Français

Privacy policy

Last updated: August 11, 2026.

EquiMail (“we”) is an email assistant that sorts, cleans up and helps reply to its users’ email. Protecting your data is central to the product: this page sets out exactly what we collect, why, and what your rights are (GDPR).

1. Data we collect

  • Account data: name, email address and profile picture passed on by Google or Microsoft during OAuth sign-in, or the email address you supply when registering.
  • Mailbox data: when you connect a Gmail or Outlook mailbox, we import recent messages from your inbox (sender, subject, body, headers) in order to categorise them, detect newsletters and cold outreach, track awaited replies and apply your rules.
  • OAuth access tokens: encrypted at rest (AES-256-GCM). We never see your password.
  • Billing data: handled by Stripe; we store no bank card details.
  • Calendar (optional): if you connect your calendar (private ICS address), that address is encrypted at rest and is never sent back to your browser.
  • Writing style (on by default, can be switched off): when you ask for a draft, we read your most recent sent emails — yours, never the ones you receive — to derive a short style sheet: greeting, register (formal or first-name basis), usual length, sign-off, characteristic turns of phrase. One sheet per correspondent you have written to at least three times, plus one general sheet for your account. Only that description is kept: no excerpt, no name, no conversation topic. You can switch this learning off in Settings → Draft tone; switching it off erases the sheets already learned.

2. How we use the data - and what we do not do

Your mailbox data is used solely to provide the features you switch on: categorisation, unsubscribing, cold outreach detection, reply tracking, drafts. We do not sell your data, we do not use it for advertising, and no human accesses the content of your emails, except at your explicit support request or where legally required.

Google Workspace APIs — Limited Use: EquiMail’s use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. That data is never sold, never used for advertising, and never used to train general-purpose AI models. It is disclosed to our processors only to the extent required by the features you switch on — see sections 3 and 4.

3. Processing by artificial intelligence

The AI features (categorisation, cold outreach detection, summaries, translation, drafts) rely on language models. To run them, the content of the emails concerned — sender, subject, body and headers — is sent to our AI processor, solely to produce the requested result and for no other purpose. That disclosure is inherent to the feature: without it, none of these functions can be delivered.

Our AI processing runs through an AI infrastructure provider established in the European Union, on an EU endpoint with processing within the European Union, under a data processing agreement (DPA), and with no reuse of your content to train its models. The up-to-date named list of our processors — legal entity, region and models used — is published on our Subprocessors page.

Your controls. AI processing rests on your express consent, requested per purpose: sorting and cold outreach detection, summaries, translation, drafting. No processing is active without a recorded consent, and every consent can be withdrawn at any time in Settings → AI consents. You can also exclude a sender (or a whole domain), a folder or a keyword from AI processing, and switch AI off entirely with a global toggle: an excluded message is never sent to a model.

Model outputs are proposals (a classification, a piece of text) that you remain free to change or ignore: they are not automated decisions producing legal effects concerning you.

4. Hosting and processors

  • Application: Railway Corp. (application hosting).
  • Database: Neon Inc. (PostgreSQL, Europe region — eu-west-2).
  • AI processing: AI infrastructure provider established in the European Union (EU endpoint, processing within the European Union).
  • Payments: Stripe Payments Europe Ltd.
  • Email APIs: Google LLC (Google Workspace APIs / Gmail), Microsoft Corporation (Outlook / Graph).
  • Transactional service email: Resend.

The named, up-to-date list of these processors is published on our Subprocessors page. It is kept separate precisely so that it can be updated whenever a provider or a model changes, without rewriting this policy.

5. Retention period

Mailbox data is kept for as long as the mailbox stays connected. Removing a mailbox from Settings immediately erases the imported emails, senders and related analyses. Deleting your account (Settings → Danger zone) immediately erases all data and cancels any active subscription.

Specific periods applying to data produced by AI processing:

  • Cold outreach detection rationales: the explanatory text the model produces to justify a verdict is erased automatically 30 days after it is created. Only the verdict itself (category, score, decision) is kept afterwards, for as long as the mailbox stays connected.
  • AI processing consents: a consent is valid for 365 days (one year). Beyond that it is treated as expired and the corresponding processing stops on its own until you renew it. The consent record (grant date, withdrawal date) is kept for as long as the account exists, as evidence of compliance.

6. Your rights (GDPR)

Under Regulation (EU) 2016/679, you have the right of access, rectification, erasure, restriction, portability and objection. You can also revoke EquiMail’s access at any time from the security settings of your Google or Microsoft account. To exercise your rights: contact@equimail.fr. You may lodge a complaint with the CNIL, the French data protection authority (cnil.fr).

Without waiting for you to act, EquiMail itself revokes its Google access grant (OAuth token) with Google when you disconnect a Gmail mailbox and when you delete your account. Microsoft exposes no server-side equivalent: for Outlook, revocation is done from your Microsoft account settings.

7. Cookies

EquiMail only uses cookies that are strictly necessary to operate: authentication session, active mailbox, display language and OAuth flow security. No advertising or third-party tracking cookies.

8. Contact

Data controller: Equinox AI (sole proprietorship Da Cunha-Magnolia, SIREN 810 926 691, 17 Rue Roger Fremeaux, 68420 Voegtlinshoffen, France) — contact: contact@equimail.fr.

9. Governing version

This page is an English translation provided for convenience. In the event of any discrepancy or dispute, the French version of this policy prevails.

Politique de confidentialité — EquiMail