Legal

Privacy Policy

Last updated: July 2026

anymail ("we", "us") is an AI email assistant operated by Creathink One, ul. Odkryta 11c/12, 03-140 Warsaw, Poland, NIP 5242921982 — the data controller. This policy explains what data we access, why, how we protect it, and your rights. anymail is built and operated in the European Union.

01

What we access

When you connect a Gmail or Outlook account, you grant anymail access via Google OAuth or Microsoft OAuth to read and organize your mail. We request the minimum scopes needed: reading messages, and creating and applying labels. For any other provider you connect over IMAP (Yahoo, Fastmail, iCloud, Zoho, GMX, your own server), you supply an app password instead, which we store encrypted. We do not request permission to send email on your behalf.
02

What we do with it

We process the sender, subject and a short snippet of each email to classify it into a category and, in the drafts beta, to generate a reply you can review. We apply labels in your mailbox and, for categories you mark "move out", archive the message from your inbox. On IMAP servers that do not support custom keywords, the category stays visible in anymail only. We never send email for you.
03

AI processing and sub-processors

To classify a message we send its sender, subject and snippet to an AI provider. If you supply your own API key, that processing runs under your account with that provider. Our sub-processors may include: Google (Gmail API), Microsoft (Graph API), the IMAP provider you connect, your chosen AI provider (e.g. DeepSeek, Anthropic/Claude, OpenAI), and our EU hosting provider (Hetzner). We do not sell your data and it is not used to train third-party models beyond fulfilling your own request.
04

What we store

We store the classification results and the fields needed to show your sorted inbox, your encrypted OAuth tokens or IMAP credentials, and — if you enable the drafts beta — a sample of your sent mail and a summary of your writing style, used only to draft replies for you.
05

Retention and deletion

You can disconnect a mailbox at any time from Settings, which removes anymail's stored data for that account. The labels remain in your mailbox; anymail simply stops accessing your mail.
06

Security

OAuth tokens are encrypted at rest. Access is on a least-privilege basis. See ourSecurity page for details.
07

Your rights (GDPR)

You may request access to, correction of, or deletion of your personal data, and object to or restrict processing. Contact us and we will respond within the timeframes required by law.
08

Google API disclosure

anymail's use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.
09

Cookies on this website

This policy covers the anymail product. The marketing site you are reading sets one cookie to remember your consent choice, and loads analytics or advertising cookies only for the categories you allow. The register of what is set, by whom and for how long is in theCookie Policy.
10

Contact

Requests under this policy: privacy@anymail.watch. The other public addresses, one per kind of question:hello@ for anything general,sales@ for plans and invoicing,support@ for a problem with the product, andsecurity@ for reporting a vulnerability — all at anymail.watch.