Sign in

Privacy

Applies to em[ai]l. at eml.ai · Last updated 27 September 2026

In short

  • We process the mail you forward so the agents you connect can read it. We do not sell personal data, use it for advertising, or use your mail to train AI models.
  • The service never receives access to your mailbox, only the messages delivered to your aliases.
  • Stored mail is encrypted and deleted on the retention schedule you choose; deleting an address destroys its keys.
  • Site analytics are cookieless, and product analytics use a pseudonym instead of your identity.

The sections below are the operative description. This list is a reading aid.

1.Who we are

em[ai]l. is operated by Subnets LLC in the United States. Subnets LLC decides how the personal data described here is used. Write to support@eml.ai with any question about this notice or your data.

2.What we collect

Account. When you sign in with Google we receive your name, email address, profile picture and Google account identifier; we receive no access to your mailbox. We record when you started the trial, which confirms that you are 18 or older and live in the United States, and which version of the terms you accepted. We keep the email addresses you forward from, starting with your sign-in address.

Mail. We receive every message delivered to your aliases, whether you forwarded it or someone sent it directly, including attachments. We also store the drafts your agents save and the progress labels they set. When our email provider refuses a message before delivery, we record only the alias, a reason and the time.

Agent connections. We record the agents you connect, including the name and details each agent supplies when it registers, the keys you create (stored as hashes) and an access log of each agent request: the time, the connection, the tool and a keyed hash of the request, not message content.

Billing. Paid plans are handled by Stripe. We keep your plan, Stripe customer and subscription references, and billing and credit records. Stripe, not us, receives your card and any billing details its checkout asks for.

Technical data. Our servers see your IP address and browser details when you use the site and the app. We store the IP address and browser of each sign-in with that session, use IP addresses to limit abuse, and our hosting providers keep request logs.

3.How we use it

We use this data to run the service: to deliver your mail to the agents you authorize, mask your own address before an agent reads a message, send you the notices you need (such as refused mail, billing confirmations and draft copies you enable), bill paid plans, answer support requests, and protect the service and its users from abuse. We are notified by email when an account is created. Our administration tools show account and billing details, not message content.

We measure how the product is used with a small, fixed set of milestones, such as an address being created or an agent connecting, recorded under a keyed pseudonym rather than your identity. We do not sell personal data, share it for advertising, or use your mail to train AI models.

4.Who receives it

Your agents. An agent you connect receives the mail it reads, and so does the company that runs that agent, under your own agreement with it. Disconnecting an agent stops further access; it cannot recall what the agent already read.

Service providers. Google Cloud hosts the application, database, encrypted storage, key management and logs in the United States, and Google provides sign-in. Cloudflare provides DNS, receives and routes inbound mail, sends our notices, serves images and video, and counts visits to the public pages. Stripe handles payments. Sentry receives limited error reports, and PostHog receives the pseudonymous product milestones. Each receives only what its role needs, some process data outside the United States, and each keeps its own records under its own retention.

Legal reasons. We disclose data when the law requires it, or to protect the rights, safety and security of our users, the public or the service. If the service changes ownership, this notice continues to apply to the data it covers.

5.How long we keep it

Each address keeps mail for the retention period you choose within your plan, and expiry is automatic. Drafts expire within 24 hours, the agent access log keeps 90 days, and records of refused mail keep 30 days. Deleting an address destroys the keys its mail was stored under; a keyed record of the retired alias, without content, remains so it is never reissued. Database backups are kept for seven days, so deleted data, with mail content still encrypted, can remain in them for up to seven days.

Deleting your account removes your account, aliases, mail and agent connections. We keep limited billing and credit records, with a keyed, one-way lookup of your sign-up email so support can find them, for as long as we need them for accounting, tax and disputes. Provider logs, error reports and analytics follow those providers’ retention, independent of your mail.

6.Your choices

In the workspace you can change retention, turn address masking on or off, disconnect agents, revoke keys, and pause or delete an address. Paid accounts can export their mail. You can delete your whole account, or ask support to delete it. Removing your forwarding filter stops mail at the source.

You can also ask us what personal data we hold about you, or ask us to correct or delete it, at support@eml.ai. We will not treat you differently for asking.

7.Cookies and browser storage

The public pages set no cookies. The app sets the cookies needed to sign you in, which last up to 30 days, and your browser remembers your light or dark theme choice. Entering payment details loads Stripe’s payment form, which may use its own cookies to process payment and prevent fraud. We use no advertising or cross-site tracking cookies.

8.Eligibility

The service is for people who are 18 or older and live in the United States. It is not directed to children, and we close accounts that do not meet these conditions. Do not forward regulated or health data; the terms explain why.

9.Changes and contact

We update this notice when our practices change and revise the date above. Material changes are announced in the workspace before they take effect. The security model describes how the service protects the data described here.