← Back to home

Privacy Policy

Last updated: September 13, 2026

Who we are

MailGeni ("we", "us") is operated by Imran Malik, an individual founder based in Qatar. We provide an AI email assistant delivered as a web application at mailgeni.ai and as a browser extension for Gmail and Outlook. This policy describes the data we collect, why we collect it, and the choices you have.

Data we collect

  • Account data. Your email address and name, managed by our authentication provider (Clerk).
  • Email provider tokens. When you connect Gmail or Outlook, we store OAuth refresh tokens so the extension and web app can read the thread you have open and send replies on your behalf. Tokens are stored encrypted at rest in our database (Supabase).
  • Email content, in transit only. The thread you are replying to is sent to our servers and to our AI provider (Anthropic) to generate the draft. We do not store email bodies after the draft is returned.
  • Voice dictation. When you tap the microphone, we send the captured audio to our transcription provider (Google, via the Gemini API) to return text, and the resulting text to Anthropic to tidy up filler words and self-corrections. Audio is not retained after transcription.
  • Preferences. Your signoff, UI language, and chip preferences are stored locally via chrome.storage.local and mirrored in our database so they follow you between devices.
  • Open-tracking pixels. Emails you send via MailGeni may include a 1×1 pixel so you can see when a recipient opens the message. We store the recipient address, subject, send timestamp, Gmail thread ID or Outlook conversation ID, open count, and first/last open timestamps. You can disable the pixel per-message.
  • A mail index.To answer “find the email from…” questions, we keep an index of the sender, recipients, subject line, date and message ID of mail in a connected mailbox for the last 36 months. No message body, snippet or attachment is stored. The index is deleted when you disconnect the mailbox or delete your account.
  • Your past replies, de-identified.When you answer a customer’s request, we keep a short record of what was asked (in general terms), the items and prices your reply quoted, and your reply as a template with the customer’s name, dates, addresses and reference numbers removed, so that a similar request can be answered the same way. The customer’s email is not kept. The newest 500 per business, for twelve months; you can forget any or all of them in the Memory tab, and they are deleted with the mailbox connection or the account.
  • Finding similar past work.We keep each invoice and quotation you send (its lines, terms and covering note, and a short line on what it was for with the customer’s details removed), and Google (Gemini API) computes a numeric representation of it, and of your de-identified replies, so that a similar past document can be found when a new request arrives. That representation cannot be turned back into the text. Kept for 36 months and deleted with your account.
  • Receipts you file.When you file an email under Receipt, we read it once — the message and any attached PDF or photo of a receipt — and keep one line in your receipt log: merchant, date, total, tax, reference and category. The text and the attachment go to our AI provider (Anthropic) to be read, under zero-retention API terms, and we do not store them. The log is yours to download and to delete line by line, and goes with your account.
  • Calendar events you create. When you use the Schedule Meeting feature, we forward the title, attendees, date/time, and optional Google Meet or Microsoft Teams link request to Google Calendar or Microsoft Graph. We do not store a copy on our servers.

Data retention

  • OAuth tokens and preferences — kept until you disconnect the provider or delete your account.
  • Email bodies sent for AI generation — not stored; held only in memory for the duration of the request.
  • Voice audio — not stored; streamed to the transcription API and discarded.
  • Tracked-email metadata (thread ID, open count, timestamps) — kept until you delete your account or ask us to remove a row.
  • Documents you send for e-signature — the PDF you send, the signed copy, the signature images the signers draw, and the signing record (who signed, when, from which address) are kept in private storage for the life of your account. You can delete any finished request from Docs › Library. Signers reach a document only through a one-time link that expires after 30 days, and every party is emailed the signed copy.
  • Invoices and quotations you build — the PDF, the figures on it, and the addressee are kept in private storage for the life of your account, so the library, the reminders and “mark as paid” work. You can delete any settled one from the library. Your business details, bank details and logo are saved once to your account preferences.
  • Documents you sign yourself — not stored. The signed copy goes into your reply or your downloads. A copy parked to get past an upload limit is deleted the moment the reply exists, and anything abandoned is swept within a day.
  • If your subscription lapses — nothing is deleted. Your documents stay, read-only: you can open, download and export them. Creating new ones beyond the free allowance, and the automatic reminders, stop.
  • Dormant accounts — an account with no sign-in for three years may be closed. We send three notices over ninety days first, each with a one-click export of everything, and signing in at any point keeps the account open.
  • Account deletion — all of the above is erased within 30 days of a deletion request. Export your documents first from Docs › Library, as one zip with the PDFs, the signing records and a list; we cannot recover them afterwards.
  • One-way record of a completed free trial — the single exception to the line above. When your free trial starts we store a salted one-way hash of your sign-up email address, so that the same person cannot obtain unlimited free trials by deleting and re-registering. This hash is kept after your account is deleted. It cannot be reversed into your email address, cannot be used to contact you, is not linked to your account or to any other record we hold, and is never shared. It is the only thing that survives deletion of your account.

What we do with it

  • Generate AI replies, summaries, and transcriptions you explicitly request.
  • Categorize inbox messages into the labels shown in the dashboard.
  • Authenticate you and keep you signed in across the web app and extension.
  • Sync your preferences and signoff across devices.

We do not sell personal data. We do not use your email content to train AI models. Anthropic and Google process content under their respective API terms and do not retain it for training.

Google API Services User Data Policy — Limited Use

MailGeni's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Gmail data to provide or improve user-facing features that are prominent in MailGeni's user experience (reading the currently open thread, generating an AI reply, sending the reply).
  • We do not transfer Gmail data to third parties except as necessary to provide or improve those features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not use Gmail data to serve advertisements, including retargeted, personalized, or interest-based advertising.
  • We do not allow humans to read Gmail data unless we have the user's affirmative agreement for specific messages, it is necessary for security investigations or to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
  • Gmail message bodies are sent to our AI provider (Anthropic) solely to generate the reply you requested, under zero-retention API terms, and are not stored by MailGeni after the draft is returned.
  • Attachments you ask MailGeni to summarise, classify, sign or answer questions about (for example PDF and Word documents) are sent to Anthropic for that request only, under the same terms, and are not stored by MailGeni.
  • Audio captured for voice dictation is sent to our transcription provider (Google, via the Gemini API) solely to return transcribed text, and that transcript is then sent to Anthropic solely to clean it up. Neither is stored by MailGeni or used to train models.

Our commitments

The data you give MailGeni access to is yours. Specifically:

  1. We do not sell or rent your data. Not to advertisers, not to data brokers, not to anyone.
  2. We do not serve advertising of any kind, including retargeted, personalised, or interest-based ads, against your Gmail / Outlook content or any data derived from it.
  3. We do not allow humans to read your email content as part of normal operation. No member of MailGeni or our sub-processors reads, reviews, or annotates your messages, except (a) where you explicitly direct us to do so for support, (b) where it is necessary for security investigations, (c) where required by applicable law, or (d) where the data has been aggregated and de-identified for internal operations.
  4. We do not train AI models on your data. Our AI sub-processors (Anthropic and Google) are contractually prohibited from using API content for training under their respective Commercial Terms / API data-usage policies, and we do not opt into any training-related program with either provider.
  5. Email content is not retained on our servers. When you click Generate, Summarize, Categorize, or Dictate, the relevant content (subject + body, or the audio clip) is held only in the memory of the function that handles your click. As soon as the response is returned to you, those bytes are dropped. The only email-related data we persist is metadata about emails you explicitly send through MailGeni — recipient address, subject, timestamp, and open counts if you enabled tracking — and only until you disconnect the provider or delete your account.
  6. We do not transfer Gmail or Microsoft Graph data to any party other than our named sub-processors, except as necessary to provide the user-facing features described in this Privacy Policy, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.

Microsoft identity and Microsoft Graph data

When you connect an Outlook account, MailGeni acts as a Microsoft identity client and calls Microsoft Graph on your behalf. We request the following delegated scopes and use them only for the features they enable:

  • User.Read, openid, profile, email — identify you and display your name and email in the dashboard.
  • offline_access — obtain a refresh token so the extension keeps working without repeated sign-in prompts.
  • Mail.Read, Mail.ReadWrite — read the thread you have open so the AI can draft a reply to it.
  • Mail.Send — send the reply you compose in the MailGeni panel.
  • Calendars.ReadWrite — create calendar events, optionally with a Microsoft Teams link, when you use the Schedule Meeting feature.

Outlook message bodies are sent to Anthropic solely to generate the reply you requested, under zero-retention API terms, and are not stored by MailGeni after the draft is returned. Attachments you ask MailGeni to summarise, classify, sign or answer questions about are sent to Anthropic for that request only, under the same terms, and are not stored by MailGeni. We do not use Microsoft Graph data to serve advertising and do not transfer it to unrelated third parties.

Sub-processors

  • Clerk — authentication and session management.
  • Supabase — database, encrypted token storage.
  • Anthropic (Claude) — generates AI replies, summaries, categories, document analyses, and the cleanup pass on voice-dictation transcripts. We send Anthropic the subject and body of the email thread you have explicitly opened in MailGeni, plus your instruction if you provided one. We never send your full inbox or other threads. Anthropic does not use API content to train its models. See Anthropic Privacy Policy, Commercial Terms, and Anthropic Trust Center.
  • Google — transcribes audio when you tap the dictation microphone in MailGeni (Gemini 2.5 Flash, via the Gemini API). We send Google the audio recording and a short vocabulary hint: a list of proper nouns drawn from your contacts and from the email you are replying to, so names spell correctly. It is a list of terms, never the message itself. Google does not use Gemini API content to train its models. This is a separate service from the Gmail access described above, under separate terms. See Gemini API terms.
  • Google / Microsoft — OAuth, Gmail API, Microsoft Graph for sending mail you compose.
  • Vercel — hosting.
  • Upstash — Redis-backed rate limiting on AI and mailbox-write endpoints.

Primary processing region: Mumbai, India (ap-south-1). Anthropic and Google AI are processed in their providers' default US regions. Where data crosses borders, all sub-processors are bound by Standard Contractual Clauses (or equivalent transfer mechanisms) under their respective Data Processing Agreements.

Permissions the extension requests

  • storage — persist your signoff, language, and chip preferences locally.
  • tabs — open the settings and billing pages in a new tab when you click them from the panel.
  • Host access to mail.google.com, outlook.live.com, outlook.office.com, outlook.office365.com, outlook.cloud.microsoft — inject the reply panel into those pages.
  • Host access to the MailGeni web app domain — pass your authenticated session from the web app to the extension.

Your choices and rights

  • Disconnect Gmail, Google Calendar or Outlook at any time from the Settingspage. Disconnecting clears the stored refresh token and, for Google providers, calls Google's revoke endpoint so MailGeni's access is also removed at myaccount.google.com.
  • Delete your account in-app from Settings → Delete account. This immediately erases your profile, OAuth tokens, tracked-email rows, memory and preferences, revokes Google access, and deletes your authentication record at Clerk. No email request is required.
  • You can also request deletion by emailing privacy@mailgeni.ai and we will complete it within 30 days.
  • EU/UK residents have the right to access, correct, and erase their data under GDPR. Use the same contact address.
  • India residents have the rights set out under the Digital Personal Data Protection Act 2023 (DPDPA), including access, correction, erasure, and grievance redress. Use the same contact address; we treat all such requests as we would a GDPR request.
  • Turn off open tracking per-message when composing.

Operator and applicable law

MailGeni is operated by an individual founder based in Qatar. Personal data handling is governed by Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016, "PDPPL"), with additional protections applied for users domiciled in the EU/UK (GDPR) and India (DPDPA 2023). Cross-border transfers to sub-processors are made under Standard Contractual Clauses or equivalent transfer mechanisms set out in their respective Data Processing Agreements. The supervisory authorities relevant to MailGeni are:

  • Qatar — National Cyber Security Agency (NCSA), via ncsa.gov.qa.
  • EU/UK users — your local supervisory authority (e.g. the ICO for the UK, ico.org.uk).
  • India users — Data Protection Board of India (DPBI) once constituted under the DPDPA 2023.

Security

Traffic is served over HTTPS. OAuth tokens are stored in a Supabase database with row-level security and access restricted to the service role key, which is never exposed to clients. Session cookies are issued and validated by Clerk.

Cookies

MailGeni sets only cookies that are strictly necessary to run the service. There is no advertising, analytics or cross-site tracking cookie anywhere in the product, and no third-party analytics script is loaded.

The cookies in use are: a session cookie issued and validated by Clerk, which keeps you signed in; mg_next, set for ten minutes when a mailbox connection starts from the welcome flow so you are returned there afterwards; mg_add_hint, set for fifteen minutes while you add a mailbox, so the app can tell you afterwards whether the account you connected is the one you asked for; and mg_oauth_state, set for ten minutes during a mailbox or calendar connection so the callback can confirm the round trip belongs to the signed-in account.

Because these are strictly necessary, UK and EU rules do not require a consent banner for them, and we do not show one. If we ever add a cookie that is not strictly necessary, we will ask for consent before setting it.

We measure how our own website is used — which pages are viewed and which buttons are pressed — first-party, with no cookie and no third-party service. A random identifier in your browser's sessionStorage links the pages of one visit and is discarded when the tab closes; it is not shared with anyone and identifies no one. Browsers that send Global Privacy Control are not measured at all. Nothing you type is recorded.

Children

MailGeni is not directed at children under 13 and we do not knowingly collect their data.

Changes

We will update this page if our data practices change, and update the "Last updated" date at the top. Material changes will be communicated by email.

Contact

Questions, deletion requests, or concerns: privacy@mailgeni.ai