Last Updated: February 2025
✓ What we do
✕ What we don't do
Emaily is a Data Processor. When you connect your email account to Emaily, you (or your organization) remain the data controller of your emails. We process your email data solely to provide the services you've requested.
| Role | What it means |
|---|---|
| Data Controller | You or your organization |
| Data Processor | Emaily |
For any questions about this privacy policy or to exercise your data rights, please contact us at privacy@emaily.click
| Data Type | Stored? | Purpose |
|---|---|---|
| Account Data | Yes | Email address, name, preferences |
| Metadata | Yes | Sender, subject, timestamps |
| Embeddings | Yes | Vector representations for search (not reversible) |
| AI Summaries | Yes | Brief summaries of email content |
| Labels | Yes | Classifications applied to emails |
When processing your emails, we temporarily cache email content for a short period (24-72 hours maximum) to perform the requested actions. This cache is automatically purged after processing.
We use your data for the following purposes:
To provide categorization, summarization, and draft reply features, we use third-party AI providers:
Your data may be processed in:
For transfers outside the EEA, we ensure protection through Standard Contractual Clauses (SCCs), Data Processing Agreements with all providers and EU-US Data Privacy Framework compliance where applicable.
We implement security measures including:
In the event of a data breach affecting your personal data, we will notify affected users within 72 hours and notify relevant supervisory authorities as required by law.
| Data Type | Retention Period |
|---|---|
| Account data | Until you delete your account |
| Metadata & embeddings | Until you disconnect or delete |
| Temporary email cache | 24-72 hours maximum |
| Audit logs | 90 days |
When you disconnect your email provider or delete your account, all your data is permanently deleted. This includes embeddings, summaries, and metadata. This happens automatically upon disconnection, no manual request required.
Under GDPR and similar laws, you have the right to: