What we access, and why
When you connect an account (today that's Gmail, with Google Calendar included in the same connection), Beemy starts read-only. It reads what it needs to triage, learn your voice, and draft on your behalf, before it ever sends, replies, or changes anything.
Outlook/Microsoft 365, Slack, Google Docs, RSS feeds, Reddit, newsletters, a mobile companion and a browser extension are rolling out, each as it clears its own safety gate. See the current status of every integration on Integrations.
We also collect what you give us directly: your name and email if you join the waitlist or use the contact form, and whatever you tell us in that message.
You can see exactly what's connected. To take one source away, you erase the silo that holds it: see Leaving for how that works.
How we use your data
Your data is used for one purpose: to serve you. It powers triage, drafts in your voice, digests, reports, and the escalations that reach you with a plain "why this reached you."
What Beemy learns from your corrections (an edited draft, a re-prioritised item, a skipped digest entry) makes it more accurate for you. It is never used to train shared models, and it is never sold, to anyone, for any reason.
The silo model
Personal, work and public knowledge live in architecturally separate stores — not a shared database with a privacy toggle on top. A work reply can't surface your personal life, and a personal message can't surface your work, because there is no path between them to leak across.
Read more about why we built it this way in our manifesto, or see the mechanics on Trust & Security.
How your data is stored & secured
Every byte moving between you and Beemy travels over TLS 1.3. Stored data is encrypted at rest with AES-256 (the same standard banks use), with access controls limiting who and what can reach it.
For enterprise tenants, data, encryption keys and model inference can additionally be pinned to a region. See Enterprise.
Retention & deletion
We keep your data for as long as your account is active, so Beemy can keep doing its job. You can erase one silo without closing your account. Your work data can go while your personal data stays.
Ask us to delete your account, and your data, drafts and history all go with it. Deletion is complete, not a soft flag on a database row: every row is purged and the encryption key destroyed.
One record survives on purpose: the audit trail that proves the deletion happened. See Leaving for the full exit path, what each move does, and exactly what that one surviving record holds.
Service providers & sub-processors
We rely on a small number of service providers to run Beemy: cloud hosting, and the AI model providers behind triage and drafting. Each operates under contract, is bound to the same never-sold, never-trained-on terms as the rest of this policy, and only processes what's needed to provide the service.
Every one of them is named, with what it can see and where it is based, on our sub-processor register.
Cookies & analytics
This marketing site uses Google Analytics to understand traffic at a page level: which pages get visited, roughly how many people, and where from. It sets first-party cookies to do that. We don't use that data to identify you personally, and we don't sell or share it with ad networks. See Google's privacy policy for how Google handles it, or install the Google Analytics opt-out browser add-on to stop it.
Your rights & controls
You control what Beemy can do through the autonomy dial. Category by category, you decide what stays in your drafts folder for review and what's promoted to act on its own.
You can ask, at any time, to access, export or delete your data. Enterprise tenants can additionally scope data residency to a region: see Enterprise for details.
Children
Beemy is not intended for, and is not directed at, anyone under 18. We don't knowingly collect data from children. If you believe a child's data has reached us, contact us and we'll delete it.
International data & residency
Beemy is built with the same silo isolation available for regional deployment: for enterprise tenants, we can pin data, encryption keys and model inference to a specific region. Outside of that scoped deployment, this isn't a default switched on for every account today (see Enterprise for the full picture).
Changes to this policy
If this policy changes in a material way, we'll update the date below and, where the change is significant, let active users know directly rather than relying on a silent date bump.
Contact
Questions about this policy or your data? Email privacy@beemy.co or use the contact form — every message gets a human reply.