Legal · early access
Privacy notice
Effective September 20, 2026 · early-access policy.
Genetech Software Solutions, based in California, United States, operates Email for Agents. This notice covers our website, console, API, MCP connections, and handling of email. A workspace’s operator chooses what mail to send or receive and which people and agents can access it. If you correspond with one of our customers, that customer also controls its own use of your information.
Information we collect and why
- Account information: your sign-in identifier, verified email address, profile details supplied through Clerk, workspace names, memberships, roles, and settings. We use these to sign you in, administer your workspace, and enforce access.
- Email and files: addresses and display names, subjects, bodies, headers, attachments, conversation relationships, and delivery and safety status. We process these to route, store, display, scan, and troubleshoot mail. A restricted copy of an original inbound email may contain transport information beyond the normalized message visible to one inbox.
- Integrations and usage: API-key prefixes and digests, OAuth client and grant records, permitted inboxes, approvals, usage counters, and provider references. We use these to authorize actions, enforce limits, prevent duplicate sends, and investigate problems.
- Network and support information: IP addresses and request information processed by hosting and identity services, application request IDs, errors, security records, and information you include in a support or privacy request. We use these to operate, secure, and support the service.
- Billing, if you later purchase a plan: customer and subscription references, plan, payment status, and transaction records. Paid checkout is currently disabled. Future card entry will use Stripe’s hosted pages; our application does not collect full card numbers through its own forms.
Information comes from you, authorized workspace users and integrations, people who email your inboxes, and our service providers. Our core mail pipeline does not call a language model. An agent you connect may send mail content to its own model or other services. Their processing depends on your configuration and their policies; this notice does not speak for them.
Who can receive information
We transmit messages to the recipients you select and make workspace information available to authorized users, API credentials, agents, and webhook destinations. Email recipients and connected applications may keep their own copies. Revoking access here cannot recall a message or erase a copy already received elsewhere.
Cloudflare provides hosting, networking, queues, and storage; Supabase provides our database; Clerk provides human authentication; and Resend handles live email. Stripe is integrated for future paid billing. The service-provider register explains their roles and links to their policies. Providers may use their own service providers. Operator access to customer information is limited to service administration, support, security, request handling, and other necessary operational work.
We may disclose relevant information when required by law or valid legal process, or when needed to investigate abuse, fraud, or a security incident and protect the service or others. We review the scope of those requests. Ordinary service-provider processing and delivery to your chosen recipients are distinct from advertising uses.
How long information is kept
During early access, retention depends on the purpose and account state rather than a customer-selectable automatic expiry schedule. The following criteria guide retention and manual request review:
- Account and access records: while needed to operate the account, manage authorized access, and resolve account or security issues.
- Stored mail and attachments: while the workspace is active and you use the service for mailbox history, subject to its storage allowance. Closing or deactivating a workspace starts a manual review; it does not automatically erase the stored content.
- Restricted originals, quarantine, and delivery evidence: while needed to resolve mail handling, safety, custody, or abuse issues. These records are included in a deletion review, with any shared-message or legal hold considered separately.
- Security, usage, billing, and request records: for fraud prevention, accounting, resolving disputes, demonstrating request handling, or applicable legal obligations. We limit retained records to what remains necessary. Minimal address-reservation and complimentary-allowance records may remain to prevent address reassignment and repeated free grants.
- Prepared exports: customer download access expires after 24 hours. That access deadline is not an automatic physical-erasure deadline for export objects or the underlying mail.
Deactivation and erasure are different. The current deactivation workflow stops the selected project or workspace and revokes relevant access. Permanent removal from application storage, provider copies, and backups requires operator review and is not a verified automatic feature. We do not promise a seven-day purge, immediate removal from backups, or that deactivation means all copies are gone. A deletion response will distinguish completed actions from retained or pending items and explain the reason where permitted.
Access, correction, export, or deletion requests
- Email support@agents.emailforagents.ai with the subject Privacy request. State what you want to access, correct, export, or delete. Include your workspace ID if you have one; you do not need an account to contact us. Do not email a password, API key, or identity document.
- We review the scope and verify identity and authority using account information and, where needed, a separate confirmation through the account’s verified contact. We request only the additional information needed for the request. An agent acting for you may need to show authorization.
- We identify the relevant data, perform supported actions, and arrange manual handling where required. For data a customer controls, we may coordinate with or direct you to that customer. We do not disclose another person’s mailbox merely because someone asks for it.
- We respond with the outcome, any permitted reason for retaining information or declining part of a request, and next steps for unresolved items. Reply to ask us to review the decision. Applicable legal rights and deadlines continue to apply.
Depending on applicable law, you may have rights to know or access information, obtain a copy, correct it, request deletion, or object to or restrict certain processing. These rights can have exceptions. We do not penalize you for exercising applicable privacy rights.
The console also offers scoped normalized exports and project deactivation. Exports have limits and exclude original MIME, hidden recipient information, attachment file contents, drafts, credentials, and audit logs. They are not a complete mailbox backup and do not replace a privacy request.
Cookies, browser storage, and tracking
Authentication and OAuth use cookies and authorization state. The console stores your selected workspace and project in browser storage. Our current website and application do not include advertising pixels or advertising-audience integrations. Browser Do Not Track signals do not alter the processing needed to provide the service. Hosting and identity providers process device, session, and network activity for their services and may recognize activity across services; see their policies in the provider register. External links and agent applications have their own practices.
Processing locations and security
Our primary Supabase database is in AWS US East (Northern Virginia), us-east-1. This does not mean all information stays there. Cloudflare runs global infrastructure, and our R2 storage has no customer-specific jurisdiction restriction. Email, identity, support, and other provider processing can occur in the United States and other countries. We do not offer an end-to-end data-residency guarantee or a compliance certification.
We use authentication, scoped permissions, access checks, restricted original-message custody, and other controls described on our security page. Internet email is not an end-to-end encrypted vault. No service can promise absolute security.
Account eligibility
Accounts are for people aged 18 or older; the service is not directed to children. A customer’s correspondence may contain information about other people of different ages. If you believe a child has opened an account or that information about a child has been handled inappropriately, contact us so we can investigate and address it.
Changes to this notice
We publish changes here and update the effective date. For material changes, we also notify affected account holders through an account notice or their account email before the change takes effect where required. A new use that requires permission will require that permission; updating this page is not a substitute.
Contact
Genetech Software Solutions · California, United States
For support, privacy requests, or abuse reports, email support@agents.emailforagents.ai. Include your workspace ID when relevant, but never send passwords or API secrets.