PRIVACY POLICY

Privacy, in plain language.

Last updated 9 October 2026

Email Studio reads connected email to run the workflows you configure. This page explains what moves through the service, who processes it, and how you control it.

1. Who this policy covers

This policy covers the Email Studio website and email automation service, operated under the name Email Studio (“we”, “us”). For privacy questions or requests, contact office@2i-digitals.com. If your organization provides your account, its own policies may also apply to your use of the service.

2. Information we access and store

  • Account information: your sign-in email, profile and organization information, access role, and authentication records.
  • Inbox connection: mailbox address, provider, encrypted authorization tokens or IMAP credentials, connection status, and synchronization markers. Google handles your Google password; we do not receive it through OAuth.
  • Email data: message identifiers, sender, subject, dates, message text, and supported attachments needed to execute your workflow. Gmail access uses gmail.readonly. The current service checks new inbox messages received after connection.
  • Workflow data: names, instructions, conditions, model selections, and any webhook URL you enter.
  • Activity: message metadata, step outputs, final results, status, model usage counts, and errors. Outputs can contain personal information from the source email.
  • Technical information: operational and security logs, connection errors, and request information used to run and troubleshoot the service. Hosting infrastructure may process IP addresses and request metadata.

The application does not archive original message bodies or attachment files in its activity database. It processes them to run your agents; copies or extracts may remain in saved outputs, processor records, or webhook destinations.

3. Why we use this information

We use it to authenticate users, connect the selected mailbox, detect incoming mail, execute your instructions, display activity and results, deliver configured webhooks, support users, and protect the service. We do not sell Google user data or use it for advertising, credit assessment, or unrelated profiling.

4. AI processing and data sharing

OpenAI: when an AI step runs, email text, supported attachments, your instructions, and previous step outputs are sent to the OpenAI API to produce that step’s result. This happens automatically for new messages while the workflow is enabled. API requests disable stored response history; this is not a promise of zero retention by the processor. OpenAI’s applicable API terms and data-handling policies govern its processing.

Webhook destinations: when you configure a webhook, Email Studio sends the email sender, subject, received date, workflow name, run identifier, and result to that destination. The result may contain email or attachment content. Choose destinations you trust; their retention and privacy practices also apply.

Service providers: infrastructure and database providers process information needed to host and operate the service. Authorized support personnel may access information when needed for a support request, security investigation, or legal obligation, subject to the Google data restrictions below.

We may disclose information when legally required or necessary to address fraud, abuse, or security threats. A business transfer involving Google user data will remain subject to applicable Google policy restrictions and any consent required by those policies. Processing locations depend on the service providers used and may be outside your country.

5. Google data and Limited Use

Email Studio’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including their Limited Use requirements.

Google data is used only to provide or improve the user-facing email automation features you request. Transfers are limited to providing those features, permitted security purposes, applicable legal requirements, or other uses expressly allowed by those policies. We do not use or retain Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.

Humans do not read your Google user data unless you give affirmative consent for specific messages, it is necessary for security purposes or to comply with law, or the data is aggregated and anonymized for internal operations as permitted by Google’s policies.

6. Retention and deletion

Workflow configuration, saved credentials, and activity are kept while the workflow exists; there is currently no automatic age-based expiration for activity. Deleting a workflow removes its configuration, saved inbox credentials, pending connection requests, and activity from the application’s active database. It also cancels its active processing.

Disconnecting an inbox removes its saved credentials; it does not erase existing results. Pausing stops new checks but retains the connection and history, and a task already in progress may finish. Deleting or disconnecting does not delete messages from your mail provider.

Information already sent to OpenAI or a webhook destination is subject to that provider’s retention and deletion processes. Operational logs or infrastructure backups, where used, can persist according to their retention settings and are not necessarily erased by the workflow delete action. Contact office@2i-digitals.com for an account deletion, data access, correction, or broader deletion request. We may need to verify your identity.

7. Security and your choices

Mailbox credentials are encrypted before storage. The application restricts workflow access by account and organization and uses authenticated API requests. No system can guarantee absolute security. Keep your account secure and only connect mailboxes you are authorized to use.

You can pause, disconnect, or delete a workflow, and revoke Google access through your Google Account connections. Revoking access prevents future authorized access but does not automatically erase saved results.

8. Website storage, children, and changes

This public website does not include advertising or analytics trackers and does not set cookies. The application uses browser storage for sign-in and preferences and a temporary cookie to secure the Google connection flow. Google and other sites you visit have their own policies.

The service is intended for adults using email automation for themselves or their organizations, and is not directed to children. We may update this policy as the service changes. The date above identifies the current version; material changes to data use will be communicated before they take effect where required.