Trust · security · GDPR

Trust & Security

You give us limited access to an inbox that may hold your customers' data. You deserve to know exactly how we protect it — here it is, in plain terms.

How access to your inbox works

What the assistant does — and does NOT do

We never train AI on your emails

Enquiry content is processed by Anthropic's commercial API — data sent this way is not used to train models. We do not use your emails to train anything. Full stop.

Google API compliance (Limited Use)

The use of raw or derived user data received from Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice: we use data from your inbox only to answer enquiries and to show them to you in your panel. We do not use it for advertising, we do not sell it, we do not pass it to data brokers, and we do not train any AI models on it — neither ours nor anyone else’s.

How long we keep data, and when we delete it

We keep enquiry and reply content only as long as the service needs it. When the contract ends we delete the connected inbox’s data within 30 days. You can revoke access at any time in your Google account settings — the assistant immediately loses the ability to read or send, and we delete the access token.

Your data stays yours

We do not sell or share the data in your inbox. It stays between you, your customer and your inbox. We use it solely to answer the enquiry and notify you.

Encryption & infrastructure

Connections to email and to our service are encrypted (TLS). We hold no certifications of our own yet — we are a small, new company and we say so openly. We do, however, run exclusively on certified providers' infrastructure: Google (ISO 27001), Anthropic (SOC 2 Type II), Stripe (PCI DSS Level 1), hosting in the European Union (Frankfurt).

Who else processes the data (subprocessors)

To run the service we rely on trusted providers. Current list (changes are announced on this page in advance):

Fly.ioapplication hosting (European Union region, Frankfurt)
Googleemail (Gmail / Google Workspace)
Anthropicthe AI model (processing enquiry content)
Stripepayment processing (we never see your card number — Stripe holds it)

Some providers process data outside the European Economic Area (incl. the USA) — under an adequacy decision (Data Privacy Framework) and standard contractual clauses (SCC).

GDPR — who is who

For the data in your inbox (including your customers' data) you are the controller. We process it on your behalf as a processor — only on your instructions and only to provide the service.

If something goes wrong (incidents)

If we detect a data breach affecting your inbox, we will notify you without undue delay — with what happened and what we did. As the controller, you decide on reporting to your supervisory authority (you have 72 h — we will help you compile the details). Security contact: [email protected].

Data-processing agreement (DPA)

The data-processing agreement is concluded automatically when you accept the Terms (section 8 of the Terms) — nothing to sign separately. On request we also provide it as a separate signable document: [email protected].

Back to the homepage · Privacy Policy · Terms of Service
FT1 · Szczecińska 48a, 80-392 Gdańsk · NIP 7582229163