Privacy Policy
Last updated: September 2026
Overview
AttneX Inc. (we, us, our) operates attnex.ai and the AttneX platform. This policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and how to have it deleted.
AttneX connects to email and calendar accounts at your instruction. Because that is the most sensitive thing the product does, this policy describes it in specific detail rather than in general terms. If you only read one section, read what we access in a connected mailbox.
Information we collect
From the website. Information you type into a contact, partnership, or integration request form: your name, email address, company name, and your message.
To create your account. Your name, email address, and business details such as company name, location addresses, and licence numbers. If you sign in with Google or Microsoft, we receive your name, email address, and profile picture from that provider. Signing in does not give us access to your mail.
Business data you bring. Inventory, sales, purchasing, vendor, labour, and compliance records that you upload or that we sync from systems you connect, such as your point of sale.
From a connected mailbox or calendar. Described in full below.
What we access in a connected mailbox
Nothing in your mailbox is accessible to AttneX until you connect it, and each mailbox is connected for one declared purpose. The purpose decides which permissions we request, and we request no permission a purpose does not need.
Signing in
Permissions requested: your basic profile and email address only. This uses a separate application from the one below, so signing in to AttneX never asks for access to your mail.
A purchasing mailbox, for vendor and purchase order email
Permissions requested: read your mail, send mail as you, and create or update calendar events. On Microsoft accounts the equivalents are Mail.Read, Mail.Send, and Calendars.ReadWrite.
Why: AttneX matches vendor replies to your purchase orders, sends purchase orders and follow ups on your behalf, and puts expected delivery dates on your calendar. Sending is the point of this mailbox, so it is the only kind we send from.
The calendar permission also lets us read the events already on your calendar, so a deadline we add appears in context next to what you have scheduled rather than on a calendar of its own, and so a later update changes the event we created instead of adding a second copy of it. We only change or remove events that AttneX created.
A monitored mailbox, for work email and licence correspondence
Permissions requested: read your mail only. Where the mailbox is also used to track a licence application, we additionally request calendar access, so that a regulator deadline becomes a dated reminder. That access works the same way as above: we read your events to place the reminder in context, and change only what we created.
Why: AttneX identifies messages that need attention, such as a regulator asking for a document by a date, and surfaces them with the deadline attached. We never send, reply, forward, delete, or mark anything as read in a monitored mailbox. The product enforces this, not just our intentions: no code path exists to send from one.
What we store, and what we do not
These two behaviours genuinely differ, so we state both rather than describing the more flattering one.
Monitored mailboxes: we do not store your messages. We store the sender, the subject, the date, and the short summary and classification our assistant produces. The message body is not written to our database. When you open a flagged message in AttneX, the body is fetched from your provider at that moment and shown to you, not saved. Automated tests in our codebase assert that message bodies and model prompts are not stored, and they run against every change.
Purchasing mailboxes: we do store vendor correspondence. To thread a vendor conversation against a purchase order, we store the full text of vendor and supplier messages in your workspace, both received and sent. This applies to the mailbox you designate for purchasing, and to the vendor and supplier correspondence in it.
Automated analysis, and the AI provider
AttneX uses a large language model to read a message and produce a short summary, a category, an urgency, and any deadline it mentions. To do that, the text of the message is sent to our AI provider, OpenAI, over an encrypted connection. Long messages are truncated before they are sent.
Under our agreement with OpenAI, content sent through their API is not used to train their models. We do not store the text we sent or the prompt we built from it; we store only the resulting summary and classification. Analysis of monitored mail runs only where both your organization and a matching rule you configured have enabled it, and it can be turned off.
How Google user data is used
AttneX use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
We use Google user data only to provide and improve the features described above, which you can see in the product. We do not use it for advertising of any kind, and we do not sell it. We do not use it to train generalized artificial intelligence models. We do not transfer it to others except as needed to provide those features (our AI provider and our hosting and database providers, listed below), because you told us to, for security purposes, or to comply with applicable law. No AttneX employee reads your mail except with your explicit permission, for instance when you ask us to help with a specific problem, or where it is necessary for security or to comply with the law.
The same commitments apply to data we receive from Microsoft Graph.
Who we share information with
We do not sell personal information and we do not share it for advertising. We use a small number of service providers to run the product, and they may process your data only on our instructions: our cloud hosting and database providers, our AI provider (OpenAI) as described above, our transactional email and SMS providers for notifications you have enabled, and the systems you explicitly connect, such as your point of sale or a state track and trace ledger.
When AttneX submits to a state compliance system, only the fields that regulation requires are sent. Your pricing, margins, and vendor terms are not included.
How we protect it
Mailbox access tokens, refresh tokens, and integration credentials are encrypted at rest with Fernet symmetric encryption and are decrypted only in memory at the moment they are used. All traffic to AttneX is over TLS. Every record is scoped to your organization, and the identifiers that decide what a request may touch come from our database using your authenticated session, never from the request itself, so one customer cannot reach another customer data. See our Security page for more.
How long we keep it, and how to have it deleted
Disconnect a mailbox at any time. In AttneX, open Settings and disconnect the account. We immediately revoke and delete the stored tokens for it and stop all access. You can also revoke AttneX from your Google account permissions page or your Microsoft account, which has the same effect on our access.
Ask us to delete your data. Email privacy@attnex.ai from the address on your account and tell us what you want removed: a single mailbox history, an employee record, or your entire workspace. We will acknowledge your request when it arrives and complete it within 30 days. We will also send you an export of your workspace data on request.
If a request is genuinely complex, for example deleting an operator with many locations whose records are linked to regulatory filings, we may need longer. In that case we will tell you why and give you a date before the first 30 days are up, and we will not extend by more than a further 60 days. We ask you to confirm your identity before we act, because deletion cannot be undone and an export hands over your business records.
Otherwise. We keep your workspace data for as long as your account is active, because it is the record your business runs on. When an account closes we delete it within 90 days, except where we must keep something longer to comply with law, such as records tied to a regulatory filing.
If your employer monitors your work mailbox
AttneX can be configured by an organization to flag messages in an employee work mailbox. This is worth being plain about, because it involves your data and your employer decision.
A mailbox is only monitored after the person who holds it signs in and grants access themselves; an administrator cannot connect someone else mailbox on their behalf. Monitoring is read only. Only messages matching the rules the organization has configured are surfaced, the message body is not stored, and the mailbox holder can disconnect at any time. If you are unsure what your employer has enabled, ask them, or contact us at the address below.
Children
AttneX is a business product for licensed operators and is not directed to anyone under 18. We do not knowingly collect information from children.
Changes to this policy
If we change how we handle your information in a way that matters, we will update the date at the top of this page and tell account holders by email before the change takes effect.
Contact
For privacy questions, a data deletion request, or an export, email privacy@attnex.ai. For anything else, email hello@attnex.ai.