Last updated: 30/07/2026
Privacy Policy
hAI Mail ("we", "us", the "Service") is an AI email assistant that connects to your Gmail account and works through AI assistants such as ChatGPT to help you triage, prioritise, and understand your email. This policy explains what data we access, how we use it, who we share it with, and the choices and rights you have.
The Service is operated by Papag.ai Ltd (registered in England and Wales, company number 16915053). At present the Service is offered to users in the United Kingdom, United States, Canada, Australia, and New Zealand; it is not currently offered in the EU/EEA. This policy is written to UK GDPR standards, which we apply to all users wherever they are. This does not remove any additional rights you may have under the privacy law of your own country.
Our data-protection role. Papag.ai Ltd is the controller of the personal data processed to provide the Service. That includes your account and registration data, the mail metadata and AI-derived insights we generate, and the personal data of the people you correspond with that we necessarily handle when we analyse your mailbox. Being the controller means we are responsible for how that data is used and for honouring the rights described in this policy. You stay in control of your mailbox: you decide whether to connect it, what to ask hAI Mail to do, and when to disconnect or delete.
You can reach us at hello@haimailassistente.com or 1 Popplestone Park, Brixton, Devon, PL8 1DS, Great Britain.
At a glance
- We access your Gmail on a read-only basis, only after you grant permission.
- We never store the contents of your email messages or attachments. Message bodies are processed transiently — while generating intelligence, or fulfilling a retrieval you request through your connected assistant — and are never stored.
- We store metadata (such as sender, subject, and dates) and the AI-derived insights we generate from your mail (such as priority and contact summaries).
- To generate insights, message content is sent transiently to our AI model provider; we restrict routing to zero-data-retention endpoints, and that content is not used to train models.
- When you use hAI Mail through an AI assistant (such as ChatGPT), the results you ask for are returned to that assistant so it can show them to you.
- You control your data: disconnect an account (which pauses it but keeps your data so you can reconnect), delete your data from our live systems, or revoke our access directly from your Google Account — at any time.
1. Information we access and collect
1.1 Google account data (via the Gmail API)
When you connect your account, you grant the gmail.readonly scope. Under that permission we access:
- Message metadata — sender name and address, recipients, subject, date, labels, read/attachment flags, and message and thread identifiers.
- Message content — the text body of messages and the filenames of attachments. We do not separately download or open attachment files; note that where a message carries text inline, that text forms part of the message body we process. All of this is processed transiently as described in Section 3.
- Contacts derived from your mail — the people you correspond with, inferred from your messages.
- Your basic Google profile — your name and email address, from the
openid, email, and profile scopes used to sign you in.
1.2 Information you provide
Profile and preference details you choose to add (for example your job title, company, or handling preferences), and the guidance rules you create to tell the assistant how to treat certain mail.
1.3 Information generated by the Service
AI-derived insights we compute from your mail, including priority scores and reasons, sensitivity assessments, contact profiles and relationship summaries, and the learned preferences behind your guidance rules.
1.4 Operational data
Authentication and session records, and non-content operational logs and cost metrics (for example token-usage counts) used to run and secure the Service. These do not contain the contents of your email.
1.5 Data about your correspondents
Because we analyse your mailbox, we necessarily handle personal data about the people you correspond with — their names, email addresses, and the content of their messages to you — obtained indirectly, through your account, rather than from them directly. We process this data only to provide the Service to you — to build the priority, relationship, and sensitivity intelligence that helps you manage your mail. We do not make legal or similarly significant decisions about your correspondents, contact them, or use their data for advertising. Because notifying every correspondent individually would involve disproportionate effort, we rely on the exemption in Article 14(5)(b) of the UK GDPR and make the required privacy information available publicly through this policy instead.
1.6 Website data and cookies
Our marketing website (haimailassistente.com) is a static site hosted on Cloudflare Pages. It does not set advertising or tracking cookies. Our hosting/CDN provider (Cloudflare) may process standard technical information — such as your IP address and browser type — in server access logs to deliver and protect the site. This is separate from, and unrelated to, the email data described above.
2. How we use your information
We use the information above solely to provide and improve the Service to you:
- to fetch and analyse your mail so we can prioritise it and surface what needs attention;
- to build contact and relationship context that helps explain why a message matters;
- to detect potentially sensitive content so it can be flagged for your review;
- to apply the guidance rules you set;
- to authenticate you, secure the Service, and understand operating costs.
We do not use your Google user data for advertising, and we do not sell your personal data. We do not use the content of your Google user data to train generalised AI models. Our use of Google user data is limited to the user-facing features described in this policy, consistent with the Limited Use commitments in Section 6.
hAI Mail's scores and labels help you organise and prioritise your mail. They do not produce legal effects or similarly significant decisions about you, and we do not carry out solely-automated decision-making of that kind (Article 22 of the UK GDPR) — you stay in control of what happens with your email.
3. What we store, and what we do not
We do not store the contents of your messages or attachments. Message bodies, message snippets, and attachment contents are never written to our database. They exist only transiently in memory — while we generate intelligence, or while we fulfil a retrieval you request through your connected assistant — and are then discarded.
We do store, encrypted where sensitive (see Section 5):
- message metadata (sender, recipients, subject, dates, labels, flags, and message identifiers);
- the AI-derived insights we generate (priority, sensitivity, contact profiles, relationship labels);
- your profile, preferences, and guidance rules;
- your connected-account email address and an encrypted copy of the Google refresh token that lets us maintain the connection.
4. How we share your information (processors and other recipients)
We share data only with the following parties, only as needed to run the Service:
- Our AI model provider (OpenRouter). To generate insights, we transiently send message content — including message bodies and attachment filenames — to OpenRouter, which routes each request to an underlying large language model (currently models from the Gemini and Mistral families). We restrict routing to model-endpoint providers that operate under a zero-data-retention (ZDR) arrangement: your content is not retained after the request and is not used to train models, and it is sent only to provide the background-analysis features you enabled or a live operation you requested. The underlying model providers are currently Google (the Gemini and Gemma models) and Mistral AI (the Mistral models); we will update this policy if that set changes. Further detail on each operator and its processing location is available on request.
- The AI assistant you connect (for example ChatGPT / OpenAI). When you use hAI Mail through an AI assistant, the results you request are returned to that assistant so it can present them to you. Depending on what you ask for, these results can include: sender and recipient names and email addresses; subjects, message snippets, and full message bodies; attachment filenames; your connected-account identity; your profile and preferences; your guidance rules; and the intelligence we derive (priority, sensitivity, and contact relationship summaries). What is returned is governed by your request; the assistant's own handling of that data is subject to its provider's privacy policy.
- Infrastructure providers. We host the Service on servers provided by Hetzner (in the European Union) and use Cloudflare for our website and domain. We also use Google Cloud Pub/Sub to receive notifications that your mailbox has changed; this processes only your account email address and an opaque Gmail change cursor — never message content. These providers process data on our behalf as processors under contract.
We do not otherwise disclose your personal data, except where required by law.
5. Security
- In transit: data sent over external networks — to Google, to our model provider, and to your browser or assistant — is protected with TLS. Traffic between our own back-end services runs on an isolated private network that is not exposed to the public internet.
- At rest: we encrypt selected sensitive fields — not every stored field — at the database column level. Free-text content such as subjects, sender names, AI-written reasons, and guidance is encrypted with randomised (Fernet) encryption; fields that must be matched for lookups, such as correspondent email addresses, are encrypted with deterministic (AES-SIV) encryption.
- Credentials: your Google refresh token is stored encrypted at rest and is never exposed to the AI assistant.
- Logging: message content is never written to our logs, and our logging is configured to redact email addresses and secrets (such as tokens and keys). Operational logs may still contain technical identifiers — such as IP addresses and pseudonymous internal reference IDs (for accounts and jobs). We keep these logs for no longer than 90 days, after which they are automatically deleted.
No method of transmission or storage is completely secure, but we take reasonable and appropriate measures to protect your information.
6. Google Limited Use disclosure
hAI Mail's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, our use of Google user data is limited to providing and improving the user-facing features described in this policy; we do not transfer or sell it for advertising, and we do not use it to train generalised AI models.
We also restrict human access to your Google user data. No one at hAI Mail reads your Google user data except: with your explicit consent, for specific data; where necessary for security purposes (such as investigating abuse or a technical fault); to comply with applicable law; or where the data has been aggregated and anonymised and is used for internal operations. Otherwise, your Google user data is processed only by automated systems.
7. Data retention
- Your email metadata and the insights we derive are retained until you delete them — by deleting the connected account or your hAI Mail account. There is no fixed expiry window. Disconnecting an account is not a deletion: it pauses new analysis and keeps the account's data (and its encrypted connection token) so you can reconnect later. Only deletion removes that data from our live systems.
- Message bodies and attachment contents are not retained at all (see Section 3).
- Operational records are automatically deleted on short schedules: completed or failed internal job records within about 48 hours, and per-execution telemetry within about 14 days. This telemetry is non-content — it records things like which model ran, token counts, success or failure, and a sanitised error type, never message content — and may be retained for the period above even after account deletion, for billing-integrity and operational purposes.
- Backups. We do not currently retain separate backups of the live database. When we introduce backups, they will be encrypted and kept on a limited rolling schedule, and our deletion process will ensure that data you delete is not reinstated from a backup; we will update this policy before that change takes effect.
- Authentication sessions expire automatically: access tokens within 60 minutes, and sign-in (refresh) sessions after 30 days.
8. Your rights and choices
- Disconnect an account. You can disconnect a connected account at any time. This pauses new analysis and syncing (after any in-flight work finishes) and keeps your existing data so you can reconnect later (see Section 7). It does not revoke Google's authorisation or delete your data, and Google may keep sending harmless change notifications until the mailbox watch expires. To stop future access, revoke at Google; to remove data, delete.
- Revoke access at Google. You can withdraw hAI Mail's access to your Google account directly from your Google Account's security settings, independently of us. This prevents any future access to your mailbox but does not delete data we have already stored — to remove that, use delete below.
- Delete your data. You can delete a connected account or your entire hAI Mail account through the assistant. This revokes our access and deletes that account's data from our live systems.
- Access and rectification. You may request a copy of the personal data we hold about you and ask us to correct it.
- Portability. Where the right to data portability applies, you can ask us to provide the relevant data in a structured, commonly used, machine-readable format and, where technically feasible, to transmit it to another controller.
- Restrict processing. Where applicable under GDPR, you may ask us to restrict certain processing of your personal data.
- Complain. You have the right to lodge a complaint with a data protection authority. In the UK this is the Information Commissioner's Office (ICO), which you can contact at ico.org.uk/make-a-complaint. If you are in another country where the Service is offered, you can also complain to your local authority — for example the OAIC in Australia, the Office of the Privacy Commissioner of Canada, or the Office of the Privacy Commissioner in New Zealand.
To exercise any of these rights, contact us at hello@haimailassistente.com.
Your right to object
You have the right to object, at any time, to our processing of your personal data that is based on our legitimate interests (see the legal bases below). If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. This right also applies to correspondents in relation to their own personal data.
Correspondents. If your personal data appears in someone else's connected mailbox, you may also contact us to exercise your applicable rights. Because that data sits within another person's mailbox, we will act on such requests subject to that person's rights and to confidentiality.
Legal bases for processing
We process your personal data under the UK GDPR on these bases:
- Article 6(1)(b) (performance of our contract with you) — for processing your own personal data needed to provide the Service you sign up for: creating and running your account, fetching and analysing your mail, and generating the intelligence you asked for.
- Article 6(1)(f) (our legitimate interests) — for authentication, security and abuse prevention, operational and cost metrics, and for the limited processing of your correspondents' personal data needed to build the mailbox intelligence we provide to you. You can object to processing based on our legitimate interests at any time (see above).
Special-category data (Article 9). Your mail may contain, or our analysis may reveal, information that is "special category" under Article 9 — for example about health, religion, political views, sexual orientation, or trade-union membership. We do not process this data to build a profile of anyone's sensitive characteristics or to make decisions about them; our sensitivity feature exists only to flag potentially sensitive messages back to you so you can handle them appropriately. Where we process special-category data that relates to you, we rely on your explicit consent (Article 9(2)(a)), which you give when you connect your mailbox and enable analysis. You can withdraw that consent at any time by deleting your account or contacting us; disconnecting on its own only pauses future analysis and does not withdraw consent. Special-category data belonging to your correspondents may pass through our transient analysis incidentally; we minimise this by never storing message content, encrypting stored fields, requiring zero data retention from our model provider, and never using it to train models or to make legal or similarly significant decisions about those individuals.
Granting hAI Mail access to your Gmail is entirely voluntary — but the core Service cannot function without it, since analysing your mail is what the Service does.
9. International data transfers
We operate from the United Kingdom and host data in the European Union (Hetzner). The UK recognises the EU as providing an adequate level of data protection, so this hosting transfer needs no additional safeguard. Some processing — in particular the transient AI analysis in Section 4 — may involve transferring data to providers located outside the UK. The countries where our recipients are currently located include the United States and member states of the European Union (our hosting and AI model endpoints). Where a transfer is to a country the UK has not deemed adequate, we rely on the UK International Data Transfer Agreement (or the UK Addendum to the European Commission's Standard Contractual Clauses). You can contact us at hello@haimailassistente.com for more information about these safeguards or to request a copy of the relevant clauses.
10. Children
The Service is intended only for adults aged 18 or over managing their own email. It is not offered to, or directed at, anyone under 18, and we do not knowingly provide the Service to under-18 users. A connected mailbox may nonetheless contain information about children within its messages; we process any such information only as part of the email content you ask us to analyse, under the terms of this policy.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and notify you by appropriate means. Where a change introduces a materially new use of your Google user data, we will give you renewed notice and obtain your consent before that new use begins. Minor, non-material updates take effect when posted.
12. Contact
Questions about this policy or your data can be sent to hello@haimailassistente.com, or by post to Papag.ai Ltd, 1 Popplestone Park, Brixton, Devon, PL8 1DS, Great Britain.
This policy is governed by the laws of England and Wales. This does not limit any mandatory rights or protections you have under the law of your country of residence.