Privacy Policy
Plain answers about what we do with your mail, and what we deliberately don’t.
Last updated: 18 August 2026
mailbud reads your incoming email so it can file it into the folders you describe. That is an unusual amount of trust to ask for, so this page is specific rather than reassuring. Nahayat.io is the data controller for your account data and your data processor for the mail we classify.
Where your mail is processed
Everything stays in the EU. Your data lives in our own database, on our own hardware, in the Netherlands, not on a hyperscaler. The AI that classifies your mail is Mistral, a French company, reached over its EU endpoint. No mailbox content is sent outside the EU, so there is no international-transfer question to answer.
What we store, and how
- Mailbox content: the subject, sender and a bounded slice of the body of incoming mail, used to decide which folder it belongs in. It is encrypted at rest with a key unique to your account (AES-256-GCM). We keep no plaintext copy: your subjects and senders exist in our database only as ciphertext.
- Search vectors: to learn from your corrections we store a numeric “embedding” of each example you confirm. These are derived from your mail, so we protect them with a secret transform unique to your account rather than storing them as the AI model produced them.
- Access tokens: the OAuth tokens Microsoft issues, encrypted at rest. We never see or store your password, and you can revoke our access from your Microsoft account at any time.
- Account and billing data: your name, email address, Microsoft identity, and what we need in order to invoice you.
What mailbud cannot do
We ask Microsoft for permission to read and move mail, and to create folders. We do not ask for permission to send. mailbud cannot send, reply to, or forward mail on your behalf, not as a policy choice you have to take on trust, but because we never requested the ability in the first place.
Your mail is never used to train AI models
We do not train any model on your mail, and we do not build shared or cross-customer models from it. Your corrections improve filing for your account only. They are encrypted under your own key and are not readable across accounts.
How long we keep it
Specific windows, rather than “as long as necessary”:
- Classification history: 30 days. After that the subject, sender and the AI’s reasoning are erased. We keep the bare record, which folder, how confident, how fast, so your statistics survive, but the text of your mail does not.
- Review queue: 30 days after you resolve an item, then deleted outright. Items left untouched are removed after 180 days.
- Your corrections: we keep the most recent 200 per category, so filing keeps improving without accumulating your mail indefinitely.
- Internal job records: deleted within a few days.
Deleting your account
There is a delete button in your settings, and it is not a support ticket. It disconnects your mailbox, deletes your tokens and all of your mail data, and then destroys your encryption key, which means any copy that still exists in a backup becomes permanently unreadable, not merely unlisted. The folders mailbud created in Outlook, and the mail inside them, stay yours and are untouched.
One exception, and it is a legal one: paid invoices are kept for seven years because Dutch tax law requires it. They contain billing details only, never mail content.
Who else is involved
We keep this list short on purpose. Each one is named so you can check it yourself:
- Microsoft (EU): your mailbox. You already have a relationship with them; we connect through the official Graph API.
- Mistral AI (Paris, France): classifies your mail, on its EU endpoint.
- Stripe: card payments and subscription billing. Never receives mail content.
- WeFact (Netherlands): invoicing and bookkeeping.
- Resend: sends the handful of transactional emails we send you, such as the welcome message. Receives your email address and our own message text; never your mail.
- Cloudflare: serves and protects this website.
Our hosting provider is absent from this list because there isn’t one: the servers are ours, in the Netherlands. We will tell you before adding any sub-processor that touches mailbox content.
Analytics and cookies
We use analytics on our public pages only, and only if you agree, decline and nothing loads at all. We never run analytics inside the app itself; your workspace is not something we measure. The only cookies we set without asking are the ones that keep you signed in and remember your language and your cookie choice.
Security
- Per-account encryption keys, so one key never unlocks another customer’s mail.
- Encrypted content is cryptographically bound to the account it belongs to and cannot be moved between accounts.
- Microsoft tokens encrypted at rest; no passwords stored.
- Database access restricted at the row level, with no public API surface.
- Our logs deliberately record identifiers, never your subjects or the addresses you correspond with.
Legal basis
We process your data to perform our contract with you, and on the basis of the consent you give Microsoft when you connect your mailbox. You can withdraw that at any time from your Microsoft account, and delete everything else from your settings.
Your rights
Under the GDPR you can access, correct, export, delete, restrict or object to the processing of your personal data. Deletion you can do yourself, immediately. For anything else, email [email protected] and we will respond within a month, usually much sooner. You may also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Contact
Nahayat.io, [email protected]. For the contractual detail of how we handle mailbox content on your behalf, see our Data Processing Agreement.