Privacy Policy
Last updated: August 9, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
Airo Mail accesses data from email and other accounts You choose to connect, including Gmail and Microsoft accounts and, where You enable applicable features, Google Calendar and Google Drive. Connected-account data may include email content, metadata, attachments, labels, contacts, calendar information, files, and permissions. We use this data solely to provide and improve the user-facing features You request. We do not use connected-account data for advertising or share it with third parties except as described below, and never for their own marketing or advertising purposes.
We use Your Personal Data to provide and improve the Service. This Privacy Policy is a notice describing Our practices; where applicable law requires consent for a particular activity, We will request that consent separately.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- Account means a unique account created for You to access our Service or parts of our Service.
- Affiliate means an entity that controls, is controlled by or is under common control with a party, where “control” means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
- Application refers to Airo Mail, the software program provided by the Company.
- Connected Account Data means data obtained from or submitted through an account You choose to connect to the Service, including email, calendar, contact, and file-storage accounts.
- Company (referred to as either “the Company”, “We”, “Us” or “Our” in this Privacy Policy) refers to Airo Intelligence, Inc., a Delaware corporation, at 2261 Market Street, Ste 67792, San Francisco, CA 94114.
- Country refers to the United States.
- Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
- Google refers to Google LLC.
- Google API Services refers to Google LLC’s APIs, services and tools that the Application may utilize.
- Gmail refers to Google’s email product, Gmail.
- Personal Data is any information that relates to an identified or identifiable individual.
- Service refers to the Application, Our website at airo.email, the web application, mobile applications, support services, and other related products and services that link to this Privacy Policy.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
- Third-Party Service refers to any third-party website, application, account provider, or platform through which You may log in, connect with, or use a feature of the Service.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
- GDPR refers to the General Data Protection Regulation (EU) 2016/679, a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area.
- Data Controller refers to the natural or legal person who determines the purposes and means of processing Personal Data. We generally act as Data Controller for account, billing, security, support, and product-operations data. Where an organization uses the Service and directs Our processing of its mailbox or other connected content, We may act as its processor or service provider for that content.
- Data Subject means any living individual who is using our Service and is the subject of Personal Data.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
- Email addresses
- First name and last name
- Profile pictures
- Usage Data
- Billing Address
- Connected Account Data, including email and calendar content and metadata, attachments, contacts, labels, files, sharing permissions, and account identifiers
- Authentication credentials and OAuth tokens
- Prompts, instructions, feedback, support communications, AI-generated outputs, classifications, summaries, recommendations, and other information derived to provide Service features
Email Messages
We integrate with Gmail and Microsoft email services to synchronize, process, and, where necessary for the features You use, temporarily store Your email messages, metadata, attachments, contacts, folders, and labels. Email and attachment content may incidentally contain sensitive Personal Data about You or other people. We do not request such information as an account field or use connected content to infer protected or sensitive characteristics.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.
Cookies, Analytics, and Privacy Signals
Our website and applications may use cookies, software development kits, and similar technologies that are necessary to authenticate users, maintain security, remember settings, and provide requested features. With any consent required by law, We may also use analytics and crash-reporting technologies to understand Service performance and improve reliability. The providers in use are identified on Our sub-processor page at https://www.airo.email/policies/subprocessors .
We do not use analytics for cross-context behavioral advertising. Where detected, We honor a Global Privacy Control signal as an opt-out of any processing that could constitute a sale or sharing under applicable law. Our website consent tool and available Account privacy settings provide additional choices where required.
Information from Third-Party Services
The Company allows You to create an account, log in, and connect to the Service through the following Third-Party Services, including:
- Microsoft
If You decide to register through or otherwise grant Us access to a Third-Party Service, We may collect Personal Data associated with that account, such as Your name, email address, profile picture, contacts, account identifiers, and the Connected Account Data necessary for the features and permissions You select.
You may also have the option of sharing additional information with the Company through a Third-Party Service. If You choose to provide such information and Personal Data, We will use, disclose, and retain it only as described in this Privacy Policy and the authorization presented when You connect the service. You may revoke access through Airo or the provider’s account-permissions controls.
Consent to Share Consumption Data with Apple
By using our app and making in-app purchases, you consent to our sharing of data regarding your usage and consumption of purchased content with Apple, as part of our efforts to resolve refund requests. This information may include details about how you have accessed and interacted with the purchased content. The purpose of sharing this data is to help Apple make an informed decision regarding refund requests. We ensure that such data sharing is done in compliance with Apple’s policies and only as necessary to process your requests.
Google API Services User Data Policy Compliance
When you use our Application with Google API Services, we adhere to Google API Services User Data Policy . Specifically:
Google API Scopes Justification
Airo Mail requires Google OAuth scopes to support full email client functionality, including but not limited to:
- Sending/replying to emails
- Reading emails and attachments
- Managing labels (e.g., archive, star, trash)
- Using Gmail search
- Keeping your inbox up to date in real time (so new mail, replies, and label changes appear without manual refresh)
- Showing contact names and photos alongside email addresses
- Improving message readability and usability
- Uploading large email attachments to Google Drive and inserting shareable links into outgoing messages
- Analyzing your Google Drive files and their sharing permissions to detect and help you remediate over-exposed files (for example, files shared publicly, shared by link, indexed by search engines, or shared with people who no longer need access), including revoking shares, lowering access roles, disabling link discovery, and removing or trashing files at your direction
- Categorizing and searching your own Google Drive and email content within the Application to help you find and organize your information
- Reading and managing your mail filters and settings
- Reading and responding to calendar invitations (RSVP) directly from your email
- Listing your calendars so Airo can show outstanding invites across your account
- Checking free/busy availability to suggest meeting times
Appropriate Access
We only request access to the Google API scopes that are necessary for the permitted Application Type as described in Google’s product-specific policies. We will only request the minimum necessary permissions to provide you with the requested services.
Limited Use of Data
Our use of data obtained through Google API Services (including raw data and data aggregated, anonymized, or derived from them) is strictly limited to:
- Providing or improving user-facing features that are prominent in our Application’s user interface;
- We will not transfer data obtained from Google API Services, except:
- To provide or improve your appropriate access or user-facing features that are visible and prominent in our Application’s user interface and only with your explicit consent;
- For security purposes (such as investigating abuse);
- To comply with applicable laws; or
- As part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent.
- We do not allow humans to read your data obtained through Google API Services, unless:
- We have first obtained your affirmative agreement to view specific messages, files, or other data;
- It is necessary for security purposes (such as investigating a bug or abuse);
- It is necessary to comply with applicable law; or
- The data (including derivations) is aggregated and used for internal operations in accordance with applicable privacy and other jurisdictional legal requirements.
Google Drive Data and AI/ML Features
We access your Google Drive metadata, sharing permissions, and (where required for a feature you invoke) file content solely to provide user-facing features within the Application, specifically: (a) detecting and remediating file-sharing security risks, and (b) categorizing and searching your own Drive and email content. All such processing is performed for, and surfaced only to, the individual signed-in user.
Where these features use artificial intelligence or machine learning, We transmit only the data reasonably necessary for the requested feature to AI inference service providers identified on Our sub-processor page. Airo routes each feature to an inference provider. Where the Service offers You a provider choice, Your selection applies to the features it covers; otherwise Airo selects the provider. Those providers serve both interactive features You invoke directly and background processing of Your connected-account data, as identified on Our sub-processor page. Those providers process the data solely to return the user-facing output to Airo under the applicable contract and configuration. We do not use, retain, or transfer Google API Services data to develop, train, or improve generalized, non-personalized, foundational, or third-party AI/ML models, and We do not permit an AI provider to use that data for such training.
Prohibited Uses
We will never:
- Transfer or sell your Google API Services data to third parties like advertising platforms, data brokers, or information resellers;
- Transfer, sell, or use your Google API Services data for serving ads, including retargeting, personalized, or interest-based advertising;
- Transfer, sell, or use your Google API Services data to determine credit-worthiness or for lending purposes.
We ensure that our employees, agents, contractors, and successors comply with the Google API Services User Data Policy.
Google API Services Security Compliance
When processing data obtained through Google API Services, we implement and maintain security measures designed to comply with Google’s API Services User Data Policy and applicable security requirements, including:
- Security Practices and Infrastructure:
- We use encryption for data in transit and at rest
- We implement access controls limiting employee access to user data
- We maintain secure development practices and security reviews
- We conduct periodic vulnerability assessment and security testing appropriate to risk
- We complete any independent security assessment required by Google for the scopes We use
- Data Incident Response:
- We maintain an incident-response process to investigate and address any potential data breaches
- We will notify affected users, regulators, and Google when required by applicable law or platform requirements
- Data Retention and Deletion:
- We retain Google API Services data only for as long as necessary to provide the Service or meet a lawful obligation
- We delete data that is no longer necessary
- We delete Google API Services data associated with a disconnected account through Our scheduled deletion process, which occurs generally after a 30-day grace period from active systems and no later than 90 days, subject to legal-preservation and backup requirements
- Verification and Monitoring:
- We review Our data-handling practices for consistency with this Privacy Policy
- We monitor access to Google API Services data to prevent unauthorized use
Our security measures are designed to provide a level of security appropriate to the risk of processing your Google API Services data and to help protect your data from unauthorized or unlawful access, use, alteration, or disclosure.
Use of Your Personal Data
We do not share, sell, or transfer your Google User Data or Personal Data to third parties for their own purposes, including advertising or marketing.
The Company may use Personal Data for the following purposes:
- To provide and maintain our Service, including to monitor the usage of our Service.
- To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
- For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.
- To contact You: To contact You by email, in-application message, push notification, or another communication channel You provide or request regarding the Service, including security, billing, account, support, and feature-related communications.
- To send You product news and marketing communications: We will only send You non-transactional product, marketing, or promotional email if You have opted in via the marketing-email consent in Your Account settings. You can withdraw that consent at any time, and every marketing email includes a one-click unsubscribe link. Transactional and service messages (security notices, account changes, billing) are sent regardless of marketing-email preferences because they are necessary to operate the Service.
- To manage Your requests: To attend and manage Your requests to Us.
- For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred. In cases involving data obtained through Google API Services, we will obtain your explicit prior consent before such transfers.
- For other purposes: We may use Usage Data, feedback, and aggregated or deidentified information for data analysis, identifying usage trends, evaluating Service reliability and marketing effectiveness, and improving Our Service and Your experience. We do not use Connected Account Data for advertising, cross-context behavioral advertising, or generalized AI-model training.
We may share Your personal information in the following situations:
- With Service Providers: We share Your personal information with the service providers and sub-processors listed at https://www.airo.email/policies/subprocessors so that they can host, store, transmit, secure, support, or analyze it on Our behalf, or perform AI inference for a feature You request. They are subject to contractual confidentiality, use, and data-protection restrictions required by applicable law and, where applicable, the Google API Services User Data Policy. We maintain and update the published list to identify providers that process Personal Data for the Service.
- For business transfers: We may share or transfer Your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company. For any data obtained through Google API Services, we will obtain your explicit prior consent before such transfers.
- With business partners: We do not share Your Personal Data with business partners for their own marketing or promotional purposes. If We introduce an optional partner feature, We will describe the disclosure and obtain any consent required before sharing Personal Data.
- With recipients and other users at Your direction: The Service does not currently provide public user profiles or public social areas. We transmit information to email recipients, calendar invitees, file recipients, connected providers, or other persons and services when necessary to perform an action You direct.
- With Your consent: We may disclose Your personal information for any other purpose with Your consent.
Use of Data for AI Processing and Model Training
The Company uses artificial intelligence and machine-learning services to perform user-facing functions such as categorizing messages, suggesting actions, creating summaries or drafts, searching connected content, and extracting calendar, travel, shipment, or other structured information. AI inference is processing data to produce an output for the requesting user.
We transmit only the content and context reasonably necessary to perform the feature You invoke.
We do not use, permit Our service providers to use, or transfer Connected Account Data, Google API Services data, Microsoft account data, prompts containing such data, or outputs derived from such data to train, fine-tune, or improve generalized, foundational, non-personalized, or third-party AI models.
We require AI inference providers to process Personal Data only for contracted purposes and subject to the settings and safeguards described on Our sub-processor page. A provider may retain limited request and response data for security or abuse monitoring only as permitted by its contract, configuration, and applicable law.
We may use intentionally submitted product feedback and aggregated, synthetic, or deidentified information that is not Connected Account Data to improve the Service. We will obtain separate consent before using identified Personal Data for any model-training activity not described in this Privacy Policy.
You may disable available AI features through Account settings where the Service provides that control. Disabling a feature does not affect the lawfulness of processing performed before it was disabled.
Lawful Bases for Processing (GDPR Art. 6 and Art. 9)
If You are in the European Economic Area, the United Kingdom, or Switzerland, We rely on the following lawful bases for each category of processing:
| Processing activity | Lawful basis |
|---|---|
| Account creation, authentication, and connected-account synchronization and features — reading, sending, and labeling Your email, and (where You enable them) calendar RSVP / free-busy / event extraction, contacts name-and-photo resolution, and Google Drive attachment upload and file-sharing security | Performance of a contract — Art. 6(1)(b); explicit consent — Art. 9(2)(a), obtained when You connect the account |
| Billing, subscription management, and tax record-keeping | Performance of a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| AI-powered features applied to Your own mailbox and connected content — AutoFile triage, the chat assistant, semantic search, and structured extraction (trips, shipments, calendar events) — including transmitting relevant content to our AI sub-processors for inference at the time You use the feature | Performance of a contract — Art. 6(1)(b); explicit consent — Art. 9(2)(a) for any special-category data incidentally present |
| Service-related transactional emails, security notices, and push notifications | Performance of a contract — Art. 6(1)(b) |
| Security monitoring, fraud prevention, abuse investigation, audit logs | Legitimate interests — Art. 6(1)(f); balancing test on file with the Privacy Lead |
| Product analytics and crash reporting with identifiers (PostHog, Firebase Analytics, Crashlytics) for understanding feature adoption, diagnosing usability, and improving reliability | Legitimate interests — Art. 6(1)(f); LIA on file with the Privacy Lead. On by default; You can opt out in Account → Privacy, and We honor Global Privacy Control. No message content is processed and no tracking identifier is stored on Your device. |
| Marketing emails about Airo products | Consent — Art. 6(1)(a) and applicable ePrivacy rules. Off by default. |
| Use of Your mailbox content to train or fine-tune AI models | Explicit consent — Art. 6(1)(a) and Art. 9(2)(a) where special-category data may appear. Off by default. |
| Disclosures to law-enforcement or in response to legal process | Legal obligation — Art. 6(1)(c) |
| Asset transfers in a merger, acquisition, or financing | Legitimate interests — Art. 6(1)(f), with notice; Your explicit prior consent for Google API Services data |
| Shipment and travel enrichment when a relevant email is detected — sending tracking numbers and carrier identifiers to EasyPost and carrier APIs (UPS, USPS, FedEx) to show delivery status and trips | Performance of a contract — Art. 6(1)(b) |
Where We rely on consent, You can withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. Where We rely on legitimate interests, You can object under GDPR Art. 21 (see below).
Retention of Your Personal Data
We retain Personal Data only for as long as necessary for the purposes described above. The periods below are general maximums or criteria; We may retain information for a longer period where reasonably necessary to comply with law, preserve evidence, resolve disputes, protect security, or enforce agreements.
| Data | Retention |
|---|---|
| Account profile, settings, and consent records | While Your account is active and generally for 30 days after account closure, except records needed to meet legal obligations or honor privacy choices. |
| Email message bodies, threads, attachments, calendar data, Drive file metadata and sharing-security findings, and AI annotations | While the underlying account is connected; generally removed from active systems within 30 days after disconnecting the account or closing Your Airo account. |
| OAuth tokens | While the account remains connected. On disconnection or revocation the token is invalidated immediately and any cached copy is evicted; the encrypted token record is then deleted with Your other account data, generally within 30 days. |
| AutoFile recommendations | Rolling 90-day period unless deleted sooner with the underlying account data. |
| Audit and security logs | Generally up to two years, depending on the log and security need. |
| Push-notification receipts | Generally 30 days |
| Shipment tracking, trip records, and calendar event extracts | Until the underlying event has passed and the information is no longer needed for the feature. |
| Backups | Removed through scheduled backup rotation, generally within 30 days after deletion from active systems and no later than 90 days after account closure or disconnection, unless legally preserved. |
| Marketing email suppression records | For as long as reasonably necessary to honor the unsubscribe or do-not-contact request. |
| Cloud Logging error logs and traces | Generally 30 days |
We may retain aggregated or deidentified information for longer where it cannot reasonably be used to identify an individual. Deletion from active systems may not immediately remove information from encrypted backups; backup copies are isolated from ordinary use and removed through scheduled rotation unless legal preservation is required.
Transfer of Your Personal Data
Where Your data is stored. Our primary production infrastructure runs on Google Cloud Platform in the United States. Personal Data may also be processed in other locations identified on Our sub-processor page. Those locations may have data-protection laws different from the laws where You live.
Personal Data may be transferred to and processed in the United States and other countries whose data-protection laws may differ from those in your jurisdiction. Where required by applicable law, We will take appropriate measures to protect Personal Data transferred internationally, which may include relying on transfer mechanisms maintained by Our service providers or implementing other legally recognized safeguards. For information about the safeguards applicable to your Personal Data, contact privacy@airo.email.
Supplementary measures. Personal Data is encrypted in transit and at rest. Sensitive third-party credentials We hold on Your behalf receive an additional encryption layer before being written to the database. Employee access to production data is restricted, requires multi-factor authentication, and is audit-logged.
Your use of the Service or submission of Personal Data does not, by itself, constitute consent to an international transfer. If We rely on consent for a transfer, We will request that consent separately.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
Our Service may give You the ability to delete certain information about You from within the Service.
You may update, amend, or delete Your information at any time by signing in to Your Account, if you have one, and visiting the account settings section that allows you to manage Your personal information. You may also contact Us to request access to, correct, or delete any personal information that You have provided to Us by emailing privacy@airo.email.
Please note, however, that We may need to retain certain information when we have a legal obligation or lawful basis to do so.
GDPR Data Protection Rights
If You are in the European Economic Area (EEA), the United Kingdom, or Switzerland, You have the following rights in relation to Your Personal Data under the General Data Protection Regulation (EU) 2016/679, the UK GDPR, and the Swiss FADP:
- The right to be informed — You have the right to receive clear information about how We process Your Personal Data, which this Privacy Policy provides.
- The right of access (Art. 15) — You have the right to obtain confirmation that We process Your Personal Data and to receive a copy. The first copy is provided free of charge. We may charge a reasonable fee based on administrative costs only for additional copies or where Your request is manifestly unfounded or excessive (in particular because of its repetitive character); in such cases We may also refuse to act on the request and will explain why.
- The right to rectification (Art. 16) — You have the right to have inaccurate Personal Data corrected and incomplete Personal Data completed.
- The right to erasure / “right to be forgotten” (Art. 17) — You have the right to have Your Personal Data deleted in the circumstances set out in the GDPR. Some data may need to be retained where We have a legal obligation or another lawful basis to keep it.
- The right to restrict processing (Art. 18) — You have the right to ask Us to limit the way We use Your Personal Data in defined circumstances.
- The right to object (Art. 21) — You have the right to object at any time to processing carried out on the basis of legitimate interests, and an absolute right to object to processing for direct marketing purposes.
- The right to data portability (Art. 20) — Where We process Your Personal Data on the basis of consent or contract by automated means, You have the right to receive a copy in a structured, commonly used, machine-readable format, and to ask Us to transmit it to another controller where technically feasible. We deliver portability exports as JSON archives.
- Rights in relation to automated decision-making (Art. 22) — Our service uses automated processing to triage Your inbox (AutoFile) and to extract structured data such as trips, shipments, and calendar events from Your emails. We do not believe this processing produces legal effects or similarly significant effects on You within the meaning of Art. 22(1), because it is a productivity assistant whose outputs You confirm or override. You can disable AutoFile in Settings and request human review of any outcome by contacting privacy@airo.email.
- The right to withdraw consent (Art. 7(3)) — Where We rely on Your consent, You can withdraw it at any time in Account → Privacy, without affecting the lawfulness of processing before withdrawal.
- The right to lodge a complaint with a supervisory authority (Art. 77) — You have the right to lodge a complaint with Your local data-protection authority. A full list is published by the European Data Protection Board at edpb.europa.eu/about-edpb/about-edpb/members_en . UK residents can complain to the Information Commissioner’s Office at ico.org.uk . Swiss residents can contact the Federal Data Protection and Information Commissioner at edoeb.admin.ch . We would appreciate the opportunity to address Your concerns before You contact a supervisory authority, but You are not required to do so first.
How to exercise Your rights
To exercise any of these rights, email privacy@airo.email with “GDPR Request” in the subject line, including:
- Full name and the email address associated with Your Airo account.
- Which right(s) You wish to exercise.
- Any context that will help Us locate the relevant Personal Data.
We will:
- Acknowledge receipt within 7 days.
- Verify Your identity proportionately to the sensitivity of the request.
- Provide a substantive response without undue delay and in any event within one month of receipt of the request, as required by GDPR Art. 12(3).
- Where a request is particularly complex or where We have received a number of requests from You, We may extend the response period by up to two further months. In that case We will notify You of the extension and the reasons for the delay within one month of receiving Your request. The total response time will never exceed three months from receipt.
- If We decide not to act on Your request, We will inform You within one month of the reasons and of Your right to lodge a complaint with a supervisory authority and to seek a judicial remedy.
- Responses are provided free of charge. We may charge a reasonable fee or refuse to act only where Your requests are manifestly unfounded or excessive (Art. 12(5)).
Article 27 EU and UK Representatives
Because the Company is established outside the EEA and the United Kingdom, it may be required to appoint representatives under GDPR Art. 27 or UK GDPR Art. 27 when the relevant law applies to Our processing and no exception is available. If an appointment is required, the representative’s current contact information will be published in this Privacy Policy or on Our legal-information page.
EEA and UK residents and supervisory authorities may contact Us directly at privacy@airo.email.
California Privacy Rights (CCPA / CPRA)
If You are a California resident, and to the extent the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to the Company, You have the rights and disclosures described in this section in addition to anything else described in this Privacy Policy.
Categories of personal information We collect and disclose. During the past 12 months, We collected the following CCPA-defined categories. The examples below include information that may appear incidentally in connected messages, files, calendars, prompts, or attachments; We do not request such information as an account field or use it to infer protected or sensitive characteristics.
- Identifiers and customer-record information: name, email address, account and device identifiers, IP address, profile picture, and billing or mailing address. Disclosed for business purposes to hosting, authentication, subscription, app-delivery, support, security, and consent-management providers.
- Commercial information: subscription status, entitlements, transaction identifiers, refund and purchase history. Disclosed for business purposes to subscription, app-store, payment, accounting, and support providers.
- Internet or other electronic-network activity: website and app activity, device and browser information, interactions, diagnostics, crash information, security events, and logs. Disclosed for business purposes to hosting, app-delivery, analytics when enabled, consent-management, and security providers.
- Geolocation information: approximate location inferred from IP address or a billing or mailing address. We do not collect precise device geolocation as an application permission for the Service described by this Privacy Policy. Disclosed for business purposes to hosting, security, app-delivery, payment, and consent-management providers.
- Communications and user content: email and calendar content, attachments, contacts, Drive content and permissions, prompts, support messages, and AI outputs. Disclosed for business purposes to hosting, connected-account, AI-inference, and support providers, and to recipients or services designated by You.
- Professional, employment-related, educational, sensory, and protected-classification information: information that may incidentally appear in content selected or connected by You. Disclosed for business purposes to hosting and AI-inference providers only as needed to provide a requested feature.
- Inferences: message categories, summaries, recommendations, extracted events, shipment and trip information, and other feature outputs. Disclosed for business purposes to hosting, AI-inference, and feature-support providers.
- Sensitive Personal Information: the contents of email and private communications; account credentials and OAuth tokens; and financial, health, precise-location, racial or ethnic, religious, sexual-orientation, citizenship, or similar information that may incidentally appear in connected content. Disclosed for business purposes to hosting, authentication, connected-account, AI-inference, and security providers only as needed to provide requested services.
Sources. Directly from You, from Your connected providers (including Google and Microsoft), automatically from devices and browsers used to access Airo, and from service providers that support transactions, security, analytics, or customer support.
Business purposes. Delivering the email-client and related features You request; processing payments; maintaining security and preventing fraud; performing analytics when enabled; providing support; complying with legal obligations; and the other purposes described under “Use of Your Personal Data.”
Retention. The retention periods or criteria for these categories are described under “Retention of Your Personal Data.”
Sale or sharing of personal information. We have not sold or shared Personal Data, as those terms are defined under the CCPA / CPRA, during the past 12 months. We do not engage in cross-context behavioral advertising. We do not have actual knowledge that We sell or share the Personal Data of consumers under 16.
Sensitive Personal Information. We use and disclose Sensitive Personal Information only to provide requested services, maintain security and integrity, and for other purposes permitted by CCPA regulations. We do not use Sensitive Personal Information to infer characteristics about consumers. Accordingly, We do not provide a separate right-to-limit mechanism for this processing.
Global Privacy Control (GPC). We honor the Global Privacy Control browser signal. When Your browser indicates GPC, We treat the session as opted out of any processing that could constitute sale or sharing and apply the signal as required by applicable law.
Your CCPA / CPRA rights. Subject to applicable exceptions, You have the right to:
- Request to know or access the Personal Data We have collected, the categories of sources, the purposes, and any disclosures.
- Request deletion of Your Personal Data.
- Request correction of inaccurate Personal Data.
- Receive information about the categories of third parties to whom We disclose Personal Data.
- Opt out of sale or sharing. Because We do not sell or share Personal Data, there is currently no sale or sharing to opt out of.
- Be free from retaliation for exercising these rights.
How to exercise Your rights and Our response timeline. Submit a request through the California Privacy Request page or email privacy@airo.email with “California Privacy Request” in the subject line. Under applicable law, We will:
- Acknowledge receipt within 10 business days.
- Verify Your identity using Your account email and, where appropriate, an additional step proportionate to the sensitivity of the request.
- Provide a substantive response within 45 days of receipt. Where reasonably necessary, We may extend the response period once by an additional 45 days and will notify You of the extension and reason within the initial 45-day period.
- Provide responses free of charge, subject to exceptions permitted by law. If We decline a manifestly unfounded or excessive request, We will explain why and any available appeal process.
Authorized agents. You may designate an authorized agent to submit a request on Your behalf. We may require written proof of authorization and verify Your identity directly.
Minors. The Service is intended only for persons who are at least 18 years old. We do not knowingly sell or share the Personal Data of anyone under 18.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy. For data obtained through Google API Services, we will obtain your explicit prior consent before such transfers.
Law Enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other Legal Requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
We use industry-standard security measures, including encryption and access controls, to protect your data. The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
Children’s Privacy
The Service is intended only for persons who are at least 18 years old. Airo does not knowingly permit anyone under 18 to create an Account or collect Personal Data through an Account belonging to a person under 18.
If We learn that We collected Personal Data through an Account belonging to a person under 18, We will take reasonable steps to close the Account and delete the information, subject to applicable legal obligations.
If You are a parent or guardian and believe a child has provided Us with Personal Data, please contact privacy@airo.email.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will post the updated Privacy Policy on this page and revise the “Last updated” date. Nonmaterial changes are effective when posted.
If a change materially expands how We collect, use, or disclose Personal Data, We will provide advance notice by email, through the Service, or by another appropriate method and obtain consent where required before applying the new practice to previously collected information.
You are advised to review this Privacy Policy periodically for changes.
Contact Us
If you have any questions about this Privacy Policy, You can contact us:
- By email: privacy@airo.email
- By mail: Airo Intelligence, Inc., Attn: Privacy, 2261 Market Street, Ste 67792, San Francisco, CA 94114