underlying account or data is deleted. Limited backups may persist for a short, defined window before being overwritten.
Security
How we protect your data:
- encryption in transit (TLS) and at rest;
- OAuth tokens and BYOK keys are envelope-encrypted via a key-management service (KMS) and are never logged or stored inline;
- least-privilege access, object-level authorization on every read and write, and audit logging of sensitive actions;
- server-authoritative design — privileged writes run server-side, not in client bundles;
- signed webhooks, idempotency keys, rate limiting, and strict CORS/CSP.
No method of transmission or storage is perfectly secure, but we work to protect your data and will notify you and regulators of a breach as required by law.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. You can export or delete much of your data directly in the app at any time. To make any other request, use our data request form or email [email protected]; we will verify and respond within the time required by law, and we will not discriminate against you for exercising these rights.
EEA / UK (GDPR)
Our legal bases are: performance of our contract with you; your consent (which you may withdraw); our legitimate interests in operating and securing the Services; and compliance with legal obligations. You may also lodge a complaint with your local supervisory authority.
California (CCPA/CPRA)
We do not sell or "share" personal information for cross-context behavioral advertising, and we do not use sensitive personal information beyond the purposes permitted by law. California residents may exercise their rights to know, delete, and correct as described above.
Cookies and tracking technologies
The non-essential technologies we use, once you allow them, are:
- Analytics — Google Analytics 4 and Microsoft Clarity, to understand aggregate usage and improve the site. We do not use advertising cookies or build ad profiles.
- Live chat — Crisp, so you can message us from the site.
You can accept, reject, or fine-tune these at any time: use the "Cookie settings" link in the footer, or clear the aiemaily-consent cookie. Rejecting or later withdrawing consent stops the relevant tools and removes their access on your next page load. Our desktop and mobile applications use local storage only for authentication and preferences, and do not use third-party advertising trackers.
Platform-specific notices
- Apple App Store (iOS, macOS): our App Privacy "nutrition label" describes the data linked to you and used to run the app. We do not use the App Tracking Transparency framework to track you across other companies' apps and sites.
- Google Play (Android): our Data Safety disclosures describe what we collect and why, and our handling of Gmail and Google account data follows the Limited Use commitments above.
- Desktop apps (macOS & Windows): the same privacy practices apply; local caches are stored on your device and cleared on sign-out or uninstall.
Children's privacy
The Services are not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact [email protected] and we will delete it.
Third-party links and services
The Services may link to or integrate with third-party sites and services that we do not control. Their use of your information is governed by their own privacy policies; we encourage you to review them.
Changes to this policy
We may update this policy as the product and applicable laws evolve. We will revise the "Last updated" date above and, for material changes, provide additional notice (such as in-app or by email). Continued use of the Services after an update means you accept the revised policy.
Contact us
Questions, requests, or complaints about this policy or your data? Reach our privacy team at [email protected]. If you are in the EEA or UK and need an EU/UK representative, contact us and we will provide the relevant details.