Privacy Policy
Last Updated: June 2026
Effective Date: June 12, 2026
MailMind ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use MailMind (the "Service") — an AI-powered email co-pilot that helps you triage, understand, and draft replies to email.
1. Information We Collect
Information You Provide
- Authentication: email address, OAuth tokens from Google or Microsoft (provider account IDs — never your email password), display name, and profile photo.
- Email data: headers (sender, subject, timestamp, thread metadata), body text (for triage and draft generation), attachment metadata (filename, size, type — contents are not processed), and folder labels.
- Application data: feedback submissions, calendar event metadata, preferences (RAG settings, Tone DNA profile, account metadata).
Information Collected Automatically
- Usage analytics (features used, errors), pipeline performance metrics (latency, cache hit rates, LLM error rates), and security signals (login attempts, device trust, rate-limit events).
2. How We Use Your Information
Core Service
- Triage emails across five axes (deadline urgency, sender authority, sentiment, thread decay, action type).
- Extract commitments — actionable items, deadlines, and stakeholders.
- Detect calendar conflicts against proposed deadlines.
- Generate drafts in your writing style (Tone DNA) using similar past emails.
- Retrieve precedents — find similar past emails to inform responses.
AI Processing & PII Protection
Before any LLM processing, we mask personally identifiable information:
- Email addresses →
[PII_EMAIL] - Phone numbers →
[PII_PHONE] - SSNs, credit card numbers, dates of birth →
[PII_REDACTED] - Secrets (API keys, tokens, passwords) →
[PII_SECRET]
The masked email is sent to Azure OpenAI for analysis. Raw email bodies are never sent to external LLMs. Only masked metadata and analysis results are stored.
3. Data Retention
- Email data: retained while your account is active; permanently deleted within 30 days of a deletion request.
- Triage results & drafts: cached for 1 hour; optionally persisted until you request deletion.
- Tone DNA profiles: deleted when you disconnect an account or delete your data.
- Session tokens: expire after 24 hours (session) or 7 days (quick-login); stored only as hashes.
- Audit logs: retained 1 year for compliance; never contain raw PII.
4. Data Security
- In transit: all data over HTTPS (TLS 1.2+).
- At rest: OAuth tokens are Fernet-encrypted; session tokens stored as SHA-256 hashes only — raw tokens live exclusively in HttpOnly, Secure, SameSite cookies.
- Access controls: every data-touching API endpoint requires an authenticated session; all calls are rate-limited and monitored.
Third-Party Services
- Azure OpenAI — masked email is processed under Microsoft's Privacy Statement.
- Gmail API / Microsoft Graph API — OAuth tokens fetch email via official APIs only; we never see your email password.
5. Data Sharing
We do not sell or rent your personal data. We share data only with service providers (Azure OpenAI, our database host) as necessary to run the Service, when legally required, or to prevent fraud and abuse.
6. Your Rights & Choices
You have the right to access, export, and delete your data. Exercise these rights by emailing [privacy@mailmind.com] with proof of identity; we respond within 30 days. You may withdraw consent at any time by disconnecting your email account or deleting your MailMind account.
7. Children's Privacy
MailMind is not intended for children under 13 (or the age of digital consent in your jurisdiction). We do not knowingly collect their information.
8. International Data Transfers
Your data may be processed in the United States or other countries. For EU/EEA users we rely on Standard Contractual Clauses with our processors.
9. Changes to This Policy
We may update this policy and will post the revised version with a new "Last Updated" date and notify you of material changes. Continued use constitutes acceptance.
10. Regulatory Compliance
- GDPR (EU): rights to access, rectification, erasure, restriction, portability, and objection.
- CCPA (California): rights to know, delete, and opt out of the "sale" of personal information. We do not sell personal information.
- DPDP Act (India): consent-based processing with clear purpose and grievance redressal.
11. Contact Us
MailMind Support — [support@mailmind.com] — https://mailmind.com
For privacy requests: [privacy@mailmind.com] (subject: "Privacy Request").
Version 1.0 — June 2026
© 2026 MailMind. All rights reserved.
Read our Terms of Service