Privacy Policy

1. Introduction
At InstaMailAi Inc. (“we,” “our,” or “us”), your privacy is important to us. This Privacy Policy explains how we collect, use, and protect your personal data when you use our services.

2. Controller and Processor Roles
InstaMailAi Inc. acts as the data controller for personal data you provide to create and manage your account. For personal data submitted through integrations (such as connected email accounts), we act as a data processor, processing data solely on your behalf and in accordance with your instructions.

3. Information We Collect
We collect the following types of personal data:

  • Account Information: Name, email address, and payment information.

  • Usage Data: Log files, device information, and usage analytics.

  • Email Data: If you connect your email account (such as Google Workspace or Microsoft Outlook), we access metadata (e.g., sender, recipient, timestamps), subject lines, and email body text as needed for specific features. We do not store full email content unless necessary for requested functionality.

4. Legal Basis for Processing
We process personal data based on:

  • Consent: For features such as AI-based processing and connected email account access.

  • Contractual Necessity: To deliver services you sign up for.

  • Legitimate Interests: For internal administration, user support, and service improvement, where your rights do not override our interests.

5. Use of Connected Email Data & AI/ML Models
When you connect an email account (e.g., Google Workspace or Microsoft Outlook), we access only the data required to provide specific features (e.g., email categorization). We use AI and ML models to power features such as sentiment analysis. In doing so:

  • We may send email data including subject lines, body text, sender, and recipient information to third-party AI providers such as OpenAI.

  • This data is used only to deliver results specific to your account and is not used to train, develop, or improve generalized or non-personalized AI/ML models.

  • We do not use Google Workspace or Outlook data to train generalized models.

  • We require explicit user consent to enable these AI-powered features.

6. Third-Party AI Provider Data Retention
Our AI provider, OpenAI, may retain limited data for a short period to monitor for abuse and misuse, in accordance with their API terms. This data is not used to train OpenAI models and is not stored long term. For more details, refer to OpenAI’s API data usage policy.

7. Data Sharing with Third Parties
We do not sell your data. We may share your data with trusted service providers—including OpenAI, Stripe, Microsoft Azure, and MongoDB—for:

  • Cloud storage and infrastructure

  • Payment processing

  • AI-based feature functionality

All vendors are contractually obligated to protect your data and may not use it for their own purposes.

8. International Data Transfers
Some of our third-party service providers are located outside the European Economic Area (EEA), including in the United States. In such cases, we ensure adequate data protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, or

  • Participation in the EU-U.S. Data Privacy Framework (where applicable).

9. GDPR Rights
If you are in the EEA, you have the right to:

  • Access your personal data

  • Request correction or deletion

  • Restrict or object to processing

  • Request data portability

  • Withdraw consent at any time

To exercise your rights, contact us at [email protected]. You also have the right to lodge a complaint with your local data protection authority.

10. Data Security
We apply industry-standard technical and organizational security measures to protect your personal data against loss, misuse, or unauthorized access.

11. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes outlined here or comply with legal requirements. You may request deletion of your account and data at any time.

12. Cookies & Tracking Technologies
We use cookies and similar technologies to enhance your experience, analyze usage, and support key features. You can control cookies via your browser settings.

13. Your Rights & Choices
You can access, modify, or delete your data by contacting us. We will respond in accordance with applicable laws and timelines.

14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we’ll notify you through the service or by email. Your continued use after updates means you accept the new terms.

15. Contact Us
For any privacy-related questions or concerns, contact us at: Email: [email protected]

Effective Date: 3/24/25