Legal

Privacy Policy

Last updated: July 2026

1. Who we are

Fawz is the data controller for personal data processed through this service. Fawz is an independent software product. Payments are processed by Paddle.com Market Limited, who act as our authorized reseller (Merchant of Record). Contact for privacy matters: support@fawzapp.com

2. Two distinct roles: your data and your customers' data

Fawz handles two separate categories of data, under two different roles: Your account data (you are the data subject): your name, email address, organization details, and subscription information. We are the data controller for this. Your customers' support emails (your customers are the data subjects): the content of emails forwarded through Fawz. For this data, you — the Fawz customer — are the data controller, and Fawz acts as your data processor. You are responsible for having a lawful basis to process your customers' emails and for informing them that their requests are handled by an automated system.

3. What data Fawz receives

When you configure a forwarding rule from your support inbox to your unique Fawz address (inbox-[your-id]@mail.fawzapp.com), every email forwarded to that address is received by Fawz. This includes: - Sender email address and display name - Subject line - Full message body (plain text) - Any content the sender included in their email Important: Fawz receives whatever your forwarding rule sends us. We strongly recommend forwarding only from your dedicated support inbox address, not from a general-purpose inbox that may also receive unrelated sensitive communications (such as internal team emails, password reset links, or financial notifications). You are responsible for scoping your forwarding rule appropriately. We also collect: - Contact memory: to provide context across separate emails, we group messages from the same sender email address within your organization and maintain a history of their previous requests together with an AI-generated summary. - Destination tool OAuth credentials: encrypted at rest using AES-256 for your connected destination tool. You connect one destination tool via OAuth — currently Asana or Jira (a task or project-management app). - Sender identity configuration (optional): if you choose to send replies from your own domain, we store the support email address and sender name you provide, and the DNS verification records generated for your domain. Adding those DNS records to your own domain is how you prove ownership; we never gain access to your email account or mailbox. - Account data: your name, email address, organization name, and subscription plan. - Billing data: name and email for checkout. Payment card details are handled exclusively by Paddle and are never accessible to us. - Usage metadata: request counts, qualification status, attempt counts, and timestamps. - AI cost metering: for each AI call we record how many tokens it consumed, which stage of the pipeline made it, and the request it belonged to. This is used to monitor our own AI costs. It records the SIZE of a message, never its content. - Account passwords: your Fawz account password is hashed using bcrypt via Supabase Auth. We never store or have access to your plaintext password.

4. How we use your data

We use data solely to provide the Fawz service: - Read and parse forwarded support emails to extract the sender, subject, and body. - Send forwarded emails to Google Gemini AI for qualification (completeness classification). - Maintain contact memory per sender to recognize follow-ups and avoid re-asking for information already provided. - Send automated follow-up emails to your customers when information is missing. By default, these are sent from a Fawz sending address (hello@fawzapp.com) showing the sender name you choose, with the Reply-To set to your Fawz inbox address so replies route back to you. If you verify your own sending domain (by adding the DNS records we provide — see below), follow-ups and resolution confirmations are instead sent directly from your real support address. - Create structured tasks in your connected destination tool once a request is complete. - Send a resolution confirmation to the customer when the task is marked complete. - Process subscription billing via Paddle. - Diagnose service issues and improve reliability. We do not use your data or your customers' data for advertising, for training AI models, or for any purpose outside of providing the Fawz service. We do not sell data.

5. Who can see email content

Email content processed through Fawz is accessible to: - Automated systems only (our servers, the Gemini AI API, and your connected destination tool): this covers the normal operation of the service — qualification, task creation, and reply sending. - You and your team members: through your Fawz dashboard, which shows the full request content, the AI analysis, and the whole conversation thread. This is the only interface in Fawz that displays the body of a support email. - Fawz staff, through the internal admin dashboard: our staff tools deliberately do NOT show the content of your customers' emails. The admin dashboard displays only the organization name, the sender's email address, the subject line, the request status and type, the number of follow-up attempts, and timestamps. It does not display message bodies, follow-up messages, the conversation thread, or the AI's analysis of a request. - Fawz staff, at the infrastructure level: the message bodies are of course stored in our database, and staff holding database credentials are technically able to read them. We do not do this as part of normal operation, and never for commercial purposes. It happens only where necessary for security incident response, investigating a specific bug, or legal compliance. We tell you this plainly rather than implying a technical barrier that does not exist. No other third parties have access to email content except as described in section 6 (sub-processors).

6. Third-party sub-processors

To operate Fawz, data is shared with the following services: - Postmark (Wildbit, LLC): all inbound emails arrive via Postmark's inbound email infrastructure. Outbound replies (follow-up questions and resolution confirmations) are sent via the Postmark API. Email content passes through Postmark's servers in transit. If you verify your own sending domain, that domain is registered with Postmark on your behalf so it can be authenticated (DKIM) for sending. - Google AI Studio / Gemini: the subject, body, and thread history of support emails are sent to Google's Gemini API for AI-powered qualification. No account credentials or customer identity data beyond what appears in the email are shared with Gemini. - Your connected destination tool — currently Asana or Jira (the task or project-management provider you choose): we create and update tasks in it on your behalf, using your OAuth credentials. Task content includes the email subject, an AI-generated summary, and relevant details. For Jira, this is an Atlassian OAuth 2.0 connection; because Atlassian requires it, we also store the Atlassian account ID of the connecting user and report it to Atlassian's Personal Data Reporting API so that account closures are honored. - Supabase: all application data (requests, contact memory, organization records) is stored on Supabase-hosted infrastructure. - Vercel: the application is hosted on Vercel's infrastructure. - Inngest: used to run and retry the background jobs that qualify a request and create the task. Inngest orchestrates these jobs and stores the intermediate results of each step so that a failed job can resume where it left off. Those intermediate results include the content of the support email being processed. - Paddle: your name and email address are shared with Paddle for billing and tax compliance. - Resend: used for system notification emails — account confirmation, team invitations, and billing notices such as a usage-limit or overage receipt. Each service operates under its own privacy policy and data processing terms.

7. Data retention

- Active accounts: all request data, contact memory, and qualification history are retained while your account is active. - Operational logs: internal system logs, used to monitor and debug the processing pipeline, are automatically deleted after 90 days. - Connector disconnection: when you disconnect a destination it is deactivated immediately, we revoke its OAuth grant with the provider where the provider supports revocation (Asana, Gmail), and we delete our stored copy of its credentials immediately. Jira/Atlassian does not offer a token-revocation endpoint, so for Jira we delete our stored credentials (you can also remove the grant from your Atlassian account settings). A Jira connection whose Atlassian account is later reported closed is deleted automatically, credentials included. - Account deletion: you delete your account yourself, from Account settings in your dashboard. You do not need to contact us, and you do not need our permission. Deletion is immediate and permanent — it is not a request we review. - What deletion removes: if you are the OWNER of an organization, deleting your account deletes the entire organization and everything in it — every request and its full email content, every follow-up message and event, contact memory, connectors and their stored credentials, usage records, the organization itself, your profile, and your login. If you are a TEAM MEMBER, only your own profile and login are removed; the organization you joined belongs to its owner and is left intact. - Your subscription: if you have an active paid subscription, it is cancelled with Paddle BEFORE any data is deleted, so you cannot end up with data gone and a subscription still billing. If that cancellation fails, the deletion is aborted and nothing is deleted. - Operational logs: internal system logs are retained for up to 90 days (see above). When an organization is deleted they are unlinked from it, so what remains is an operational record with no organization attached. - Backup data: encrypted backups are cycled within 90 days, so a deleted account may persist in an encrypted backup until that cycle completes. If you would rather we did it for you, or you cannot access your account, email support@fawzapp.com.

8. Your rights (GDPR and applicable law)

You have the right to: - Deletion: delete your account and all associated data yourself, at any time, from Account settings in your dashboard. No request, no waiting, no contacting us. - Correction: update your profile and organization information from the dashboard. - Access: request a full export of your data at any time. - Portability: request your data in a structured format. - Objection: object to specific processing activities. Deletion is self-service. For the others — export, portability, objection — email support@fawzapp.com and we respond within 72 hours. For your customers' data (which you control as data controller), you are responsible for responding to their data subject requests. Contact us if you need assistance fulfilling those requests against data stored in Fawz.

9. Security

We implement the following security measures: - Destination tool OAuth tokens are encrypted at rest with AES-256-GCM (authenticated encryption, so a tampered value is detected rather than silently used) before being stored. No plaintext tokens are ever persisted. - Account passwords are hashed via Supabase Auth. We cannot access or recover your password. - All data is encrypted in transit using TLS 1.2 or higher. - Organization isolation is enforced on the server: every API request is authenticated, and the data it touches is checked against the organization you belong to before anything is read or written. Row Level Security is enabled on the database as a second layer, so the public key that ships in the browser cannot read our tables directly. - Inbound email webhooks are authenticated with a secret token, and payment webhooks are verified against a cryptographic signature, so neither can be spoofed. - Access to production infrastructure is restricted to the Fawz team.

10. Cookies

We use only essential cookies required for authentication and session management. We do not use tracking, advertising, or third-party analytics cookies.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you by email when material changes take effect. Continued use of Fawz after that date constitutes acceptance of the updated policy.

12. Contact

For any privacy questions or data requests: Email: support@fawzapp.com Response time: within 72 hours