Your inbox contains sensitive information. We take that responsibility seriously with enterprise-grade security practices and transparent data handling.
Our commitment to protecting your data
We are committed to data privacy and integrity. Email PA only uses your email content to categorize messages and draft responses — never for any other purpose. Your data is never used to train AI models.
This page outlines our security practices and policies in detail, including how we identify and mitigate security risks, implement best practices, and continuously improve our security posture.
Key security measures that protect your data every day
We draft email responses, but cannot send emails without you pressing the send button. You always remain in control.
We have a Zero Data Retention agreement with OpenAI. Your email data is never stored on their servers or used to train their models.
All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Your email content is protected at every step.
Email PA is a verified Google application, meeting Google's security requirements for accessing Gmail and Google Workspace.
Hosted on Heroku, a Salesforce company, benefiting from enterprise-grade security, SOC 2 compliance, and world-class infrastructure.
Your data belongs to you. We can access it to provide the service, but you remain in control. Request deletion anytime.
Common questions about Email PA's security and data handling
We use the OpenAI API to enable AI features in Email PA. When you interact with these features, we share your email content with OpenAI, but only to provide you with the requested feature.
Your data is never used to train OpenAI's models or any other third-party provider.
We have a Zero Data Retention (ZDR) agreement with OpenAI, meaning your data is not stored on their servers after processing.
Email data: Email PA stores metadata and categorization information to provide the service. Email content is processed in real-time and not permanently stored beyond what's necessary for the service.
Account data: Your account information and preferences are stored securely in our encrypted database hosted on Heroku.
You do. Email PA can access your email data to provide the service, but you remain in control of your data. All data can be exported or deleted at your request. When you close your account, we promptly delete your data from our systems.
All data is processed on Heroku, a Salesforce company, which provides enterprise-grade physical security including 24/7 monitoring, access controls, and comprehensive environmental protections. For more details, see Heroku Security.
Third-party services that help us deliver Email PA securely
Cloud hosting by Salesforce. SOC 2 Type II certified.
Email categorization and drafts. Zero Data Retention.
Payment processing. PCI DSS Level 1.
Gmail API access via OAuth2.
We're happy to discuss our security practices in more detail or answer any specific questions about how we protect your data.