1.Who We Are
White Rabbit Foundry Limited ("WRF", "we", "us", "our") operates the Emily virtual assistant service. We are registered in England and Wales. We act as a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For privacy enquiries or to exercise your rights, contact us at: help@emily-wrf.com.
2.Data We Collect
We collect and process the following categories of personal data:
- Account data: name, email address, organisation name (optional), password hash (stored by Firebase Authentication).
- Email content: the content of emails you send to Emily's address, including any attachments, for the purpose of processing your instructions.
- Chat messages: messages you send via the in-app chat interface.
- Third-party contact data: names, email addresses and any details you record (phone, organisation, role, notes) for individuals you ask Emily to contact. Emily also auto-saves a contact (email and a name) for people you email, so it recognises them next time; you can turn auto-save off, edit, or delete any contact from your Contacts page.
- Usage and activity data: actions taken, timestamps, job logs, and usage counts for billing and service improvement.
- Billing data: processed entirely via Stripe. WRF does not store card numbers. We store Stripe customer and subscription IDs.
- Memories: facts and preferences you ask Emily to remember, stored to personalise future interactions.
- Connected calendar data (optional): if you choose to connect a Microsoft, Google or Apple calendar, we access your calendar free/busy information and event details (times, titles, attendees, locations, meeting links) to show your availability and manage meetings, and we create, update or cancel events at your request. We only access calendars; we do not access your email or mailbox through these connections. See section 13.
- Connected Zoom account (optional): if you choose to connect a Zoom account, we create a Zoom meeting on your account when you ask Emily to arrange a meeting, so the join link can be added to the invitation, and we read your Zoom account email address once at connection to show which account is linked. We do not read, list or modify your existing Zoom meetings. See section 13.
- Connected AI assistant access (optional): if you connect Emily to ChatGPT or another compatible assistant, we process connection permissions, short-lived authorisation records and hashed access credentials so that assistant can use the Emily tools you approve. See section 14.
- Technical data: authentication tokens, IP addresses (for security), and error logs.
- Sender authentication results: for email sent to Emily's addresses, we record the sender-authentication checks reported by our email provider (SPF and DKIM results, the sending domains, and any spam classification) so we can tell genuine messages from attempts to impersonate you. See section 9.
3.How We Use Your Data
We process your personal data for the following purposes and on the following lawful bases:
- Providing the Service (contract): processing your emails and instructions, scheduling meetings, setting reminders, sending replies.
- Billing and account management (contract): creating and managing your subscription, invoicing, and billing communications.
- Service communications (legitimate interest): sending operational emails such as confirmations, updates, and security alerts.
- Service improvement (legitimate interest): analysing usage patterns in aggregate to improve performance and features.
- Account security and anti-impersonation (legitimate interest): confirming that you control the email addresses registered to your account, checking sender authentication on inbound email, holding messages that appear to impersonate an account holder so they are not acted on, and checking new sign-ups for signs of automated abuse - so that our sign-up emails cannot be used to flood an address belonging to someone who never asked for them. See section 9.
- Legal compliance (legal obligation): retaining records required by law.
- Beta feedback (consent / contract): if you are a beta participant, we may contact you to request feedback as agreed at registration.
We do not sell your personal data to third parties, and we do not use your content for advertising.
4.AI Processing
Email content, chat messages, and attachments you provide to the Service are processed by AI language models (currently Google Gemini, accessed via the Gemini Developer API) to generate responses and take actions. By using the Service, you consent to this AI processing. AI-generated outputs may not always be accurate; you remain responsible for monitoring actions taken on your behalf via the Activity log.
We do not use your content to develop, improve or train AI or machine-learning models, and we do not transfer your content to any third party that would use it to train their models. This applies unconditionally to data obtained from Google Workspace APIs (including Google Calendar): such data is never used for model development or training, and is used solely to provide the user-facing features you have asked for.
Google Workspace APIs - Limited Use. Emily's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
5.Third-Party Data Sharing
We share data with the following categories of third parties, solely to provide the Service:
- Google Cloud Platform / Firebase: infrastructure (compute, database, authentication). Data is stored in europe-west2 (London).
- Google Gemini (Gemini Developer API): AI processing of your email content and instructions.
- Mailgun (Sinch, EU region): our email transport provider for sending and receiving Emily's emails on the emily-wrf.com domain (including inbound mail routed to your Emily address). Message content, headers, attachments and sender/recipient addresses are processed by Mailgun in the EU to deliver the Service.
- Microsoft 365 (Graph API): calendar events and Teams meeting links, both for WRF's own service tenant and, if you connect a Microsoft calendar, for your own calendar (see section 13).
- Google Calendar API: if you connect a Google calendar, to read your availability and create/manage events and Google Meet links on your behalf (see section 13).
- Apple iCloud (CalDAV): if you connect an Apple calendar with an app-specific password, to read your availability and create/manage events (see section 13).
- Zoom (API): if you connect a Zoom account, to create Zoom meetings on your behalf and read your Zoom account email at connection (see section 13).
- OpenAI / ChatGPT and other assistant platforms: if you choose to connect Emily, the platform receives the Emily tool results you request and sends your instructions to Emily under the permissions you approve. The platform processes that information under its own terms and privacy policy. See section 14.
- Stripe: payment processing. Stripe is a data controller for card data under their own privacy policy.
Each third-party provider processes data under their own data processing agreements and privacy policies. We may also share data with third-party individuals (e.g., the person you ask Emily to email), but only in order to carry out your instructions.
Finding and contacting a local service. If you ask Emily to find a provider such as a cleaner or plumber, she runs a web search (through the AI provider's search grounding) using the type of service and the area you give her, and returns publicly listed businesses and their published contact details. The area you supply may be saved as a note so she does not have to ask again; you can remove it at any time on the Files and memory page. If you then ask her to contact one of them, she emails that business on your behalf, sharing your name and whatever details you asked her to pass on. Emily never contacts a business without your explicit instruction.
6.International Transfers
Your data is primarily stored and processed in the United Kingdom (europe-west2, London). Some processing may occur in the United States (e.g., Stripe, Google Gemini Developer API infrastructure). We ensure appropriate safeguards are in place for any international transfers, including standard contractual clauses or adequacy decisions as applicable.
7.Data Retention
We retain personal data for as long as your account is active. Data that is regularly used continues to be retained while you use the Service; data is automatically deleted on the following schedules:
- Short-lived processing records (such as inbound-message deduplication and pending confirmations) are purged within days.
- Connected-assistant authorisation codes and access tokens expire within minutes. Refresh access normally expires after 30 days unless renewed through use, disconnected or revoked sooner.
- Held-message records (sender address, subject line and authentication result for messages held as possible impersonation - never the message body) and address-confirmation links, which expire within days of being issued.
- Account data, content, activity history, logs and automations are retained for up to 6 years from their last use, then automatically deleted. Records that you keep current (for example saved files, memories, contacts and active automations) are retained for as long as you continue to use them.
Upon account closure:
- Account deletion or cancellation: when you delete your account (or it is closed), your account data is retained for 12 months for accounting, legal and dispute-resolution purposes, and is then permanently deleted. You can reactivate at any time before then.
Billing records are retained for the period required by UK tax law. You may submit a deletion request at any time by emailing help@emily-wrf.com; we will action it in line with the periods above and your statutory rights.
8.Your Rights Under UK GDPR
Subject to applicable law, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your personal data where there is no compelling reason for continued processing.
- Restriction: request that we restrict processing of your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format.
- Object: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on your consent, withdraw it at any time.
To exercise any of these rights, email help@emily-wrf.com. We will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9.Security
We implement appropriate technical and organisational measures to protect your data, including encryption of data in transit (TLS) and at rest, OAuth token encryption using Google Cloud KMS for calendar and meeting-provider connections, hashed credentials for connected-assistant access, role-based access controls, and audit logging. No method of transmission over the internet is entirely secure; we cannot guarantee absolute security.
Confirming your email addresses. Because Emily acts on instructions emailed from your registered addresses, and sends email on your behalf, we ask you to confirm each address you register - your sign-in address and any additional addresses you add. Until an address is confirmed, Emily will not act on instructions sent from it. This prevents someone registering an address they do not control and having your mail treated as theirs.
Screening for impersonation. Our email provider checks the sender authentication (SPF and DKIM) of messages sent to Emily's addresses, and reports the result to us. Where a message claims to come from an account holder but fails those checks, Emily holds it instead of acting on it, and limited details may be reviewed by our team to decide whether it is genuine. That review is limited to the sender address, the subject line, the authentication result and the account concerned - never the message body or any attachments. Messages that pass authentication, and messages from third parties that are not claiming to be an account holder, are not held and are not reviewed. Held-message records are kept in line with section 7.
Screening sign-ups. Anyone can type someone else's address into a sign-up form, and a sign-up email sent to an address that never asked for it is unwanted email however legitimate the sender. When an account is created we therefore check a small number of signals - the shape of the name and address given, the source of the request, and whether a password reset is asked for within minutes of signing up - and where a sign-up looks automated we send only a single message asking the address holder to confirm it. Nothing else is sent until they do, and confirming the address releases everything normally. We record the outcome of that check on the account, and short-lived counts of sign-ups per source address, which expire within days.
This screening applies only to email received at Emily's own addresses. It does not apply to, and never involves, data from your connected calendar, meeting or assistant accounts (see sections 13 and 14).
10.Cookies and Analytics
We use cookies and similar technologies for the following purposes:
- Strictly necessary: authentication tokens and session management cookies, required for the Service to function. These cannot be disabled.
- Optional analytics: with your consent, we use Google Analytics 4 across our website and the signed-in dashboard to understand which pages are visited, what is clicked, and what is typed into our search boxes, so we can improve the product. It stays off entirely unless you accept. We send only the shape of a page address, never the address itself: identifiers, tokens and email addresses in a path are replaced before anything is sent. The one exception is the campaign label on a link - the utm_source, utm_campaign and similar tags we add to our own advertising and referral links, and the click identifiers advertising platforms append to them. We keep those so we can tell which advert, email or website brought you here. They describe the link, not you. Everything else in a web address is discarded before anything is sent, including invitation tokens and confirmation codes, and we never send form entries, the content of your messages, your calendar or meeting data, or anything Emily has processed on your behalf. If you decline, we ask again on your next visit rather than treating one refusal as permanent; if you accept, we remember that until you change it or clear your browser. You can change your mind at any time using Cookie settings in the footer of any page.
- Optional advertising measurement: with the same consent, the OpenAI Ads measurement pixel may record visits to our public marketing pages so we can understand the effectiveness of our advertising. It is not given your Emily content, invite token, dashboard activity or connected-calendar data.
Server-side conversion measurement. When a new account is created, we also report that a registration took place directly from our own servers to the OpenAI advertising measurement service, so that we can tell which advertising leads to sign-ups. This report uses no cookies and no access to your device. It contains a one-way cryptographic hash (SHA-256) of your email address and of your account identifier, never the address itself, together with your IP address, your browser user agent and the page you registered on. We rely on our legitimate interest in measuring the effectiveness of our own advertising, and you may object at any time by contacting us. If you have not accepted optional cookies, we do not include the browser identifier set by the pixel, and we mark the report so that it is used only to count the registration and never for personalised advertising.
Changing or withdrawing your choice. Optional measurement stays off unless you select "Accept optional cookies" in our cookie control. Withdrawing is as easy as consenting: select Cookie settings in the footer of any page, choose "Reject optional cookies", and we stop the optional measurement and delete the analytics cookies already set in your browser. You can also install the Google Analytics Opt-out Browser Add-on.
11.Children
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately.
12.Organisations and Enterprise Accounts
Where Emily is used by an organisation, member accounts are grouped under that organisation's admin, billing and policy layer. If your account belongs to an organisation (including where you join automatically by signing up with a verified organisation email domain, or by accepting an invitation):
- Your organisation's admins can see your usage and activity at the organisation level, manage your display name and Emily address, set organisation-wide rules and memory that apply to your assistant, and set the communication policy (including restricting Emily to internal recipients).
- Organisation-wide memory and rules created by your admins are shared with, and applied to, all members' assistants.
- Team scheduling. When a colleague in your organisation asks their Emily to arrange a meeting with you, Emily may check your availability - the free/busy times from your connected calendars together with your stated working hours - to propose times you are both free, instead of emailing you to ask. Only whether you are free is used: your colleague is never shown why you are busy, and never any event detail - no titles, attendees, locations or anything else from your calendar. This applies only while you have a calendar connected, and your organisation's admins can turn it off for the whole organisation.
- Billing is handled at the organisation level. We share organisation billing and usage information with the organisation's admins and process it to issue invoices.
- For your organisation's members, WRF acts as processor on behalf of the organisation for the content processed under the organisation's instructions, and as controller for account, security and billing data. The organisation is responsible for having a lawful basis to add members and to process the data it directs Emily to handle.
If you have questions about your organisation's use of Emily or wish to exercise your rights, contact your organisation admin or email us at help@emily-wrf.com.
13.Connected Calendars and Meeting Providers (Microsoft, Google, Apple, Zoom)
You may optionally connect one or more calendars so Emily can read your real availability and manage meetings for you, and optionally a Zoom account so Emily can add a Zoom link to the meetings she arranges. Connecting is entirely optional; the Service works without it.
- How you connect. Microsoft and Google calendars are connected using OAuth 2.0 - you sign in with the provider and grant consent in your browser; we never see your password. Apple iCloud calendars are connected using an app-specific password you generate at appleid.apple.com and enter in Settings.
- What we access. Only your calendar data: your free/busy times and event details (times, titles, attendees, locations and meeting links) across the calendars you connect, and the ability to create, update and cancel events and generate online meeting links (Microsoft Teams or Google Meet). We request the minimum scopes needed for this - for Microsoft, Calendars.ReadWrite and, on a work or school account only, OnlineMeetings.ReadWrite (Microsoft offers Teams meeting creation on work and school accounts only, so on a personal Microsoft account we do not request it and access is limited to your calendar); for Google, the Calendar read-only scope (calendar.readonly, which covers reading your event details, your free/busy availability and your calendar list) and the Calendar events scope (calendar.events, to create, update and cancel events). We do not request or access your email, mailbox, contacts or files through these calendar connections.
- How we use it. Solely to provide the scheduling features you ask for: showing your availability, summarising your schedule, proposing meeting times, and creating or changing calendar events on your behalf. We do not use connected-calendar data for advertising, we do not sell it, and we do not use it to train or fine-tune AI models.
- How we store it. OAuth access and refresh tokens (and the Apple app-specific password) are envelope-encrypted with Google Cloud KMS and stored in the United Kingdom; they are never exposed to your browser or shared with third parties. Calendar contents are processed transiently to answer your requests and are not retained beyond what is needed to provide the Service.
- Connecting Zoom. Zoom is connected using OAuth 2.0; you sign in with Zoom and grant consent in your browser, and we never see your password. We request only the minimum scopes needed - meeting:write:meeting to create a meeting on your account, and user:read:user to read your account email once so we can show which Zoom account is linked. When you ask Emily to arrange a meeting, she creates a Zoom meeting on your account and places the join link in the calendar invitation. We do not read, list or modify your existing Zoom meetings, and we do not access recordings, participants, chat or account settings. Your Zoom OAuth tokens are envelope-encrypted with Google Cloud KMS and stored in the United Kingdom, and the join links of meetings Emily creates are retained only to reuse in related messages. We do not use Zoom data for advertising, we do not sell it, and we do not use it to train or fine-tune AI models.
- Disconnecting. You can disconnect any calendar or your Zoom account at any time from Settings → Calendars & scheduling (or by asking Emily). Disconnecting revokes our access with the provider and deletes the stored tokens. You can also revoke access directly in your Microsoft, Google, Apple or Zoom account security settings.
Google API Services Limited Use. Emily's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide and improve the scheduling features you request, do not transfer it except as necessary to provide the Service or as required by law, do not use it for advertising, and do not allow humans to read it except with your consent, for security, to comply with the law, or where the data is aggregated and anonymised.
14.Connected AI Assistants (ChatGPT and Compatible Platforms)
You may optionally connect your Emily account to ChatGPT or another compatible assistant through Emily's plugin. Connecting is optional and Emily continues to work by email and through the dashboard without it.
- How you connect. You sign in to your existing Emily account on Emily's own consent page and approve the listed permissions. The connected platform never receives your Emily password.
- What the platform can access. Identity permission returns your stable Emily user identifier, verified sign-in email and the fact that it is verified so the platform can retain the correct account connection and apply workspace-domain protections. Read permission can return your Emily rules, automations, recent activity, stored-file metadata, contacts, memories and usage. Chat permission can pass an instruction to Emily, which may use credits or, after the platform shows you a prepared plan and you confirm it, cause external actions such as sending email, changing calendar events or managing supported Emily data. Purchases, billing and subscription changes, paid-address changes and account deletion are not available through the connection. The consent page shows the permissions requested before you approve them.
- How credentials are stored. Emily issues random access and refresh credentials and stores only cryptographic hashes of them. Access credentials are short-lived, refresh credentials rotate after use, and detected reuse revokes the whole connection.
- How data is shared. The connected platform receives only the tool result needed for the request you make. Its handling of your prompt and the returned result is governed by that platform's own settings, terms and privacy policy.
- Disconnecting. You can revoke each authorisation from Account settings → Connected assistants, or remove it from the connected platform. Revocation stops refresh access and immediately invalidates the connection credentials. Some platforms may share one authorisation across desktop and mobile.
15.Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by email or via the Service at least 14 days before the changes take effect.
16.Complaints
If you have a concern about how we handle your personal data, please contact us first at help@emily-wrf.com. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. Details at ico.org.uk/make-a-complaint. ICO helpline: 0303 123 1113.