Privacy Policy

Last updated: March 14, 2026

cmail (“we,” “us,” or “our”) operates the getcmail.com website and the cmail AI email co-pilot service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

1. Information We Collect

Account Information

When you create an account, we collect your email address, organization name, and subdomain. If you upgrade to a paid plan, we collect billing information through our payment processor, Stripe. We do not store full credit card numbers on our servers.

Email Data

To provide our AI email drafting service, cmail accesses incoming emails for accounts connected by your organization’s administrator. We process email content (subject lines, body text, sender/recipient information) to classify emails, generate AI drafts, and track pipeline stages. Email content is processed in real time and is not stored beyond what is necessary for classification and draft generation.

Usage Data

We collect information about how you interact with the Service, including pages visited, features used, draft approval/rejection rates, and classification accuracy metrics. This data helps us improve our AI models and user experience.

2. How We Use Your Information

  • To provide, operate, and maintain the cmail Service
  • To classify incoming emails into organizational buckets
  • To generate AI-drafted email replies in your company’s voice
  • To track email conversations through your sales pipeline
  • To improve our AI models through aggregated, anonymized usage patterns
  • To process payments and manage subscriptions
  • To send transactional emails (OTP codes, billing receipts, service updates)
  • To respond to support inquiries
  • To enforce our Terms of Service and protect against misuse

3. Data Storage and Security

Your data is stored on secure servers provided by Supabase (PostgreSQL) and hosted within the United States. We use industry-standard encryption for data in transit (TLS 1.3) and at rest (AES-256). Email provider credentials (OAuth tokens, IMAP passwords) are encrypted before storage using separate encryption keys.

We implement role-based access controls, audit logging, and regular security reviews. While we strive to protect your data, no method of electronic storage or transmission is 100% secure.

4. Third-Party Services

We share data with the following third-party services to operate cmail:

  • Supabase — Authentication and database hosting
  • Stripe — Payment processing and subscription management
  • OpenAI / Anthropic — AI model inference for email classification and draft generation
  • Resend — Transactional email delivery (OTP codes, notifications)
  • Vercel — Application hosting and edge network

We do not sell your personal information to third parties. We do not share email content with any party except AI providers strictly for the purpose of generating drafts and classifications, as described in this policy.

5. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (“right to be forgotten”)
  • Export your data in a portable format
  • Opt out of AI model training using your data
  • Withdraw consent for data processing

Organization administrators can delete team members, export organization data, or delete the entire organization from the admin dashboard. For individual data requests, contact us at the address below.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your organization, we will remove all associated data within 30 days, except where retention is required by law (e.g., billing records for tax compliance, which are retained for up to 7 years).

Email content processed for AI drafting is not retained after the draft is generated. Classification metadata and pipeline tracking data are retained as part of your organization’s operational data.

7. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:

cmail Privacy Team

Email: privacy@getcmail.com

Sensfix Inc.