Only you can see your data.

Remy reads your mail and calendar to work for you. Here is how that access is protected, what we will never do with it, and the controls you hold.

Last updated: August 13, 2026

Three promises

We don’t sell your data.

Not to advertisers, not to data brokers, not to anyone. Your data has one job: helping you.

We don’t train AI models on it.

Your mail, calendar, and conversations never train anyone’s models — not ours, not our providers’. Every AI provider we use is contractually barred from it. See AI model providers.

Nothing sends without your approval.

Remy never sends an email, books an event, places a call, or takes any outward-facing action without your explicit tap on that specific action.

What Remy accesses, and why

Email
Finds what matters, catches you up, drafts replies you approve. Remy indexes message metadata so it can find things fast instead of re-reading your whole inbox.
Calendar
Answers schedule questions, spots conflicts, and books events — writes only after you approve.
Memory
A compact working memory of the people, projects, and preferences that matter to you — scoped to your account, visible only to you, deletable any time.

How it’s protected

  • Encrypted everywhere. TLS 1.2+ in transit; encrypted databases and backups at rest. Your account tokens get a second layer of AES-256-GCM encryption with keys kept outside the database.
  • Isolation enforced by the database itself. Every table with user data uses Postgres row-level security: the database refuses to return another account’s rows, even if the application asked.
  • US-hosted infrastructure. Served from Fly.io and Supabase in the United States.
  • Humans don’t read your data. Production access is limited, logged, and two-factor protected. Nobody reads your mail, calendar, or conversations in the ordinary course of running the Service.
  • Independent security assessment. Remy is completing Google’s OAuth verification for Gmail access, which includes an independent CASA security assessment based on the OWASP ASVS standard.
  • Google API Limited Use. Google user data is used only to provide features you see in the app — never for ads, never sold, never for training.

Your controls

  • Approve every action. Outward-facing actions show you exactly what will happen — recipient, content, time — before you tap approve.
  • Revoke access instantly. From the app, or directly at your Google or Microsoft account — Remy’s access dies with the grant.
  • Delete everything. Delete your account in the app and your data is removed from production systems within 30 days.

The full picture

Every vendor that touches your data: subprocessors. Every AI provider and its retention terms: AI model providers. The legal detail: Privacy Policy.

Found a vulnerability? Email [email protected] and we will respond promptly.