Aisla← Back home
Privacy

Privacy Policy

Last updated: 6 August 2026

1. Who we are

Aisla ("Aisla", "we", "us", "our") provides an AI assistant that reads wedding-related emails and delivers summaries by email or WhatsApp. This policy explains how we handle personal data.

Data controller: Aisla. Contact: aisla.app@gmail.com.

2. Personal data we collect

  • Account data: name, email address, authentication identifiers from Supabase.
  • Profile data: wedding date, WhatsApp phone number (optional), country code, preferences.
  • Connected mailbox data: the email address of the Gmail or Microsoft account you link, and its OAuth access and refresh tokens.
  • Email content we access: message headers (sender, recipients, subject, date) and message bodies of wedding-related emails identified by our classifier, plus attachment metadata (filename, type, size).
  • Generated content: AI-produced summaries, task lists and draft replies derived from your emails.
  • Delivery data: WhatsApp / email delivery status and timestamps.
  • Technical data: IP address, browser, device, log data.
  • Payment data (if you subscribe): handled by Stripe — we do not store card numbers.

3. What email data we access and store

When you connect Gmail (via the Google Gmail API) or Outlook (via Microsoft Graph), we request read-only scopes needed to identify wedding-related messages, group them by supplier and generate summaries.

Storage of email bodies: Full message bodies are processed transiently in memory. They may be stored to speed up processing times for your daiy briefing.

Metadata retained: sender, subject, thread ID, timestamps and AI-generated summaries are stored so we can show your dashboard and produce daily briefings.

We do not store personal, financial or unrelated emails beyond what our classifier identifies as wedding-related. No human at Aisla routinely reads your email; access is restricted to authorised engineers for debugging or safety, subject to internal controls.

Aisla's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. OAuth access and refresh tokens

Google and Microsoft OAuth tokens are stored encrypted at rest in our database (Supabase, hosted on eu-west-1). Tokens are used only to fetch emails on your behalf. You can revoke access at any time from your Google Account or Microsoft Account settings, or from within Aisla by disconnecting your mailbox — this deletes the tokens from our systems.

5. How AI providers process your email content

We use AI to generate summaries, categorisations and draft replies. Relevant email content and metadata are sent to OpenAI over TLS for processing.

Model training: we have configured our OpenAI usage so that your data is not used to train OpenAI's models, in line with OpenAI's API data-usage terms.

Aisla does not use your email content to train our own AI models.

6. Purposes and legal bases (UK GDPR / EU GDPR)

  • Providing the service (reading your mailbox, generating summaries, sending briefings) — performance of a contract with you.
  • Sending WhatsApp / email briefings — performance of a contract and, where required, your consent (which you can withdraw at any time).
  • Security, fraud prevention, service improvement — legitimate interests.
  • Legal and regulatory compliance — legal obligation.
  • Marketing communications — consent (opt-in only).

7. Data retention

  • Account data: for the life of your account.
  • Email content and AI summaries: Kept until you disconnect your mailbox or delete your account, then purged within 30 days.
  • OAuth tokens: deleted immediately when you disconnect your mailbox or delete your account.
  • Logs and analytics: 30 days.

8. International data transfers

Some processors (e.g. OpenAI, Whatsapp, Microsoft, Google) may process data outside the UK / EEA, including in the United States. Where required, transfers are protected by the UK International Data Transfer Addendum, EU Standard Contractual Clauses and/or the EU–US and UK–US Data Privacy Framework where a processor is certified.

9. Third-party processors

  • Supabase — authentication, database and file storage.
  • Google (Gmail API) — mailbox access when you connect Gmail.
  • Microsoft (Graph API) — mailbox access when you connect Outlook.
  • OpenAI — AI summaries and draft replies.
  • WhatsApp delivery: WhatsApp Business API.
  • Payments: Stripe.
  • Hosting / infrastructure: Cloudflare.

10. Your rights

Under UK GDPR and EU GDPR you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data;
  • request deletion of your data;
  • restrict or object to processing;
  • data portability;
  • withdraw consent at any time (without affecting prior processing);
  • lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office (ICO).

Exercise any right by emailing aisla.app@gmail.com. We respond within one month.

11. Disconnecting your mailbox and deleting your account

You can disconnect Gmail or Outlook at any time from the Aisla dashboard — this removes the OAuth tokens and stops all further email access. To delete your account and all associated data, use the delete option in your account settings or email aisla.app@gmail.com. We complete deletion within 30 days, subject to any legal retention obligations.

12. Cookies

Cookies used: Only strictly necessary cookies for authentication and session management. We do not use advertising cookies.

13. Security

We use TLS in transit, encryption at rest for sensitive fields (including OAuth tokens), access controls and audit logging. No system is perfectly secure — please report suspected issues to aisla.app@gmail.com.

14. Children

Aisla is not directed at people under 18 and we do not knowingly collect data from children.

15. Changes to this policy

We may update this policy. Material changes will be notified by email or in-app before they take effect.

16. Contact

Privacy questions: aisla.app@gmail.com