1. Controller and policy details
- Data controller
- Matteo Bobbio
- Postal address
- Via San Carlo 8, Mornese (AL), Italy
- Privacy contact
- borbalf@gmail.com
- Effective date
- 25 May 2018
- Primary jurisdiction
- Italy
You can use the privacy contact for questions, requests, or concerns about this notice and about data processed by AIfred.
2. Why data is processed
AIfred processes data for the purposes below. The applicable legal basis depends on the feature you use and the circumstances of the processing.
- Provide the workspace and sign-in. Create and maintain an account, authenticate through Google or Microsoft, protect access, and link sign-in identities. The usual basis is performance of the service requested by you.
- Organize your information. Store and display topics, notes, messages, attachments, extracted attachment content, agenda items, preferences, and chat action plans so AIfred can provide the workspace features you request. The usual basis is performance of the service.
- Provide AI features. Generate analyses, recaps, and responses from content you make available to AIfred, and record operational usage information needed to provide and monitor those features. The usual basis is performance of the service or your request for a particular feature.
- Connect and import mail. Search or import Gmail and Microsoft mailbox messages when you connect a mailbox and request those actions. The basis is your request and the authorization you give to the relevant provider.
- Send agenda digests and notifications. Use your preferences to prepare and deliver requested notifications or digest messages. The basis is performance of the service and, where required, your preferences or consent.
- Secure and operate AIfred. Maintain sessions, CSRF protection, OAuth state, reliability, abuse prevention, troubleshooting, and legally required records. The usual bases are legitimate interests and compliance with legal obligations.
- Handle support and rights requests. Respond to messages, access requests, corrections, portability requests, deletion requests, and other exercises of your rights. The basis is compliance with legal obligations and legitimate interests in administering the service.
3. Sources and categories of data
Data comes from you, from the sign-in or mailbox provider you choose, from content and actions you submit, and from the technical operation of AIfred. The current local data inventory includes:
- Identity and sign-in identities, including provider subject identifiers and account profile details.
- Profile and preferences, including timezone, digest settings, and chat mutation preferences.
- Topics and content, including notes, emails, metadata, and archived state.
- Attachments and extracted content, including original filenames, metadata, and indexed text where extracted.
- Imported Gmail and Microsoft messages and the metadata associated with an import.
- Agenda items, action keys, and digest data.
- Chat conversations, chat messages, and action plans.
- AI analyses, recaps, generated results, job state, and AI usage records.
- Notifications and notification-delivery records.
- Mailbox connection metadata and encrypted provider credentials used to maintain a connection.
- Technical session, CSRF, and OAuth state used to authenticate requests and complete integrations.
Please do not submit special-category data or other sensitive information unless it is necessary for your requested use of AIfred. Content you submit may contain personal data about you or other people; you are responsible for having an appropriate basis to provide it to AIfred.
4. Recipients, processors, and international transfers
AIfred may involve the following providers or hosting components, depending on the deployment and the features you use:
- Google and Microsoft for authentication and account identity, and Gmail and Microsoft Graph for authorized mailbox access and imports.
- The configured OpenAI-compatible language-model provider for requested AI processing of relevant workspace content and for associated usage information.
- SMTP infrastructure for requested digest and notification delivery.
- Supabase/PostgreSQL for relational data hosting where configured.
- OCI object storage or local blob storage for attachment bytes where configured.
These recipients process data only as needed for the relevant feature or hosting function, subject to their own terms and privacy information and to the configuration selected by the operator. Depending on provider location and deployment, data may be processed outside Italy or the European Economic Area. Appropriate transfer safeguards may be required for a particular deployment; this notice does not claim that every provider-side transfer or retention has been independently certified.
5. Necessary cookies and browser storage
AIfred currently uses only strictly necessary first-party session and security state. The current
inventory includes JSESSIONID, the CSRF cookie XSRF-TOKEN, and authentication or
OAuth session state. These are needed for sign-in, request security, and integrations. No analytics,
advertising, or marketing cookies are currently used.
The site-wide cookie banner summarizes this in plain language and links here for the technical
inventory above. The acknowledgement in the banner is stored only in your browser's
localStorage under a namespaced acknowledgement key. It is not a consent cookie, does not
enable optional tracking, and does not block sign-in or application access. If browser storage is
unavailable, the notice remains visible.
6. Security
AIfred uses authentication, server-side sessions, CSRF protection, OAuth state, access checks, and provider connection controls appropriate to the current application. Provider credentials are handled as encrypted connection data where the configured implementation supports it. No method of transmission or storage is completely risk-free, so keep your sign-in account secure and contact us promptly if you suspect unauthorized access.
7. Retention and deletion
AIfred retains local account data while it is needed to provide the service, to maintain requested integrations, to meet legal obligations, or to resolve disputes. Content and imports remain until you remove them or request account deletion, subject to necessary operational records and backup cycles.
Authenticated users can download a portable export of AIfred-held data, including their owned attachment files, and can request deletion from the account controls. A deletion request disables the local account immediately, signs the browser out, and queues cleanup of local relational data and attachment blobs. Connected Gmail and Microsoft credentials are revoked on a best-effort basis where supported, and local connection data is removed even if a remote provider cannot complete revocation.
The export and deletion features cover data held by AIfred and do not control retention by Google, Microsoft, an LLM provider, SMTP infrastructure, or another external processor. You must also use the relevant provider's controls or contact that provider for provider-side access or deletion.
8. Your GDPR rights
Subject to the conditions and limits in applicable law, you may ask for access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability of data you provided, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it for the future without affecting earlier lawful processing.
To exercise a right, email borbalf@gmail.com with the request, the account or sign-in identity concerned, and enough information to help us understand the scope. We may ask for reasonable information to verify your identity and protect another person's data. We will respond within the period required by applicable law and explain any lawful reason a request cannot be completed as submitted.
You may also complain to the Italian supervisory authority, the Garante per la protezione dei dati personali, through www.garanteprivacy.it, or to the supervisory authority in the place where you live or work, or where you believe an infringement occurred.
9. Changes to this notice
We may update this notice when the service, providers, data categories, or legal requirements change. The effective date at the top will identify the version currently published. Material changes will be communicated through AIfred or another appropriate channel where required.
10. Contact
For privacy questions, rights requests, or concerns about this notice, contact Matteo Bobbio at borbalf@gmail.com or write to Via San Carlo 8, Mornese (AL), Italy. Please do not include passwords, refresh tokens, session identifiers, or other authentication secrets in a message.