Privacy Policy
Last updated: August 30, 2026
Speemail ("we", "us") is an AI-powered email assistant available at speemail.ai, with the application hosted at app.speemail.ai. This policy explains what data Speemail accesses, what it does with it, and the choices you have.
What we access
When you connect a mailbox, you grant Speemail access via OAuth — we never see or store your mailbox password.
- Gmail (Google APIs): read and modify messages and labels (
gmail.modify), send mail on your behalf (gmail.send), and read and create calendar events (calendar.readonly,calendar.events) so the assistant can show your agenda and send invites you approve. - Outlook / Microsoft 365 (Microsoft Graph): read mail, and — where you've consented — send mail, move messages, and read and create calendar events, so the assistant can show your agenda and send invites you approve.
Speemail accesses message content, headers, sender/recipient addresses, and labels/folders, only to provide the features you see in the app.
Signing in
Speemail accounts are created by the person who runs your Speemail installation. There is no public signup. You can sign in with an email address and password, or with Google or Apple sign-in. When you use Google or Apple, we receive only your verified email address, and only to match it against an account that already exists. Signing in with Google or Apple never creates an account. If you use Apple's Hide My Email, the relay address won't match your account: choose Share My Email, or ask whoever set up your account to use the relay address instead.
How we use your email data
- Classification — deciding whether an email needs your reply, or whether a sent email expects one.
- Drafting — generating suggested replies and follow-ups that wait in an approval queue. Nothing is ever sent without your explicit approval.
- Inbox cleanup & mail rules — suggesting archive/label/unsubscribe actions and running automations you create.
- Display — showing your inbox, threads, and activity statistics inside the app.
- Attachment safety checks — before you download an email attachment, Speemail inspects it locally. If VirusTotal is enabled, only the file's SHA-256 fingerprint is looked up; the file itself is never uploaded.
- Voice dictation (optional) — with voice enabled, your recorded clip is sent to Groq to be transcribed into text. The text fills the chat box; nothing is sent anywhere until you send it.
- Open tracking (on by default, off in Settings) — mail you send through Speemail can include a small tracking image. When a recipient's mail client loads it, we record the time and the client's user-agent string against your sent message, so you can see it was opened. We use this only to show you open status. We do not build profiles of your recipients.
We do not sell your data, use it for advertising, or share it with third parties except the service providers listed below. Humans at Speemail do not read your email, except with your explicit permission for support, where required for security investigation, or where required by law.
Google API Limited Use disclosure
Speemail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI processing
Email content is processed by Anthropic's Claude API to classify messages and generate draft text. Per our agreement with Anthropic, data sent to the API is not used to train Anthropic's models. We do not use your Google user data (or any mailbox data) to develop, improve, or train generalized AI or machine-learning models.
What we store
- OAuth tokens for your connected mailboxes (so Speemail can poll between visits).
- Message metadata, AI classifications, and draft text needed to run the approval queue, watched threads, and activity history.
- Your settings, tasks, chat history with the assistant, and feedback you give the AI.
Data is stored on our hosting provider's infrastructure (Fly.io) and transmitted over TLS.
The database is continuously replicated to encrypted object storage (Tigris, via Fly.io) for disaster recovery, and short-lived volume snapshots are kept. Where an installation has more than one user, each person's mail, drafts, tasks, and chat are isolated to their own account: one user cannot read another's.
Service providers
- Anthropic — AI processing of email content (no model training).
- Fly.io — application hosting and storage.
- Slack — only if you connect a Slack webhook, notification digests are posted to your chosen channel.
- Groq — speech-to-text for voice dictation; receives only the clips you record, and only if voice is enabled.
- VirusTotal — optional attachment safety lookups, by file fingerprint only, never the file.
- Stripe — payment processing for paid plans. Stripe receives billing details; we never store your card number.
Retention and deletion
Disconnecting a mailbox deletes its OAuth tokens and stops all polling. You can request deletion of all data associated with your account at any time by contacting us; we'll complete it within 30 days. AI usage logs are automatically pruned after 180 days.
The mobile app
The Speemail iOS app talks only to your Speemail server and handles the same data under this same policy. Signing in stores a device token on your phone so you stay signed in; signing out revokes it. The app collects no analytics and shows no ads.
Cookies
Speemail uses only functional cookies: a session cookie to keep you signed in and a cookie remembering which mailbox view is active. No advertising or cross-site tracking cookies.
Changes
If this policy changes materially, we'll note it here and update the date above.
Contact
Questions or deletion requests: support@speemail.ai