Legal / Privacy
Privacy is part of the interface.
Last updated: August 18, 2026
This policy describes how MailHero by AISaver (“MailHero,” “we,” “us”) handles data when you use the Gmail Add-on and related services. Material changes will be reflected here before they take effect.
Google user data we access
MailHero accesses Google user data only while the Gmail Add-on is active and only for the Gmail conversation you explicitly open. Depending on the action you choose, this can include the current thread’s message content; subject; sender, recipient, and CC information; timestamps; Gmail thread and message identifiers; and the Google Account email address used to identify your MailHero session. MailHero can also create a Gmail reply draft when you explicitly request it.
MailHero does not scan, search, monitor, or read other Gmail messages or your mailbox in the background. It does not automatically send, modify, or delete email.
How we use Google user data
We use the current open thread only to provide the action you explicitly request: create an AI case brief, generate, improve, or translate an editable reply, create a Gmail draft, or save a user-selected record to Notion. Gmail thread and message identifiers let the Add-on associate a saved Notion record with the conversation and honor your selected overwrite or new-record preference. For a reply, you may also choose specific saved Notion records as context. Translation uses only the reply text you provide.
We do not use Gmail or other Google user data for advertising, profiling, selling data, creditworthiness decisions, or generalized AI/ML model training.
When Google user data is shared
MailHero shares the minimum data needed for an explicit action with the following recipients:
- Your selected AI service. When you click Analyze, Generate reply, Improve draft, or Translate, the applicable current-thread content, reply text, and any Notion records you selected are sent to either MailHero’s managed AI service or the custom OpenAI-compatible provider you configured.
- Notion. When you explicitly click Save to Notion or authorize Notion, MailHero sends the record you chose to save and the information needed to access the pages or databases you authorized.
- Service providers that operate MailHero. They process limited account, connection, and operational data solely to provide, secure, and support MailHero.
We do not sell Google user data or disclose it to advertising networks, data brokers, or unrelated third parties. A custom AI provider is controlled by you; its handling of data is governed by its own privacy policy and terms.
Data protection
MailHero uses HTTPS/TLS for data in transit and restricts production-service access to authorized personnel and systems. OAuth and connection credentials that must be retained to provide an authorized connection are stored using protected storage with encryption at rest. MailHero does not retain Gmail message bodies in its hosted service, request logs, analytics, or error tracking. Custom AI provider credentials remain in your Apps Script user properties and are not stored by MailHero’s hosted service.
Notion
MailHero accesses only Notion pages and databases you authorize. A Case Brief or a thread is written to Notion only after you click Save. You choose whether to include the original email content in the Notion page. Notion authorization tokens are encrypted at rest.
Email sending
MailHero creates a Gmail draft for your review. It does not automatically send email.
Retention and deletion
Gmail message bodies are processed for the action you request and may be held temporarily in your Add-on user cache for up to six hours so that you can review the result or continue an explicit workflow. MailHero does not retain Gmail message bodies in its hosted service after processing. Temporary Notion authorization state expires after 10 minutes. We retain limited account, connection, settings, operational metadata, and Gmail/Notion record identifiers needed for a selected save preference only while your MailHero account or authorized connection remains active, or as needed to resolve security, abuse, or legal obligations.
You may revoke Google access through your Google Account connected apps page and revoke Notion access from Notion at any time. To request deletion of your hosted account, connection, settings, and associated operational metadata, contact support@aisaver.app from the email address associated with your account. We will verify the request and delete the applicable hosted data unless we must retain limited information for security, abuse prevention, or legal obligations. A deletion request does not remove content you previously chose to save in your own Notion workspace; you control and can delete that content in Notion.
Google API Services User Data Policy
MailHero’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.