Back to Home

Privacy Policy

Effective May 23, 2026

At NextEmail.ai, operated by CalMax Systems ("we," "us," or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, store, disclose, and safeguard your information when you use our service.

Our Privacy Commitment

Your emails are processed by AI running entirely on our own servers. Your email content is never sent to third-party AI providers like OpenAI, Google AI, or Anthropic. No human reads your emails — only our automated AI systems process them. We do not use your email content to train our AI models.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

1.2 Email Data

When you connect your email account (Gmail or Microsoft 365), we download and persistently store the following on our servers:

Why we store your email data: Persistent storage is required for continuous security scanning (threat detection runs approximately every 60 seconds), AI-powered search, and email organization. Without stored data, we could not provide real-time protection or search functionality.

No human reads your emails. All email processing is performed by our automated AI systems running on our own servers. Your email content is never sent to third-party AI services.

1.3 Billing Information

When you subscribe to a paid plan, payment information (credit card number, billing address) is collected and processed by Stripe. We store only your Stripe customer ID and subscription status — we never see or store your full credit card number.

1.4 Usage Data

We automatically collect:

1.5 Device Tokens (Mobile App)

If you use our iOS app, we collect your Apple Push Notification service (APNs) device token to send you push notifications. You can disable notifications in your device settings at any time.

2. How We Use Your Information

We use collected information to:

We do not use your email content to train our AI models. Our AI models are trained on separate datasets and deployed on our servers. Your email data is only used for providing the service to you.

3. Data Storage and Security

Your data security is our priority:

4. Data Sharing

We do not sell your personal information. We may share data only:

5. Automated Decision-Making

NextEmail.ai uses fully automated AI systems to make decisions that directly affect your email. Under GDPR Article 22 and similar regulations, you have the right to understand these decisions:

5.1 Threat Classification

Our AI analyzes each incoming email and classifies it as safe, spam, or phishing. Emails classified as threats are automatically moved to a filtered folder ("AI Filtered Spam") in your email provider. This happens without human review.

Logic: Our AI model (a large language model running locally on our servers) analyzes the email's sender, subject, body content, attachment metadata, and authentication headers to produce a classification. Post-model heuristics check for known threat patterns (brand impersonation, sender spoofing, attachment-based scams).

Significance: Emails classified as threats are moved out of your inbox. You may miss a legitimate email if it is incorrectly classified (false positive).

Your rights: You can review all classified emails in your dashboard. Moving a misclassified email back to your inbox in your email provider overrides our classification. You can contact us to request human review of any classification decision.

5.2 Email Organization

When AI Organize is enabled, our AI assigns category labels (e.g., "AI/Amazon," "AI/Bank of America") to safe emails. This is optional and disabled by default for new accounts.

5.3 Auto-Unsubscribe

For spam emails that include RFC 8058 one-click unsubscribe headers, our system automatically sends an unsubscribe POST request. This only applies to spam categories — never to emails classified as phishing (to avoid interacting with attacker infrastructure).

6. Your Rights

Regardless of your location, you have the right to:

To exercise any of these rights, contact us at privacy@nextemail.ai or use the account management features in your settings.

7. Data Retention

We retain your data as follows:

8. Sub-Processors (Third-Party Service Providers)

We use the following third-party services to operate NextEmail.ai. These providers process data on our behalf under contractual obligations to protect your information:

Provider Purpose Data Shared
Stripe Payment processing Email address, payment method (collected directly by Stripe)
Cloudflare DNS, CDN, DDoS protection (marketing site) IP address, page requests (marketing site only)
Google reCAPTCHA Bot prevention on referral invitations Browser fingerprint, IP address
Microsoft Graph API Office 365 email access (at your request) OAuth tokens (encrypted), email data (downloaded to our servers)
Google Gmail API Gmail email access (at your request) OAuth tokens (encrypted), email data (downloaded to our servers)

No third-party AI services. Our AI models (for security scanning, email organization, and search) run entirely on our own GPU servers. Your email content is never sent to OpenAI, Google AI, Anthropic, or any external AI provider.

9. Google API Services Disclosure

NextEmail.ai's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Limited Use Disclosure

NextEmail.ai's use of information received from Gmail APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Gmail Permissions We Request

When you connect your Gmail account, we request the following permissions:

How We Use Gmail Data

We use your Gmail data exclusively to:

What We Do NOT Do With Gmail Data

Revoking Access

You can revoke NextEmail.ai's access to your Gmail data at any time by:

When you revoke access, we will permanently delete your Gmail data from our servers. If you disconnect via NextEmail.ai settings, deletion occurs when you delete the mailbox. If you revoke via Google, deletion occurs within 30 days.

10. Cookies

We use the following cookies:

We do not use advertising cookies or third-party tracking cookies on our application.

11. Children's Privacy

Our service is not intended for users under 16 years of age. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal information, contact us at privacy@nextemail.ai and we will delete it.

12. Data Breach Notification

In the event of a data breach that compromises your personal information:

13. International Data Transfers

Our servers are located in the United States. If you access our service from outside the United States, your data will be transferred to and processed in the United States. By using our service, you consent to this transfer.

For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on your explicit consent (provided when you connect your email account) as the legal basis for this transfer under GDPR Article 49(1)(a).

14. For Residents of the European Economic Area (GDPR)

If you are located in the EEA, UK, or Switzerland, the following additional terms apply:

14.1 Legal Basis for Processing

14.2 Your GDPR Rights

In addition to the rights listed in Section 6, you have the right to:

14.3 Data Protection Contact

For GDPR-related inquiries, contact our data protection point of contact at privacy@nextemail.ai.

15. For Residents of California (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise these rights, contact us at privacy@nextemail.ai or use the account management features in your settings. We will respond within 45 days.

16. Changes to This Policy

We may update this policy periodically. We will notify you of material changes via email at least 14 days before they take effect. The "Effective" date at the top of this page indicates when this version was last updated.

17. Contact Us

Questions or Concerns?

If you have any questions about this Privacy Policy or our data practices, please contact us: