Privacy Policy
Last Updated: April 12, 2026
This Privacy Policy describes how Mailient Intelligence ("Mailient," "we," "us," or "our") collects, uses, stores, and protects your personal information when you use our email intelligence platform at mailient.xyz. By using Mailient, you agree to the practices described in this policy.
1. Who we are
Mailient is an AI-powered email intelligence platform founded and operated by Maulik. Our service connects to your Gmail or Google Workspace account (with your explicit permission) to help you triage, summarize, draft, and manage email communications more efficiently.
Contact: For all privacy-related inquiries, please reach out to us at mailient.xyz@gmail.com.
2. Scope of this policy
This policy applies to:
- All users of the Mailient website and web application at mailient.xyz
- Users who connect their Google or Google Workspace accounts to Mailient
- Users on Free, Starter, and Pro subscription tiers
- Visitors who browse mailient.xyz without creating an account
This policy does not apply to third-party websites, services, or applications that may be linked from our platform.
3. Information we collect
3.1 Account and identity information
When you sign up or log in via Google OAuth 2.0, we receive from Google: your full name, email address, and profile picture. We never receive or store your Google account password. Authentication is handled entirely and securely by Google's identity infrastructure.
3.2 Email data
To provide AI-powered inbox analysis, Mailient accesses your Gmail data through the official Gmail API, using the scopes you explicitly grant during OAuth. This may include: email subject lines, sender and recipient addresses, timestamps, email body content (for analysis and drafting), and thread metadata. This data is processed in real time or near-real time to deliver features such as Mailient Sift analysis, Arcus AI queries, smart drafts, and email summaries.
3.3 Usage and analytics data
We collect anonymized usage data to improve our service. This includes: features used, frequency of use, session duration, error logs, and browser or device type. This data does not contain email content and cannot be linked back to specific emails.
3.4 Notes and user-generated content
If you use the Notes feature, the content of notes you create is stored to enable access across sessions. Notes may be shared in text or image format as you initiate.
3.5 Subscription and payment information
If you upgrade to a paid plan (Starter at $7.99/month or Pro at $29.99/month), payment is processed by a third-party payment processor. We do not store your full credit card number, CVV, or raw financial information. We may retain your subscription tier, billing status, and anonymized transaction records.
4. How we use your information
We use the information we collect for the following purposes:
Service delivery
Powering AI inbox analysis, drafting, summaries, and smart triage via Sift and Arcus.
Personalization
Calibrating your neural voice style and relationship tracking to match your unique communication style.
Product improvement
Analyzing anonymized usage patterns to improve AI accuracy, feature quality, and reliability.
Security & compliance
Detecting and preventing abuse, fraud, unauthorized access, and policy violations.
Support & communication
Responding to support requests, sending essential service notifications, and providing updates.
Billing & subscriptions
Managing your plan tier, usage limits, and processing subscription renewals or upgrades.
5. What we do not do with your data
We do not sell your personal data — ever. Your email content and identity information are not sold to advertisers, data brokers, or any third party.
We do not use your data to train public AI models — your email content is never used to improve foundational or publicly shared machine learning models.
We do not send emails automatically on your behalf — all email sending actions require you to review and approve each message before it is sent.
We do not store your passwords — authentication is handled entirely through Google OAuth 2.0; we never see or store your Google credentials.
We do not serve advertisements — Mailient is a subscription product and is not supported by advertising. We do not allow advertisers to target you based on your email content.
6. Data security and encryption
We take the security of your data extremely seriously and have implemented multiple layers of protection:
- AES-256 encryption: Sensitive metadata and stored data is encrypted using AES-256, a military-grade encryption standard. Your decryption keys reside in your browser and never transmit to our servers.
- Zero-knowledge architecture: We store only encrypted blobs which we cannot read. Sensitive metadata is encrypted client-side before reaching our servers.
- Google OAuth 2.0: We authenticate users via enterprise-grade Google OAuth 2.0. Access tokens are scoped, time-limited, and can be revoked by you at any time via your Google account settings.
- Secure transmission: All data transmitted between your browser and our servers is encrypted via TLS (Transport Layer Security).
- Access controls: Internal access to user data is strictly limited to systems that require it to deliver the service. No human team member routinely accesses your email content.
- Breach notification: In the event of a data breach that affects your personal data, we will notify you and relevant regulatory authorities within the timeframes required by applicable law.
7. Google API services disclosure
Mailient's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This means:
- We only request the minimum permissions necessary to provide the features you use.
- Gmail data is used solely to deliver and improve Mailient's core email features.
- We do not transfer Gmail data to third parties except as necessary to provide the service, or as required by law.
- We do not use Gmail data for serving advertisements or for any purpose other than providing and improving the Mailient service.
- Humans at Mailient do not read your Gmail messages unless you explicitly share them for support purposes or as required by law.
- You can revoke Mailient's access to your Google account at any time by visiting myaccount.google.com/permissions.
8. Data retention
We retain your data only for as long as necessary to provide our service or as required by law:
- Email content and metadata accessed via the Gmail API is processed transiently and is not permanently stored on our servers beyond what is needed for the immediate analysis.
- Account information (name, email address) is retained for as long as your account is active.
- Notes you create are retained until you delete them or close your account.
- Usage analytics (anonymized) may be retained for up to 24 months for product development purposes.
- Billing records may be retained for up to 7 years as required by financial and tax regulations.
- Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
9. Sharing of information
We do not sell your personal data. We may share limited information only in the following circumstances:
- Service providers: We may engage trusted third-party vendors (e.g., cloud hosting, payment processors, analytics tools) who process data on our behalf under contractual data processing agreements and are not permitted to use the data for their own purposes.
- Legal compliance: We may disclose information if required to do so by applicable law, court order, or regulatory authority, or to protect the rights, property, or safety of Mailient, our users, or the public.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
We never share your Gmail data or email content with third parties for advertising, profiling, or any commercial purpose beyond service delivery.
10. Your rights and choices
Regardless of where you are located, you have the following rights regarding your personal data:
Access
Request a copy of the personal data we hold about you.
Correction
Request correction of inaccurate or incomplete information.
Deletion
Request deletion of your personal data (right to be forgotten).
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to certain types of processing, including profiling.
Revocation of consent
Withdraw access permissions granted to Mailient at any time.
To exercise any of these rights, contact us at mailient.xyz@gmail.com. We will respond within 30 days. You may also revoke Google access permissions at any time via your Google account settings at myaccount.google.com/permissions.
11. Cookies and tracking technologies
Mailient uses minimal cookies and similar technologies to operate the service:
- Essential cookies: Required to maintain your login session and ensure the application functions correctly. These cannot be disabled without breaking the service.
- Analytics cookies: We may use anonymized, aggregated analytics (e.g., page views, feature usage) to understand how users interact with Mailient. No email content is included in these analytics.
We do not use advertising cookies, cross-site tracking cookies, or third-party behavioral tracking technologies.
You can manage or delete cookies via your browser settings. Disabling essential cookies will prevent you from using the application.
12. International data transfers
Mailient is operated globally and your data may be processed in countries other than your country of residence. We ensure that any international transfer of personal data is subject to appropriate safeguards in accordance with applicable data protection laws, including standard contractual clauses or equivalent measures where required. By using Mailient, you acknowledge that your data may be transferred to and processed in countries with different data protection standards than your own.
13. Third-party services and integrations
Mailient integrates with or relies on the following categories of third-party services:
- Google (Gmail API & OAuth): Core to our service. Google's privacy policy governs their data handling at policies.google.com/privacy.
- Payment processors: Used to handle subscription payments. They do not receive your email content.
- Cloud infrastructure providers: Used to host and operate our service securely.
- AI model providers: We may use AI APIs to power features such as drafting and summarization. Any data sent is subject to data processing agreements and is not used for model training on our users' data.
We carefully vet all third-party processors and ensure they operate under data processing agreements consistent with this Privacy Policy.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you by email or in-app notification for significant changes
- Where required by law, seek your renewed consent before the changes take effect
We encourage you to review this policy periodically. Continued use of Mailient after changes are posted constitutes your acceptance of the updated policy.