Ezra Mail
FeaturesHow it worksFor teamsSecurityPricing
Sign inStart for free
Documents
  • All documents
  • Terms of service
  • Privacy policy
  • Data processing agreement
  • Sub-processors
  • Security measures
  • Acceptable use policy
  • Cookie policy
Version 2026-10-07 · effective 7 October 2026

This translation is provided for convenience. The Polish version of this document is binding and prevails in case of any discrepancy. Wersja polska

Privacy policy

We explain what data we process, why, for how long and who we share it with — and how to exercise your rights.

Contents
  1. 1. Who the controller is
  2. 2. Two roles: controller and processor
  3. 3. Data, purposes, legal bases and periods
  4. 4. Where we get data from
  5. 5. Recipients of data
  6. 6. Transfers outside the EEA
  7. 7. Your rights
  8. 8. Do you have to provide data
  9. 9. Automated decisions
  10. 10. Security
  11. 11. Changes to this policy

1. Who the controller is

The controller of the personal data of Ezra Mail Users is Operator usługi Ezra Mail (“we”, the “Service Provider”). For personal data matters write to privacy@saauf.xyz. We have not appointed a data protection officer — we are not required to; we handle all matters at this address.

2. Two roles: controller and processor

  • As a controller we process the data of people who have an Account, are invited to an Organization or contact us — for the purposes described in section 3.
  • As a processor we process data contained in an Organization’s mail and settings (e.g. data of the correspondents of a company using Ezra Mail). The Organization (our Customer) is the controller of that data, and we act on its instructions under the data processing agreement.

If you corresponded with a company that uses Ezra Mail and want to exercise your rights, contact that company directly — it decides about your data. If you write to us, we will forward your request to the relevant Organization.

3. Data, purposes, legal bases and periods

PurposeDataLegal basisHow long
Running the Account and providing the ServiceFull name, email, password hash (bcrypt), profile photo, chosen language, roles and permissions, assigned mailbox, last sign-in date, version and date of acceptance of the Terms; if you turn them on — the encrypted two-step verification secret, hashes of backup codes, and public keys and names of passkeysContract — Art. 6(1)(b) GDPR; for people acting on behalf of the Customer — the legitimate interest of the Customer and the Service Provider in performing the contract (Art. 6(1)(f))Until the Account is deleted
Invitations to an OrganizationEmail address of the invitee, role, who sent the invitationLegitimate interest of the Customer in inviting a co-worker (Art. 6(1)(f))Until the invitation is accepted; unused — 30 days after expiry
System messagesEmail, first name, message content (invitations, password resets, notices about changes to the Service)Contract (Art. 6(1)(b))One-time links — until used or expired (reset: 1 hour, invitation: 7 days); the link record — up to 30 days
Security and abuse preventionHashes of the IP address and email address in attempt counters, the Organization activity log (who, what, when), hosting technical logsLegitimate interest — protecting the Service and Accounts (Art. 6(1)(f))Attempt counters — 48 hours; activity log — 24 months; hosting logs — according to the provider’s policy, usually up to 30 days
Billing and Plan changesBilling details provided by the Owner, Plan historyLegal obligation — tax and accounting law (Art. 6(1)(c)), contract (Art. 6(1)(b))Invoices and accounting records — 5 years from the end of the year in which the tax obligation arose; Plan change request — until the Organization is deleted
Contact, complaints and reportsData from correspondence sent to @saauf.xyz addressesLegitimate interest — handling requests and defending against claims (Art. 6(1)(f))Until the matter is closed, then until claims become time-barred (generally 3 years)
Feedback about the ServiceFeedback text and category, the page it was sent from (if you allow it), language, browser, Account and OrganizationLegitimate interest — developing and fixing the Service (Art. 6(1)(f))24 months
AI usage statisticsProvider and model, number of tokens, call result, User — without message contentLegitimate interest — accounting for Plan limits (Art. 6(1)(f))13 months

When the retention period ends, we delete data automatically. Deleting an Account deletes the Account data and the Organizations in which you were the only person. Data in backups disappears as they are overwritten, within no more than 30 days.

4. Where we get data from

You provide most data yourself when creating an Account or using the Service. If someone from an Organization invited you, the inviting person provided your email address and role. Technical data (e.g. a hash of your IP address) is generated automatically when you use the Website.

5. Recipients of data

  • Infrastructure providers we entrust data to: hosting, database and mail delivery — the full list with locations is on the Sub-processors page.
  • The AI provider chosen by the Organization — only the content needed to prepare a reply. When the Organization uses its own key, the provider acts under its agreement with the Organization.
  • The Organization you belong to — its Owners and Administrators see your name, email, role and actions recorded in the activity log.
  • Public authorities — only when required by law.

We do not sell data, do not use it for advertising and do not use message content to train AI models.

6. Transfers outside the European Economic Area

Some of our providers are based in the USA. We transfer data to them on the basis of the European Commission’s adequacy decision (EU-US Data Privacy Framework) for certified providers, or on the basis of standard contractual clauses approved by the Commission (Art. 46(2)(c) GDPR). You can obtain a copy of the safeguards by writing to privacy@saauf.xyz.

7. Your rights

You have the right to:

  • access your data and receive a copy — download it yourself under Account settings → Download my data;
  • rectify your data — change your name and photo in account settings, other data on request;
  • erasure — delete your Account yourself in account settings;
  • restriction of processing and data portability (the export is in JSON format);
  • object to processing based on legitimate interest — on grounds relating to your particular situation;
  • lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) or with the supervisory authority in your country of residence.

We respond to requests without undue delay and no later than within one month. We may ask you to confirm your identity, e.g. with a message sent from the address linked to the Account.

8. Do you have to provide data

Providing your name, email address and password is voluntary, but you cannot create an Account without them. Billing details are required to switch to a paid Plan.

9. Automated decisions

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you (Art. 22 GDPR). Automatic tagging and AI replies in an Organization’s mailboxes are enabled by the Organization as the controller of that data.

10. Security

We use, among other things, encrypted connections (TLS, HSTS), bcrypt password hashes, encryption of stored keys and secrets (AES-256-GCM), isolation of Organization data, optional two-step verification and passkeys, sign-in rate limits and an activity log. Details are in Security measures. Cookies are described in the Cookie policy.

11. Changes to this policy

We update this policy when the Service, the list of providers or the law changes. We announce significant changes in advance by email and on the Website. The effective date of the current version is shown at the top of the page.

Ezra Mail

A team inbox with an AI assistant that writes in your tone — and always leaves you the last word.

Product

  • Features
  • For teams
  • Security
  • Pricing

Account

  • Create an organization
  • Sign in
  • Forgot password

Information

  • Terms of service
  • Privacy policy
  • Data processing agreement (DPA)
  • Sub-processors
  • Security
  • Acceptable use
  • Cookies
© 2026 Ezra MailContact: kontakt@saauf.xyz