Privacy Policy

Last updated: March 2026

1. Introduction

Aphra ("we", "our", "us") operates the aphra.me website and the Aphra mobile and web applications (the "Service"). This privacy policy explains how we collect, use, and protect your personal data when you use our Service.

2. Data We Collect

When you use Aphra, we collect:

  • Account information: Your name, email address, and authentication credentials.
  • Connected account data: Metadata from your email and calendar accounts (sender, subject, timestamps, calendar event titles and times). We do not store the full body content of your emails on our servers.
  • Usage data: How you interact with Aphra, including features used, preferences set, and actions taken.
  • Device data: Device type, operating system, and app version for troubleshooting and compatibility.

3. How We Use Your Data

We use your data exclusively to:

  • Provide the AI secretary features (email triage, calendar management, briefings).
  • Improve and personalise the Service based on your preferences.
  • Send transactional communications (account confirmations, security alerts).
  • Comply with legal obligations.

We never sell your personal data to third parties. We never use your email content to train AI models.

4. Data Security

We use industry-standard encryption (TLS 1.3 in transit, AES-256 at rest) to protect your data. Our infrastructure is hosted on SOC 2 compliant providers. We conduct regular security audits.

5. Data Retention

We retain your account data for as long as your account is active. Email and calendar metadata is processed in real time and retained for up to 90 days for feature functionality. You can request deletion of all your data at any time.

6. Your Rights

You have the right to:

  • Access, correct, or delete your personal data.
  • Export your data in a portable format.
  • Withdraw consent for data processing.
  • Lodge a complaint with a supervisory authority.

7. Third-Party Services

Aphra integrates with third-party email and calendar providers (Google, Microsoft, Apple). These integrations are governed by the respective providers' privacy policies. We only access the minimum data necessary to provide our Service.

8. Cookies

Our website uses essential cookies for authentication and session management. We use Plausible Analytics for privacy-friendly, cookie-free website analytics.

9. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or in-app notification.

10. Contact

For privacy-related questions, contact us at privacy@aphra.me.