Legal

Privacy Policy

Last updated: July 2026

This is a draft template provided for the working prototype. Have it reviewed by counsel \u2014 and aligned to the jurisdictions you operate in \u2014 before relying on it for a live product.

1. What we collect

Account data (name, work email, company name, hashed password) when you register; mailbox connection details (host, port, username, and an encrypted credential) when a Company Admin provisions a mailbox; and the content of messages sent and received through connected mailboxes, for archival purposes.

2. How mailbox credentials are protected

Credentials are encrypted at rest using AES-256 envelope encryption and are only ever decrypted in memory, inside the backend mail-worker process, to authenticate to your mail host. They are never returned in any API response or shown in the UI after initial entry.

3. How archived message data is used

Archived messages are used solely to provide the service to your company: display in the employee webmail view, search, compliance export, and retention/legal-hold enforcement. We do not use message content to train models or for advertising, and Convicle products do not carry ads.

4. Who can access archived data

Employees can see their own mailbox. Company Admins can access their company's archive and audit log. Convicle Super Admin / Support access to message content is logged and requires justification — see the audit trail described in our technical documentation.

5. Data retention

Retention is configured per company by your Company Admin. On contract termination, data is available for export for a defined window before permanent deletion.

6. Your rights

Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your personal account data. Contact your Company Admin or hello@convicle.com to exercise these rights.

7. Contact

Questions about this policy can be sent to hello@convicle.com or via the contact page.