🌿

LetEmily Privacy Policy

LetEmily v12.20.2 • Last Updated: August 29, 2026 • Built for GDPR compliance

LetEmily is a product of Bright Root Labs LLC, based in New Jersey, USA. We take your privacy seriously and are committed to protecting the information you share with us. This Privacy Policy is compliant with the EU General Data Protection Regulation (GDPR) and applies to all users worldwide.

🔒 Data Protection Contact

For privacy-related inquiries, data requests, or to exercise your rights: privacy@letemily.com

1. Information We Collect

When you use LetEmily, we collect:

  • Account Information: name, email, login credentials.
  • Manager Notes & Insights: content you enter, upload, or generate in LetEmily, including AI-generated insights and recommendations (such as Emily, the Morning Report, and the Weekly Reflection).
  • Calendar & Meeting Data: if you connect a calendar (e.g. Microsoft 365), the meeting and 1:1 events LetEmily imports on your behalf.
  • Connected Workspace Content: if you connect Slack, the notes and follow-ups you capture from Slack and the reminders/notifications we deliver there.
  • Uploaded Content: images, documents, or files that you choose to upload.
  • Billing Information: handled securely by Stripe (we do not store credit card details).
  • Usage Data: basic analytics on how the service is used (to improve performance and reliability).

2. How We Use Your Information & Legal Basis (GDPR Article 6)

We process your personal data based on the following legal grounds:

Contract Performance

To provide the LetEmily service, generate AI insights, manage your account, and deliver customer support. This is necessary to fulfill our contract with you.

Legitimate Interest

To improve service quality, prevent fraud, ensure security, and conduct analytics. We balance these interests against your privacy rights.

Consent

For marketing communications, optional features, and cookies (where required). You can withdraw consent at any time.

Legal Obligation

To comply with tax, accounting, and other legal requirements.

We do not use customer data to train AI models. All AI requests through OpenAI's API are configured so that your data is not retained for model training.

3. Data Storage, Security & Retention

Data Location & International Transfers

All data is stored on servers located in the United States. If you are located in the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, your data will be transferred to and processed in the United States. We rely on standard contractual clauses and adequacy decisions where applicable to ensure your data receives adequate protection.

Security Measures

We implement multiple layers of security to protect your data in accordance with GDPR Article 32 (Security of Processing):

  • Transport Layer Encryption: All data transmission uses TLS 1.3 with 256-bit encryption
  • Password Protection: Passwords are hashed using bcrypt with cost factor 12 (irreversible, OWASP-compliant)
  • API Token Encryption: OAuth tokens and API credentials are encrypted using libsodium XSalsa20-Poly1305 authenticated encryption with 256-bit keys before database storage
  • Database Security: Binary data (avatars, screenshots) stored in encrypted database with access controls
  • Key Management: Encryption keys are stored securely in environment variables, never in code or version control
  • Regular Audits: Security reviews, vulnerability assessments, and encryption validation
  • Access Controls: Role-based permissions and authentication required for all sensitive operations
  • Audit Logging: Comprehensive logging of data access, exports, and deletions for accountability

Encryption Standards: We use industry-standard encryption algorithms including bcrypt (password hashing), libsodium/XSalsa20-Poly1305 (API tokens), and TLS 1.3 (data in transit). All encryption implementations are regularly tested and validated.

Data Retention Periods

  • Active Accounts: Data retained while account is active
  • Account Deletion: Immediate hard delete with 30-day anonymized audit trail
  • Cancelled or Expired Subscriptions: Your account continues on the Free plan and your data is retained: your people, notes, meetings and commitments are not deleted. Deletion happens only when you delete your account
  • Login Attempts: 90 days
  • AI Conversation Cache: 30 days
  • Deleted Conversations: 60 days before permanent removal
  • Encrypted Backups: 90 days maximum
  • Cookie Consents: 13 months from last consent

Data Breach Notification: In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of discovery, as required by GDPR Article 33.

4. Data Processors & Third-Party Services

We do not sell your personal information. We work with the following GDPR-compliant data processors:

OpenAI (United States)

AI processing for insights and conversations. Your data is not used for AI training. Data Processing Addendum in place.

Stripe (United States)

Payment processing. PCI-DSS compliant. We do not store credit card details.

Microsoft 365 (Optional)

When you connect Microsoft 365, LetEmily imports your upcoming meetings and 1:1s from your calendar, and can create Teams meeting links and back up notes to OneDrive. Only the calendar and account data you authorize is accessed; OAuth tokens are encrypted at rest.

Slack (Optional)

When you connect Slack, LetEmily can send meeting reminders and Emily notifications to you, and let you capture notes and follow-ups directly from Slack. Captured content is stored in your LetEmily workspace; OAuth tokens are encrypted at rest.

Other Integration Partners (Optional)

Google Workspace and Zoom for meeting links and file backup. Only data you authorize is shared.

Email Delivery Services

For transactional emails and notifications.

We may also share data when:

  • Required by law, court order, or legal process
  • To protect our rights, property, or safety
  • In connection with a business transaction (merger, acquisition)

5. Uploaded Content Policy

  • You are responsible for any content you upload.
  • Content must not violate laws, infringe on others' rights, or contain harmful or abusive material.
  • Uploaded documents and images may be processed by AI to provide insights within LetEmily.

6. Age Restrictions

LetEmily is not intended for use by anyone under 18 years old. We do not knowingly collect information from minors.

7. Your Rights Under GDPR

Under GDPR Articles 15-21, you have comprehensive data protection rights:

Right to Access (Article 15)

Request confirmation of what data we process and receive a copy. Available via Settings > Privacy & Data.

Right to Rectification (Article 16)

Correct inaccurate or incomplete data. Update your profile anytime in Settings.

Right to Erasure (Article 17)

Request deletion of your data ("right to be forgotten"). Use Settings > Privacy & Data > Delete Account for immediate hard delete.

Right to Restrict Processing (Article 18)

Request we limit how we use your data while resolving disputes or verifying accuracy.

Right to Data Portability (Article 20)

Receive your data in machine-readable JSON format. Available via Settings > Privacy & Data > Export My Data.

Right to Object (Article 21)

Object to processing based on legitimate interest or for direct marketing purposes.

Right to Withdraw Consent

Withdraw consent anytime for cookie tracking, marketing emails, or optional features.

How to Exercise Your Rights:

  • Most rights available directly in Settings > Privacy & Data
  • Email privacy@letemily.com for complex requests or questions
  • We respond within 30 days per GDPR Article 12
  • If unsatisfied with our response, you may lodge a complaint with your data protection authority

8. Ask Emily: AI-powered leadership support

Data Collection

When you use Ask Emily, we collect:

  • Chat Conversation Content: Your messages, questions, and AI-generated responses.
  • Conversation Metadata: Timestamps, conversation titles, and usage patterns.
  • User Preferences: Your interaction patterns and feature engagement data.
  • Team Context: Information about team members when explicitly referenced in conversations.
  • Usage Analytics: Feature engagement and conversation frequency for service improvement.

Data Retention

  • Active Conversations: Stored until user account termination or manual deletion.
  • Deleted Conversations: Retained for 60 days before permanent deletion.
  • Analytics Data: Aggregated and anonymized after 90 days for service improvement.

Data Usage

We use Ask Emily data for:

  • Providing leadership guidance drawn from your own team context.
  • Service improvement and feature development based on usage patterns.
  • User experience personalization and conversation continuity.
  • Security monitoring and abuse prevention.
  • Customer support and troubleshooting when requested.

Important: Ask Emily conversations are processed through AI services for generating responses. While we implement privacy safeguards, avoid sharing highly sensitive, confidential, or regulated information through Ask Emily.

Emily & AI-Generated Insights

Beyond Ask Emily, LetEmily generates insights and recommendations from the notes, meetings, commitments, and team context you record. These power features such as Emily (your recommended next conversations), the Morning Report, the Weekly Reflection, and team insight reports.

  • Many insights (including Emily recommendations, the weekly reflection and the Worth Noticing signals) are computed deterministically from your own data, without any external AI call.
  • Where AI narration is used (for example, the Morning Report summary), requests run through OpenAI's API and are not retained for model training.
  • Insights are visible only to you and are derived solely from your own workspace: they are never shared with other managers or used to build cross-customer profiles.

Your data is never used to train AI models, and AI-generated insights remain private to your account.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you before they take effect.

Contact Information

Privacy & Data Protection: privacy@letemily.com

General Support: support@letemily.com

For exercising your GDPR rights (access, deletion, portability), use Settings > Privacy & Data or email privacy@letemily.com.

Record of Processing Activities: View our GDPR Article 30 compliance documentation