SayMail

Privacy Policy

Last updated


This Privacy Policy describes how SayMail collects, uses, stores, and shares your information when you use our website, our web application, and our mobile application (together, the "Service"), and tells you about your privacy rights.

SayMail is an AI email client. To do its job it needs access to your mailbox, and often to your calendar and to other tools you choose to connect. This policy is written to be specific about what that access covers, what we keep, and what we never keep. If anything here is unclear, write to us at [email protected].

Interpretation and definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for you to access our Service or parts of our Service.
  • Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest, or other securities entitled to vote for election of directors or other managing authority.
  • Company (referred to as either "the Company", "We", "Us", or "Our" in this Agreement) refers to SayMail.
  • Cookies are small files that are placed on your computer, mobile device, or any other device by a website, containing the details of your browsing history on that website among its many uses.
  • Country refers to: Delaware, United States.
  • Device means any device that can access the Service, such as a computer, a cellphone, or a digital tablet.
  • Mailbox means an email account you connect to SayMail, currently a Google (Gmail) or Microsoft (Outlook) account.
  • Integration means a third-party service you choose to connect to SayMail in addition to your Mailbox, such as Google Drive, Notion, Todoist, Linear, or Zoom.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Service refers to the Website, the SayMail web application at https://app.saymail.ai, and the SayMail mobile application.
  • Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service, or to assist the Company in analyzing how the Service is used.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
  • Website refers to SayMail, accessible from https://saymail.ai.
  • You means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Collecting and using your personal data

Types of data collected

Account information

When you sign up we receive your name, email address, and profile picture from the Google or Microsoft account you sign in with. We use these to create and identify your Account and to contact you about the Service.

Mailbox and Integration access

When you connect a Mailbox or an Integration, the provider gives SayMail access tokens that let the Service act on your behalf. We store these tokens, encrypted, so the Service can keep working without asking you to sign in again. What each grant lets us do is described in the "Data from your Google account" and "Data from Microsoft and other connected services" sections below.

Email content

To show you your inbox, summarize a thread, sort your mail, or send a reply, the Service reads and writes email in your Mailbox. This content is fetched from your provider when you use the Service and is processed in memory to serve your request. We do not store your email messages, subjects, bodies, or attachments in our database. The exceptions, described in "Retention of your personal data", are small and specific: per-thread sorting labels, and the sender addresses of any sender rules you create on purpose.

Voice and text you give the assistant

When you talk or type to the SayMail assistant, your speech or text is streamed to our AI provider to understand and carry out what you asked. We do not keep recordings of your voice.

Usage Data

Usage Data is collected automatically when using the Service. It may include your device's IP address, browser type and version, the pages you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data. For the assistant, we also record usage counts such as the number of voice minutes and AI tokens used per day, so we can enforce plan limits and understand costs. These counts never include the content of your mail or your conversations.

Billing information

Subscriptions are billed through Stripe. Your card details are entered on and stored by Stripe, never by SayMail. We store the Stripe customer and subscription identifiers needed to know what plan you are on.

Tracking technologies and cookies

We use cookies and similar technologies to keep you signed in and to understand how the Service is used. The technologies we use may include:

  • Cookies or browser cookies. A cookie is a small file placed on your device. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. If you do not accept cookies, you may not be able to use some parts of our Service.
  • Web beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons that let us count users who have visited a page or opened an email.

Cookies can be "Persistent" or "Session" cookies. Persistent cookies remain on your device when you go offline, while session cookies are deleted as soon as you close your web browser.

We use both session and persistent cookies for the purposes set out below:

  • Necessary / essential cookies. Type: Session cookies. Administered by: Us. Purpose: These cookies are essential to provide you with services available through the Service and to enable you to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts.
  • Cookies policy / notice acceptance cookies. Type: Persistent cookies. Administered by: Us. Purpose: These cookies identify if users have accepted the use of cookies on the Website.
  • Functionality cookies. Type: Persistent cookies. Administered by: Us. Purpose: These cookies allow us to remember choices you make when you use the Service, such as your language or which mailbox you last viewed.

Data from your Google account

If you connect a Google account, SayMail requests the following permissions through Google's OAuth consent screen. You can review and revoke them at any time at https://myaccount.google.com/permissions.

  • See your email address and basic profile (userinfo.email, userinfo.profile, openid): to create your Account and identify which mailbox is which.
  • Read, compose, and send emails from your Gmail account (gmail.modify): to show your inbox and threads, summarize and sort mail, send the emails, replies, and forwards you write or dictate, archive threads, mark them read or unread, apply and manage labels, and download attachments you open or forward. SayMail never permanently deletes your mail.
  • See and download any calendar you can access (calendar.readonly): to check your availability when an email proposes a meeting time and to answer questions like "am I free Thursday at 3?".
  • View and edit events on all your calendars (calendar.events): to create, update, or cancel the events you schedule from an email thread.
  • See and download all your Google Drive files (drive.readonly), only if you connect Google Drive: to search your Drive by name or content and attach the file you pick to an outgoing email. SayMail never creates, edits, moves, shares, or deletes anything in your Drive.

We use this data only to provide the features you use inside SayMail. Specifically:

  • We do not use Google user data for advertising.
  • We do not sell Google user data.
  • We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
  • No human at SayMail reads your Google user data, except with your explicit permission to resolve a support request, when required for security purposes such as investigating abuse, to comply with applicable law, or as part of internal operations where the data has been aggregated and anonymized.
  • We transfer Google user data to third parties only as necessary to provide or improve user-facing features of the Service (for example, to our AI provider to generate a summary you asked for), to comply with applicable law, or as part of a merger or acquisition with notice to you.

SayMail's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Data from Microsoft and other connected services

If you connect a Microsoft account, SayMail requests the equivalent permissions from Microsoft: read and write access to your mail and calendar, and your basic profile. The same commitments in the section above apply to Microsoft user data. You can review and revoke the grant at https://account.live.com/consent/Manage.

If you connect an Integration such as Notion, Todoist, Linear, or Zoom, SayMail stores the access token for that service, encrypted, and uses it only to carry out the actions you ask for (for example, saving an email as a task or adding a meeting link to a reply). Data flows from SayMail to the Integration only when you trigger such an action. Each Integration's own privacy policy governs what it does with that data. You can disconnect any Integration from the Integrations page, which revokes SayMail's access where the provider supports it and deletes our stored token.

How the AI assistant processes your data

SayMail's assistant, summaries, sorting, and writing help are powered by models from OpenAI. When you use these features, the relevant content (for example, the thread you asked to summarize, or the speech you gave the assistant) is sent to OpenAI's API to produce the result and returned to you. We use OpenAI's API under terms that do not permit OpenAI to use this data to train its models. Sending is per request; we do not send your mailbox to any AI provider in bulk or in the background beyond what the feature you are using requires.

Use of your personal data

The Company may use personal data for the following purposes:

  • To provide and maintain our Service, including to monitor the usage of our Service.
  • To manage your Account: to manage your registration as a user of the Service.
  • For the performance of a contract: to provide the subscription you purchased and to bill you for it.
  • To contact you: by email, or through the mobile application's push notifications, about updates, security notices, and information related to the features and services you use, including reminders you asked the assistant to set.
  • To provide you with news and general information about goods, services, and events that we offer, unless you have opted not to receive such information.
  • To manage your requests: to attend and manage your requests to us.
  • For security and abuse prevention: to protect the Service, our users, and the providers we connect to.
  • For business transfers: to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, in which personal data held by us about our Service users is among the assets transferred.
  • For other purposes: such as data analysis, identifying usage trends, and evaluating and improving our Service. Mailbox and Integration content is never used for these purposes; only aggregated Usage Data is.

Sharing your personal data

We share your personal information only in the following situations:

  • With Service Providers that process data on our behalf to run the Service. Our current Service Providers are: Vercel (hosting), a managed PostgreSQL database provider (data storage), Upstash (short-lived operational data and background job queues), OpenAI (AI processing, as described above), Stripe (billing), Resend (transactional email such as receipts and reminders), and Sentry (error monitoring; reports are scrubbed of email content, tokens, and secrets before they are sent).
  • With the providers you connect: Google, Microsoft, and any Integration, when you use a feature that reads from or writes to that provider.
  • For business transfers: in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of our business to another company, with notice to you.
  • With Affiliates: in which case we will require those affiliates to honor this Privacy Policy.
  • With your consent: for any other purpose with your consent.

We do not sell your personal data, and we do not share Mailbox or Integration content with advertisers or data brokers.

Retention of your personal data

We keep your Account information and encrypted Mailbox and Integration tokens for as long as your Account exists and the connection is active.

Email content is not retained; it is fetched from your provider each time you use the Service and discarded after your request is served. The only mail-related records we keep are:

  • Sorting labels. For each thread the Service has sorted, we store the thread identifier, an importance level, a category, a short reason code, a content fingerprint, and the model version, so the inbox does not have to be re-sorted on every visit. No subject, sender, or body text is stored in this record.
  • Sender rules. If you tell SayMail to always treat a sender as important or routine, we store that sender's address, encrypted, so the rule can be applied. You can remove a rule at any time from Settings, which deletes the address.

Usage Data is retained for internal analysis for a shorter period, except when it is needed to strengthen security or improve the Service, or we are legally required to keep it longer.

When you disconnect a Mailbox or Integration, we revoke SayMail's access at the provider where the provider supports it and delete the stored tokens for that connection.

When you delete your Account, we revoke every Google and Integration grant we hold for you, then permanently delete your Account, your Mailbox and Integration connections, your sorting labels, and your sender rules from our database. Microsoft does not offer a programmatic revoke, so we recommend also removing SayMail from your Microsoft account's connected apps. We may keep billing records that we are legally required to retain.

Transfer of your personal data

Your information, including personal data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located, principally in the United States. It means that this information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

The Company will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy, and no transfer of your personal data will take place to an organization or a country unless there are adequate controls in place, including the security of your data and other personal information.

Delete your personal data

You have the right to delete or request that we assist in deleting the personal data that we have collected about you.

You can disconnect any Mailbox or Integration from within the Service, and you can delete your whole Account from Settings. You can also revoke SayMail's access directly from your Google or Microsoft account's permissions page at any time; the Service will stop working for that mailbox until you reconnect it.

You may also contact us at [email protected] to request access to, correct, or delete any personal information that you have provided to us. Please note that we may need to retain certain information when we have a legal obligation or lawful basis to do so.

Disclosure of your personal data

Business transactions

If the Company is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before your personal data is transferred and becomes subject to a different Privacy Policy.

Law enforcement

Under certain circumstances, the Company may be required to disclose your personal data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Other legal requirements

The Company may disclose your personal data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Company
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users of the Service or the public
  • Protect against legal liability

Security of your personal data

All traffic between your device, SayMail, and the providers we connect to is encrypted in transit. Mailbox and Integration tokens, and the sender addresses in your sender rules, are encrypted at rest with a key that is stored separately from the database, so a copy of the database alone cannot be used to reach your mailbox. Access to production systems is limited to the people who operate the Service.

No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

Children's privacy

Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from anyone under the age of 13 without verification of parental consent, we take steps to remove that information from our servers.

Links to other websites

Our Service may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Changes to this Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For material changes, we will also let you know by email or by a notice inside the Service before the change becomes effective.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact us

If you have any questions about this Privacy Policy, you can contact us by email at [email protected].

The last morning you spend typing email.

Give SayMail one morning and hear what an empty inbox sounds like.