Privacy Policy
This policy explains what personal data SMailOS processes, why it is processed and what rights you have.
1. Controller
The controller is IRSE, computer infrastructure and data processing, Rajmond Hočevar s.p., Novi dom 72, 1420 Trbovlje, Slovenia. Use the SMailOS contact option for privacy questions.
2. Data we process
We process account and workspace data, subscription and payment status, settings, security events, and data you enter or connect through email, social networks, documents, CRM and other modules.
3. Purposes and legal bases
We process data to perform the SMailOS contract and features, protect security and prevent abuse, provide support and billing, and meet legal obligations. Where consent is required, it can be withdrawn for the future.
4. Email and connected channels
You control permissions for connected email and social accounts. The external provider remains the source of truth. SMailOS may keep an operational local cache, index, metadata and content needed for enabled features and permitted quotas rather than a permanent full copy of the external account.
5. AI processing
When you use an AI feature, data needed for the request may be processed by the configured AI provider. Scope depends on the enabled feature, permissions and settings. Do not treat AI output as infallible fact.
6. Processors and transfers
We may use contracted providers for hosting, payments, communications, security and AI. Stripe processes payment data under its own terms. Where data is transferred outside the EEA, appropriate legal safeguards are used when required.
7. Retention and deletion
We retain data as long as necessary for the service, security, billing, legal obligations and claims. Operational caches and indexes may be rotated or deleted according to quotas and lifecycle rules.
8. Cookies
Necessary cookies support sessions, security, language and core operation. Optional analytics or marketing cookies are used only when enabled and properly consented to. You can later clear your choice in browser settings.
9. Your rights
Under the GDPR, depending on the circumstances, you may request access, correction, deletion, restriction, portability or object, and you may complain to the competent supervisory authority.
10. Security and changes
We use technical and organisational safeguards including access controls and audit trails. We may update this policy when the service or law changes; the current version is published here.
11. Google user data and Google Workspace APIs
When a user voluntarily connects a Google or Gmail account to SMailOS, SMailOS accesses only Google user data covered by the OAuth permissions explicitly granted by the user. Depending on the permissions granted, this may include basic Google account information and Gmail data needed for SMailOS features, including message content and metadata, message and thread identifiers, labels, drafts and other data required to display, synchronize, search, organize, reply to, send or otherwise manage email.
12. How we use Google user data
Google user data is used only to provide or improve user-facing SMailOS functionality that the user sees, enables or explicitly requests, such as connecting a Gmail account, synchronizing and displaying email, searching and organizing messages, preparing replies, sending email and managing email. SMailOS does not sell Google user data and does not use it for advertising, advertising retargeting, determining credit-worthiness or creating databases for sale to third parties.
13. Sharing, transfer and disclosure of Google user data
SMailOS does not sell Google user data. Google user data may be shared only with infrastructure, hosting, security or processing service providers acting on our behalf and only to the extent necessary to provide functionality requested or enabled by the user. Such providers may use the data only for the agreed service purpose and must apply appropriate data-protection measures. Data may also be disclosed when required by applicable law or legal process, for security or abuse-prevention purposes, or when explicitly requested or authorized by the user.
14. Protection of Google user data
SMailOS applies technical and organizational measures designed to protect Google user data against unauthorized access, disclosure, alteration, loss or destruction. Data transmitted between the user and SMailOS is protected using HTTPS/TLS connections. Access to production systems, databases, credentials and OAuth tokens is restricted through authentication, authorization and server or database permissions to people or system processes that require access to provide the service. OAuth credentials and tokens are treated as confidential information.
15. Retention, disconnection and deletion
Google user data and related cached or indexed data are retained only for as long as necessary to provide the connected functionality, protect the service, troubleshoot technical issues or comply with applicable legal obligations. A user can disconnect a Google account from SMailOS and can revoke previously granted permissions through the user's Google account. When Google user data is no longer required for the requested functionality or a valid deletion request is made, the data is deleted or anonymized in accordance with applicable retention procedures unless continued retention is required by law.
16. Artificial intelligence and Google data
When a user explicitly invokes an AI-powered SMailOS feature, only data necessary to provide the requested user-facing feature may be processed through an appropriate service provider acting for that purpose. Data obtained through Google Workspace APIs is not used to develop, improve or train generalized or non-personalized artificial-intelligence or machine-learning models.
17. Google API Limited Use
SMailOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google API Services User Data Policy
18. YouTube API Services and YouTube user data
SMailOS uses YouTube API Services only after a user explicitly connects and authorizes a YouTube account. Depending on the enabled SMailOS features and permissions granted, SMailOS may access and process the authorized channel identity, channel and video metadata, comments and replies, and data required to perform user-requested YouTube actions. This data is used to synchronize and display YouTube content in SMailOS and to provide user-initiated functions such as publishing or deleting videos, posting or replying to comments, and moderating or deleting comments. YouTube user data is not sold or used for advertising. Access, sharing, protection, retention, deletion, AI processing and Limited Use of Google and YouTube data are governed by the Google-data provisions in this Privacy Policy.
AI usage metering
To provide AI functionality, enforce plan limits, prevent abuse, maintain security, support billing and plan capacity, we may process AI usage information such as the number of requests or actions, the model or provider used, estimated or actual token counts, timestamps, the related workspace and technical metadata. Prompt and output content is processed only to the extent needed for the enabled function, security and the agreed service, and may be sent to the configured AI provider where necessary to perform the request.
AI usage, credit and purchase records
To operate AI limits, protect the service, support billing and provide account and platform-administration reporting, SMailOS records workspace-level AI usage metrics, timestamps, credit grants, AppSumo tier changes and prepaid AI-credit purchases. Purchase records may include the number of credits, amount, currency and Stripe or marketplace reference. SMailOS does not need to store full payment-card details. These records are retained only as long as needed for service operation, accounting, fraud prevention, dispute handling or legal obligations. A commercial term such as ‘lifetime’ does not mean perpetual personal-data retention; service duration is governed by the Terms of Service.
