1. Who We Are
White Rabbit Foundry Limited ("WRF", "we", "us", "our") operates the Emily virtual assistant service. We are registered in England and Wales. We act as a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For privacy enquiries or to exercise your rights, contact us at: help@emily-wrf.com.
2. Data We Collect
We collect and process the following categories of personal data:
- Account data: name, email address, organisation name (optional), password hash (stored by Firebase Authentication).
- Email content: the content of emails you send to Emily's address, including any attachments, for the purpose of processing your instructions.
- Chat messages: messages you send via the in-app chat interface.
- Third-party contact data: names, email addresses and any details you record (phone, organisation, role, notes) for individuals you ask Emily to contact. Emily also auto-saves a contact (email and a name) for people you email, so it recognises them next time; you can turn auto-save off, edit, or delete any contact from your Contacts page.
- Usage and activity data: actions taken, timestamps, job logs, and usage counts for billing and service improvement.
- Billing data: processed entirely via Stripe. WRF does not store card numbers. We store Stripe customer and subscription IDs.
- Memories: facts and preferences you ask Emily to remember, stored to personalise future interactions.
- Connected calendar data (optional): if you choose to connect a Microsoft, Google or Apple calendar, we access your calendar free/busy information and event details (times, titles, attendees, locations, meeting links) to show your availability and manage meetings, and we create, update or cancel events at your request. We only access calendars; we do not access your email or mailbox through these connections. See section 13.
- Connected Zoom account (optional): if you choose to connect a Zoom account, we create a Zoom meeting on your account when you ask Emily to arrange a meeting, so the join link can be added to the invitation, and we read your Zoom account email address once at connection to show which account is linked. We do not read, list or modify your existing Zoom meetings. See section 13.
- Technical data: authentication tokens, IP addresses (for security), and error logs.
3. How We Use Your Data
We process your personal data for the following purposes and on the following lawful bases:
- Providing the Service (contract): processing your emails and instructions, scheduling meetings, setting reminders, sending replies.
- Billing and account management (contract): creating and managing your subscription, invoicing, and billing communications.
- Service communications (legitimate interest): sending operational emails such as confirmations, updates, and security alerts.
- Service improvement (legitimate interest): analysing usage patterns in aggregate to improve performance and features.
- Legal compliance (legal obligation): retaining records required by law.
- Beta feedback (consent / contract): if you are a beta participant, we may contact you to request feedback as agreed at registration.
We do not sell your personal data to third parties, and we do not use your content for advertising.
4. AI Processing
Email content, chat messages, and attachments you provide to the Service are processed by AI language models (currently Google Gemini, accessed via the Gemini Developer API) to generate responses and take actions. By using the Service, you consent to this AI processing. AI-generated outputs may not always be accurate; you remain responsible for monitoring actions taken on your behalf via the Activity log.
We do not use your content to develop, improve or train AI or machine-learning models, and we do not transfer your content to any third party that would use it to train their models. This applies unconditionally to data obtained from Google Workspace APIs (including Google Calendar): such data is never used for model development or training, and is used solely to provide the user-facing features you have asked for.
Google Workspace APIs - Limited Use. Emily's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
5. Third-Party Data Sharing
We share data with the following categories of third parties, solely to provide the Service:
- Google Cloud Platform / Firebase: infrastructure (compute, database, authentication). Data is stored in europe-west2 (London).
- Google Gemini (Gemini Developer API): AI processing of your email content and instructions.
- Mailgun (Sinch, EU region): our email transport provider for sending and receiving Emily's emails on the emily-wrf.com domain (including inbound mail routed to your Emily address). Message content, headers, attachments and sender/recipient addresses are processed by Mailgun in the EU to deliver the Service.
- Microsoft 365 (Graph API): calendar events and Teams meeting links, both for WRF's own service tenant and, if you connect a Microsoft calendar, for your own calendar (see section 13).
- Google Calendar API: if you connect a Google calendar, to read your availability and create/manage events and Google Meet links on your behalf (see section 13).
- Apple iCloud (CalDAV): if you connect an Apple calendar with an app-specific password, to read your availability and create/manage events (see section 13).
- Zoom (API): if you connect a Zoom account, to create Zoom meetings on your behalf and read your Zoom account email at connection (see section 13).
- Stripe: payment processing. Stripe is a data controller for card data under their own privacy policy.
Each third-party provider processes data under their own data processing agreements and privacy policies. We may also share data with third-party individuals (e.g., the person you ask Emily to email), but only in order to carry out your instructions.
6. International Transfers
Your data is primarily stored and processed in the United Kingdom (europe-west2, London). Some processing may occur in the United States (e.g., Stripe, Google Gemini Developer API infrastructure). We ensure appropriate safeguards are in place for any international transfers, including standard contractual clauses or adequacy decisions as applicable.
7. Data Retention
We retain personal data for as long as your account is active. Data that is regularly used continues to be retained while you use the Service; data is automatically deleted on the following schedules:
- Short-lived processing records (such as inbound-message deduplication and pending confirmations) are purged within days.
- Account data, content, activity history, logs and automations are retained for up to 6 years from their last use, then automatically deleted. Records that you keep current (for example saved files, memories, contacts and active automations) are retained for as long as you continue to use them.
Upon account closure:
- Account deletion or cancellation: when you delete your account (or it is closed), your account data is retained for 12 months for accounting, legal and dispute-resolution purposes, and is then permanently deleted. You can reactivate at any time before then.
Billing records are retained for the period required by UK tax law. You may submit a deletion request at any time by emailing help@emily-wrf.com; we will action it in line with the periods above and your statutory rights.
8. Your Rights Under UK GDPR
Subject to applicable law, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your personal data where there is no compelling reason for continued processing.
- Restriction: request that we restrict processing of your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format.
- Object: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on your consent, withdraw it at any time.
To exercise any of these rights, email help@emily-wrf.com. We will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Security
We implement appropriate technical and organisational measures to protect your data, including encryption of data in transit (TLS) and at rest, OAuth token encryption using Google Cloud KMS, role-based access controls, and audit logging. No method of transmission over the internet is entirely secure; we cannot guarantee absolute security.
10. Cookies and Analytics
We use cookies and similar technologies for the following purposes:
- Strictly necessary: authentication tokens and session management cookies, required for the Service to function. These cannot be disabled.
- Analytics: we use Google Analytics 4 (GA4) on our marketing pages (e.g. the homepage) to understand how visitors interact with the site. GA4 may set cookies and collect data such as page views, session duration, and approximate location. This data is processed in aggregate and is not used to identify individual users, serve advertising, or sell data to third parties.
To opt out of Google Analytics, you can install the Google Analytics Opt-out Browser Add-on, or browse in your browser's private or incognito mode. We do not use advertising cookies.
11. Children
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately.
12. Organisations and Enterprise Accounts
Where Emily is used by an organisation, member accounts are grouped under that organisation's admin, billing and policy layer. If your account belongs to an organisation (including where you join automatically by signing up with a verified organisation email domain, or by accepting an invitation):
- Your organisation's admins can see your usage and activity at the organisation level, manage your display name and Emily address, set organisation-wide rules and memory that apply to your assistant, and set the communication policy (including restricting Emily to internal recipients).
- Organisation-wide memory and rules created by your admins are shared with, and applied to, all members' assistants.
- Billing is handled at the organisation level. We share organisation billing and usage information with the organisation's admins and process it to issue invoices.
- For your organisation's members, WRF acts as processor on behalf of the organisation for the content processed under the organisation's instructions, and as controller for account, security and billing data. The organisation is responsible for having a lawful basis to add members and to process the data it directs Emily to handle.
If you have questions about your organisation's use of Emily or wish to exercise your rights, contact your organisation admin or email us at help@emily-wrf.com.
13. Connected Calendars and Meeting Providers (Microsoft, Google, Apple, Zoom)
You may optionally connect one or more calendars so Emily can read your real availability and manage meetings for you, and optionally a Zoom account so Emily can add a Zoom link to the meetings she arranges. Connecting is entirely optional; the Service works without it.
- How you connect. Microsoft and Google calendars are connected using OAuth 2.0 - you sign in with the provider and grant consent in your browser; we never see your password. Apple iCloud calendars are connected using an app-specific password you generate at appleid.apple.com and enter in Settings.
- What we access. Only your calendar data: your free/busy times and event details (times, titles, attendees, locations and meeting links) across the calendars you connect, and the ability to create, update and cancel events and generate online meeting links (Microsoft Teams or Google Meet). We request the minimum scopes needed for this - for Microsoft, Calendars.ReadWrite and OnlineMeetings.ReadWrite; for Google, the Calendar events and free/busy scopes. We do not request or access your email, mailbox, contacts or files through these calendar connections.
- How we use it. Solely to provide the scheduling features you ask for: showing your availability, summarising your schedule, proposing meeting times, and creating or changing calendar events on your behalf. We do not use connected-calendar data for advertising, we do not sell it, and we do not use it to train or fine-tune AI models.
- How we store it. OAuth access and refresh tokens (and the Apple app-specific password) are envelope-encrypted with Google Cloud KMS and stored in the United Kingdom; they are never exposed to your browser or shared with third parties. Calendar contents are processed transiently to answer your requests and are not retained beyond what is needed to provide the Service.
- Connecting Zoom. Zoom is connected using OAuth 2.0; you sign in with Zoom and grant consent in your browser, and we never see your password. We request only the minimum scopes needed - meeting:write:meeting to create a meeting on your account, and user:read:user to read your account email once so we can show which Zoom account is linked. When you ask Emily to arrange a meeting, she creates a Zoom meeting on your account and places the join link in the calendar invitation. We do not read, list or modify your existing Zoom meetings, and we do not access recordings, participants, chat or account settings. Your Zoom OAuth tokens are envelope-encrypted with Google Cloud KMS and stored in the United Kingdom, and the join links of meetings Emily creates are retained only to reuse in related messages. We do not use Zoom data for advertising, we do not sell it, and we do not use it to train or fine-tune AI models.
- Disconnecting. You can disconnect any calendar or your Zoom account at any time from Settings → Calendars & scheduling (or by asking Emily). Disconnecting revokes our access with the provider and deletes the stored tokens. You can also revoke access directly in your Microsoft, Google, Apple or Zoom account security settings.
Google API Services Limited Use. Emily's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide and improve the scheduling features you request, do not transfer it except as necessary to provide the Service or as required by law, do not use it for advertising, and do not allow humans to read it except with your consent, for security, to comply with the law, or where the data is aggregated and anonymised.
14. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by email or via the Service at least 14 days before the changes take effect.
15. Complaints
If you have a concern about how we handle your personal data, please contact us first at help@emily-wrf.com. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. Details at ico.org.uk/make-a-complaint. ICO helpline: 0303 123 1113.