At Fyltre (“Fyltre,” “we,” “our,” or “us”), we are committed to respecting your privacy and keeping any information you share with us secure. This privacy policy explains how we collect, use, disclose, and process your personal data when you use our application, AI features, and related services (the “Service”) — and the data protection rights available to you under your country’s or state’s laws. By accessing or using the Service, you acknowledge that you have been informed of and consent to these practices.
Your personal workspace
Your communication environment should remain under your control while still enabling powerful AI assistance. Fyltre processes only the minimal data necessary to deliver intelligent, contextually aware results.
When Fyltre works on your behalf, only the data relevant to the task — the message being summarized, the thread being triaged — is securely transmitted to our AI partners solely to generate the result. Our AI partners are contractually prohibited from training models on your data.
Information we collect
- Account information — email address, name, and authentication credentials when you create an account.
- Usage data — how you interact with the Service, including features used and preferences.
- Communication context — email and message content temporarily processed to generate AI summaries, classifications, and draft replies. Raw bodies are not stored permanently: they are discarded after AI processing and re-fetched from your provider on demand.
- AI-generated data — summaries, priority scores, categories, and drafts generated for you, stored to provide the Service.
- Device information — browser type, operating system, and device identifiers for compatibility purposes.
- Integration data — OAuth tokens (encrypted with AES-256-GCM at rest) and metadata from connected services (Gmail, Outlook, Slack, Teams) necessary to provide the unified inbox.
- Audit logs — records of security-relevant actions (logins, data access, settings changes), retained for 90 days for security and compliance.
How we use your information
- Provide, maintain, and improve the Service
- Process and respond to your AI assistant requests
- Generate daily briefings and smart summaries
- Personalize your experience and remember your preferences
- Send you technical notices and support messages
- Detect, prevent, and address technical issues or abuse
- Comply with legal obligations
Cookies
Fyltre uses only strictly necessary cookies— the session cookies required to keep you signed in securely. That’s the whole list.
- Authentication cookies — set by our authentication provider (Supabase) when you sign in, used solely to maintain your session. They expire when your session ends and are deleted when you sign out.
We set no advertising, analytics, or tracking cookies, and no third-party cookies of any kind. Because strictly necessary cookies are exempt from consent requirements under GDPR and PECR, you won’t see a cookie banner on Fyltre — there is nothing to consent to. If this ever changes, we will update this policy and ask for your consent first.
Information sharing & subprocessors
We do not sell your personal data. We share information only with the following categories of processors:
- AI processing (OpenAI)— message content is sent to OpenAI’s API for summarization, classification, and draft generation. API data is never used to train models and is retained by OpenAI only within their limited abuse-monitoring window before deletion. See OpenAI Enterprise Privacy.
- Hosting (Vercel) — application hosting and serverless function execution. No persistent access to your data.
- Database (Supabase) — data storage with encryption at rest and automatic backups. EU region available.
- Rate limiting (Upstash) — Redis-based rate limiting. Stores only request counters, never content.
- Payments (Stripe) — payment processing. We never see or store your full card details.
- Legal requirements — when required by law, regulation, or legal process.
The full list lives at /security/subprocessors.
Your rights & choices
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data
- Object to or restrict certain processing activities
- Receive your data in a structured, portable format
- Withdraw consent at any time for consent-based processing
- Lodge a complaint with your local data protection authority
- Disconnect any integrated service at any time
To exercise these rights, contact our team — or simply use the export and delete controls in Settings.
California privacy rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights over your personal information. Fyltre honours these rights regardless of where you live.
- Right to know — request the categories and specific pieces of personal information we have collected, the sources, the purpose, and any parties we share it with.
- Right to delete — request deletion of the personal information we hold about you, subject to legal exceptions.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell or shareyour personal information for cross-context behavioural advertising, so there is nothing to opt out of. Because we never do this, we do not offer a “Do Not Sell or Share My Personal Information” toggle.
- Right to limit sensitive information — we only use the contents of your messages to provide the Service you asked for, never to infer characteristics about you.
- Right to non-discrimination — we will never deny service, charge a different price, or provide a different quality of service because you exercised a privacy right.
Exercising your rights. Use the export and delete controls in Settings, or contact our team. You may use an authorised agent to submit a request on your behalf, with proof of authorisation. We verify requests against the account email on file and respond within 45 days (extendable once by a further 45 days where permitted). California’s “Shine the Light” law does not apply because we do not share personal information with third parties for their own direct marketing.
Data retention
- Raw email/message bodies — discarded immediately after AI processing for handled conversations, and within 30 days otherwise. When you open an old conversation, content is re-fetched directly from your provider.
- AI summaries & classifications — stored for the duration of your account, or until the conversation is removed by our automated retention job.
- Automated cleanup — a daily retention job permanently deletes completed conversations past their retention window.
- Audit logs — retained for 90 days, then automatically purged.
- OAuth tokens — encrypted at rest with AES-256-GCM, deleted immediately when you disconnect an integration or delete your account.
You may request full deletion of your account and all associated data at any time from Settings. Server logs are retained for a 30-day rolling period for security, debugging, and abuse prevention.
Data security & encryption
We use technical and organizational measures appropriate to the sensitivity of your data. No internet transmission is 100% secure, but we hold ourselves to the standards below:
- All data in transit is secured with TLS 1.2 or higher
- Credentials at rest are encrypted with AES-256-GCM
- Access to personal data is restricted to authorized personnel and logged for auditing
- Every database query is scoped to your user — strict per-user isolation
The full picture is on our security page.
Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe we have, contact us immediately and we will delete it.
Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with an updated “Last updated” date. Continued use of the Service after changes constitutes acceptance.
Contact us
Questions about this policy or our data practices:
Fyltre Ltd — get in touch