Who we are and what this policy covers
EmailGPT is published by XIONAI COMPANY LIMITED, enterprise code 2902272132, Du Thinh Hamlet, Dong Hieu Commune, Nghe An Province, Vietnam. Contact us at hello@aurelight.com about this policy or your information.
This policy explains EmailGPT desktop and mobile applications and our hosted service. Sign-in options and AI features depend on the supported app version and deployment; descriptions of Google sign-in apply when that option is available and you use it. When your employer operates its own deployment, it manages that deployment's server, account administration and chosen service providers. Ask your employer for its privacy notice and any additional requirements before using company information.
EmailGPT synchronizes mail directly between your device and your mail provider and keeps a local mail cache. AI features send relevant content through the EmailGPT server to an AI provider. Account, billing, usage, company knowledge-base and support records are separate from mailbox synchronization.
Information on your device
Downloaded messages, drafts, search data, attachments, signatures, settings and cached AI results are stored locally. Your mail provider continues to hold your mailbox. Synchronization does not upload a complete mailbox copy to our server.
Stored passwords and OAuth credentials use protected credential storage: Electron safeStorage on desktop, including Windows DPAPI, and platform secure storage or the native sign-in service on mobile. This does not mean the entire local mail database is encrypted. Device security, backups and access by other device users affect the protection of local information.
The app also keeps technical logs. Information can leave the device through the AI, feedback, diagnostics and eligible contact-sharing functions described below.
Sign-in and mailbox permissions
- Google: Google handles sign-in; we do not receive your Google password. The app obtains your email address, Google account identifier and an identity token, which can include basic profile information. Our server verifies the identity token and associates your email address with Google's stable account identifier. Google's mailbox access tokens and refresh credentials remain on the client or in Google's native sign-in service; they are not sent to the EmailGPT server.
- Microsoft: Microsoft handles sign-in; we do not receive your Microsoft password. Our server verifies an identity token. Credentials used for mailbox access remain on the device.
- Mailbox password or app password: the client stores the credential in protected credential storage. It also sends it over TLS to the EmailGPT server when establishing or renewing a server session so the server can verify access with the mail provider. The server does not persist the mailbox password.
Google-connected mailboxes use full-mail permission for IMAP and SMTP. This supports reading and searching messages, folders and message state, attachments, and sending or deleting mail through the features you use or mail rules you configure. Sender and recipient information supports correspondence, including addressing messages; this is not a separate Google Contacts import.
Information held by the server
- Account and authentication: email address, display name, sign-in method, Google account identifier where applicable, role, status, timestamps, session-token hashes, and sign-in IP address and device or browser information. These support authentication, administration and revocation of sessions.
- AI usage: monthly request and token counts for quotas and reporting, with company subscription seat assignments and usage where applicable. Usage counters do not contain message bodies.
- Billing: customer and subscription identifiers, plan, status, billing periods, country, currency and transaction amounts. Paddle handles card payment details; EmailGPT does not receive your full card number. For prepaid VietQR bank transfers we also keep order codes, recipient information, verified bank transaction references, amounts, payment times, refund requests and refund audit records.
- Company knowledge base: documents uploaded by administrators are processed into extracted text and numerical search vectors, stored for AI Reply, and can be deleted by administrators. Relevant excerpts may be sent to the AI provider when answering a request.
- Support and eligible contact-sharing records: feedback, images, diagnostics and correspondent details described below.
AI processing and your choices
AI processing can include personal or confidential information present in the content you provide:
- Reply and Compose use your instructions and relevant message context, which may include subjects and sender details. Knowledge-base replies also use relevant company document excerpts.
- Translation and summarization use the message text or the selected attachment or document text.
- Briefings and conversation summaries use relevant subjects, sender information, dates and message content from the included correspondence.
Requests travel over TLS through the EmailGPT server to the provider. Knowledge-base search may also send text to create numerical representations called embeddings. Results return to the client and may be cached locally. The AI request handlers process mail content without creating a synchronized server mailbox or a database archive of AI request bodies. This does not eliminate provider retention, operational logs, or content you separately submit as documents or feedback.
For a mailbox connected using Google sign-in, automatic AI starts off. You can enable automatic processing for that mailbox in Settings. Depending on the client and enabled feature, this allows background translation or summaries to send relevant recent mail without a new button press. Turning the setting off prevents future automatic requests; it does not recall requests already sent. Explicit actions such as Translate or Generate continue to send the content needed for that action. Other sign-in methods follow their available AI settings.
Our operating policy is to use the Gemini Developer API under Paid Services terms for hosted generation and embeddings. If the applicable paid processing status cannot be established, we will suspend the affected hosted AI processing until it is confirmed. We will not enable optional sharing of customer prompts or responses for product improvement or training. A change of provider or data-use conditions requires review and updated disclosure before affected processing begins.
Under Google's Gemini API terms, Paid Services prompts and responses are not used to improve Google's products. Google's separate abuse-monitoring policy provides for retention of prompts, context and output for 55 days, authorized staff review of flagged data, and use for policy-enforcement models. That security use is distinct from training general-purpose models. We do not promise zero provider retention.
Customer-managed deployments may use a different provider. The operator must disclose and establish appropriate processing terms before enabling AI for personal or confidential mail. The Google-data restrictions below continue to apply to EmailGPT's handling of Google user data.
Google user data and Limited Use
EmailGPT's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We will use Google user data, including data derived from it, only to provide or improve the user-facing mail and AI features described here. We will not sell it, use it for advertising or prospect lists, or use it to develop, improve or train generalized AI or machine-learning models. We will not allow our service providers to use it for those purposes.
Transfers will be limited to providing or improving those user-facing features with your consent, necessary security purposes, applicable legal obligations, or a merger, acquisition or asset sale with your prior consent. We will apply these limits to service providers processing Google user data for EmailGPT.
Human access will be limited to specific information you affirmatively agree to share for support, necessary security investigations, legal obligations, or internal operations involving data aggregated and anonymized as permitted by Google's policy. A general acceptance of this privacy policy is not permission for unrestricted human reading of your mail.
Mailboxes connected with Google sign-in are excluded from EmailGPT's contact-contribution feature. Removing a mailbox or changing a setting does not itself erase historical records or material you separately submitted in a support report.
Feedback, diagnostics and contact sharing
Feedback. A report includes your message, selected images, account email, application version and operating-system information. If you include diagnostics, it also contains recent app log entries. Company administrators can read submitted reports and images. Review the material before submitting it: text and screenshots may contain mail or other personal information.
Diagnostic sharing. Technical logs describe app activity, failures, versions and technical context. They can contain identifiers, addresses or information included in error details; we do not represent them as guaranteed anonymous or free of personal information. Desktop diagnostic sharing is enabled by default and can be disabled in Settings. Mobile presents a sharing choice during first-run setup. Turning sharing off stops future uploads; it does not delete information already received.
Contact sharing. For eligible non-Google sign-in accounts, the app can contribute correspondent email addresses and names to your company's contact list when the company and app settings allow it. The company can export that list for its own outreach; EmailGPT does not send those invitations. Desktop contact sharing is enabled by default at the app level, subject to the company setting. Mobile presents the choice during first-run setup. You can change the app setting. Your company is responsible for its use of exported lists and for responding to requests about copies it holds.
Other recipients and international processing
Our hosting provider operates infrastructure holding the server data described above. Authorized service administrators access information as necessary for operation and support, subject to the limits in this policy. AI providers process the content sent for the selected features. Your mail and sign-in providers handle authentication and mailbox operations under their own policies; sending a message delivers it and its attachments to the chosen recipients.
Paddle processes purchases made through its checkout as Merchant of Record and handles checkout and billing information under its own privacy notice. We receive the subscription and transaction records described above. Where VietQR bank transfers are enabled, we send the order reference, amount and recipient details to VietQR to generate payment instructions and verify incoming transfers. EmailGPT does not ask for your banking password or banking login.
Providers may process information in countries other than where you live. The applicable providers, processing locations and transfer arrangements depend on the deployment. Contact us or your deployment administrator for those details before submitting information subject to location restrictions. We do not promise that AI requests remain within one country.
Website information
Our website serves product information and links to account, support and checkout functions. Requests to operate the website can include IP address and technical request information. Pages that load Google Fonts cause your browser to request font resources from Google. When you open a Paddle checkout, Paddle processes that interaction under its own policy. This policy does not describe those third parties' separate sites as being controlled by EmailGPT.
Retention, removal and deletion requests
Retention depends on the category and purpose:
- Local mailbox information and credentials: retained on your device until removed through app account or data controls or device storage tools. Uninstall and backup behavior varies by platform. Removing a local account does not delete your provider mailbox or your EmailGPT server account.
- Account, identity bindings, sessions and usage: used to operate the account, administer access and quotas, and investigate account issues. Ask us or your company administrator to delete the server account and associated information.
- Company documents: retained for the knowledge-base feature until an administrator removes them, subject to applicable backup and legal requirements.
- Billing: retained for transaction administration and applicable accounting, tax and legal obligations.
- Feedback, contacts and uploaded diagnostics: separate support and contact records are not all deleted when the account is deleted. We assess continuing operational or legal need and deletion requests separately for these categories.
- AI-provider data: subject to the provider handling described above. Stopping AI or deleting a local account does not automatically erase provider-held records.
Write to hello@aurelight.com to request deletion and identify the relevant account, deployment and categories, including support material where applicable. Do not send us your password. We may need to verify that you are entitled to make the request. Legal obligations and backup arrangements may affect what can be deleted and when; we will explain applicable limits when responding. Copies held by your employer, recipients, mailbox provider or another independently responsible organization may require a separate request.
You can revoke EmailGPT's Google access in Google Account connections. Revocation stops future access once existing authorization is no longer valid; it does not erase downloaded mail, prior AI requests or support submissions. Remove local data and request server-data deletion separately.
Your rights and contact
Depending on applicable law, you may request access to or a copy of your information, correction, deletion, restriction, portability or objection to processing. Where processing depends on consent, you can withdraw it for future processing using the relevant control or by contacting us. You may also have the right to complain to your data-protection authority, including in the EU or UK.
For our hosted service, contact XIONAI COMPANY LIMITED at hello@aurelight.com. If your employer manages the deployment or determines how workplace data is used, contact it as well; we will clarify the appropriate handling of the request.
Adults and business use
EmailGPT is intended for professional and business use by people aged 18 or older. It is not offered for use by children or minors. If you believe a minor has supplied personal information through the service, contact us so we can investigate and address it.
Policy changes
This policy takes effect on the date shown above. We will update it when material practices change. Where a change requires notice or consent, we will provide that before the affected new processing begins.
Contact
XIONAI COMPANY LIMITED (EmailGPT). hello@aurelight.com. Postal address: Du Thinh Hamlet, Dong Hieu Commune, Nghe An Province, Vietnam.