Privacy Policy

Last updated: March 19, 2026

1. Important Information and Who We Are

1.1 Purpose of This Privacy Policy

This privacy policy aims to provide you with information on how EmailAI collects and processes your personal data through your use of our website, our EmailAI services, or when you communicate or interact with us in the course of business.

1.2 Data Controller

If you are a registered customer of EmailAI, we act as the 'data controller' of personal data about you and your use of EmailAI, but as the 'data processor' of personal data in the information you submit to EmailAI to use our products and services (such as information about your emails, email accounts, calendar events, and related data). If we are the data processor of your personal data (i.e., not the data controller), please contact the controller party in the first instance to address your rights with respect to such data.

Company: MB GRIMM.LT

Company Code: 305728699

VAT Code: LT100013931112

Address: Gedimino g. 59, Kaišiadorys, Lithuania

1.3 Contact Details

If you have any questions about this privacy policy, including any requests to exercise your legal rights referred to below, please contact us by email at info@grimm.lt.

You have the right to make a complaint at any time to the State Data Protection Inspectorate (VDAI), the Lithuanian supervisory authority for data protection issues (vdai.lrv.lt). We would, however, appreciate the chance to deal with your concerns before you approach the VDAI, so please contact us in the first instance.

1.4 Changes to the Privacy Policy

This version was last updated on March 19, 2026. If you use our website or the EmailAI services after any changes to this privacy policy have been posted, that means you agree to all of the changes. It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

2. The Data We Collect About You

We may create aggregated, de-identified or anonymized data from the personal data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and share it with third parties for our lawful business purposes, including to analyze, build and improve the EmailAI services and promote our business, provided that we will not share such data in a manner that could identify you.

We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:

3. How Is Your Personal Data Collected?

We use different methods to collect data from and about you, including through:

4. How We Use Your Personal Data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

5. Data Shared with Third-Party AI Models

5.1 Data Shared with AI Models

In order to provide email categorization, draft reply generation, and email analysis functionalities, our service employs machine learning models using third-party AI providers. We require our AI service providers to use your information only for the purpose of providing our Service. We do not allow those providers to train their AI models using your data.

The following data types may be shared with these AI models:

This data is processed for the sole purpose of delivering the services described and is not used for any other functions within the AI models.

5.2 User Consent for Data Sharing with AI Models

Before sharing any of your data with our AI models, we seek explicit user consent. Upon initial setup or significant changes to this privacy policy, a prompt will appear within the app requiring users to consent to data sharing for AI processing.

5.3 Third-Party Data Retention

We have a Zero Data Retention agreement with our AI service provider in which our provider does not store customer API data on their servers.

6. Disclosures of Your Personal Data

We will need to share your personal data with the parties set out below for the purposes set out in section 4 above:

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

7. International Transfers

Some of our service providers processing your personal data on our behalf may be based outside of the EEA, so their processing of your personal data may involve a transfer of data outside the EEA.

Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring that either:

8. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

9. How Long Will We Use Your Personal Data?

10. Your Legal Rights

You have the right in certain circumstances to:

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

11. Contact Us

MB GRIMM.LT

Company Code: 305728699

VAT Code: LT100013931112

Gedimino g. 59, Kaišiadorys, Lithuania

Email: info@grimm.lt