1. Information We Collect
Account Information
We collect your email address when you create an account. This is used for authentication and account management.
Content Data
We process documents and text you upload to analyze writing style and generate content. This includes:
- Document content and metadata — The text you upload for style analysis
- Writing style analyses — Patterns extracted from your writing
- Generated content — Text created based on your styles and prompts
2. How We Use Your Information
Your information is used exclusively to provide and improve the Husia service. We never sell your data to third parties.
Your information is used to:
- Provide writing style analysis
- Generate content in your writing style
- Maintain your account and preferences
- Improve our service through anonymous analytics
3. Data Storage and Security
Your data is stored securely on our servers. We implement industry-standard security measures including:
- Encrypted data transmission (HTTPS)
- Secure password hashing
- Regular security updates
- Limited access controls
4. Third-Party Services
We use OpenAI's API to process your content for style analysis and generation. Your content is transmitted securely and processed according to OpenAI's privacy policy.
5. Data Retention
We retain your account information and uploaded content as long as your account is active. You may delete your account and data at any time.
6. Your Rights & Choices
Depending on where you live, you have rights over your personal data, including the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete information;
- Delete your account and associated data;
- Export / portability — receive your data in a portable format;
- Object to or restrict certain processing, and withdraw consent (such as disconnecting a connected mail account) at any time;
- Opt out of "sale" or "sharing" of personal data — note we do not sell or share your personal data;
- Non-discrimination — we will not treat you differently for exercising these rights.
You can exercise most of these directly from your account page (including deleting your email-voice data or your entire account), or by emailing [email protected]. If you are in the EU/UK (GDPR) or California (CCPA/CPRA), these rights apply to you, we respond within the timeframes the law requires, and you may also lodge a complaint with your local data-protection authority. We do not use your data for automated decision-making that produces legal effects.
Children's privacy
Husia is intended for users 18 and older and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact [email protected] and we will delete it.
International data transfers
Husia is operated from, and stores data in, the United States. If you access the Service from outside the U.S., your information may be transferred to and processed in the U.S. and other countries where we or our sub-processors operate, which may have different data-protection laws. We rely on appropriate safeguards (such as standard contractual clauses where required) for such transfers.
Cookies & local storage
We use only a minimal set of cookies and browser local storage that are strictly necessary to operate the Service — for example, to keep you signed in (an authentication token) and remember your selected writing style. We do not use third-party advertising or cross-site tracking cookies. Our hosting/CDN provider may set basic operational cookies for security and performance.
7. Changes to This Policy
We may update this privacy policy occasionally. We will notify users of significant changes through the application.
8. Contact Us
Husia is operated by Cai and Vitaldevara Holdings LLC, a California limited liability company (United States), which is the data controller for the personal data described in this policy. For privacy-related questions or requests, contact us at [email protected].
9. Google User Data & Limited Use
Last updated: 2026-06-26
What Google data we access
When you connect your Google account to use the Husia Gmail add-on, we request a single restricted scope:
- gmail.readonly (
https://www.googleapis.com/auth/gmail.readonly) — We read a sample of your own sent emails to learn your personal writing voice and build a private style model used to draft replies. The full message body is needed because writing style cannot be derived from headers or metadata alone.
The Husia Gmail add-on inserts the generated draft into your Gmail compose window using Google's narrow add-on action scope (gmail.addons.current.action.compose), limited to the message you are actively composing — it inserts editable draft text only and never sends mail. We do not request send, modify, delete, full-mailbox, or broad compose scopes, and we do not access your received inbox, labels, contacts, calendar, Drive, or any other Google account data.
How it is used
Google user data accessed through these scopes is used solely to generate email drafts in your writing voice inside Gmail. Husia's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
Limited Use commitments
In accordance with Google's Limited Use requirements, we commit to the following:
- Purpose-limited use — Data obtained via Google APIs is used only to provide and improve the Gmail drafting feature visible to you. It is not used for any other purpose.
- No transfer or sale — Your Google user data is not transferred, sold, or disclosed to third parties, except as strictly necessary to operate the service (see Sub-processors below) or as required by law.
- No advertising — Your Google user data is never used to serve advertisements or for any advertising-related purpose.
- No human reading — Husia staff do not read your email content, except with your explicit consent, to investigate a security incident, or as required by applicable law.
- No AI/ML model training — Your Google user data is never used to develop, train, or improve generalized or non-personalized AI/ML models. It is used only to build the personal style model that drafts your replies. Our LLM and embedding sub-processors are used under terms that prohibit training on submitted content.
How it is stored and protected
OAuth tokens for your Google account are encrypted at rest with AES-256-GCM; we never log tokens, OAuth codes, or email bodies. Retrieved sent-email content, derived numeric style profiles, and embeddings are stored in our database (Supabase) with encryption at rest, and all data in transit is protected with HTTPS/TLS.
Retention and deletion
Sent-email content retrieved to build your writing style model is stored in our database for as long as your Google account remains connected to Husia. When you disconnect your Google account, we make a best-effort call to revoke our token at Google and immediately delete the stored sent-email content from our database; the same purge occurs when you delete your Husia account. In all cases, deletion completes within 30 days at the latest.
You can also revoke Husia's access at any time from your Google Account at myaccount.google.com/permissions. To request deletion of your Google user data, contact us at [email protected] and we will process the request within 30 days.
Sub-processors that handle Google user data
- OpenAI / Anthropic — Email content is sent to LLM and embedding API endpoints to generate drafts and extract style signals. We use these APIs under terms that prohibit training on submitted content.
- Supabase — Our primary database, which stores your style model and any retained sent-email excerpts. Data is stored in encrypted form at rest.
10. Microsoft User Data (Outlook Add-in)
Last updated: 2026-06-26
What Microsoft data we access
When you connect your Microsoft account to use the Husia Outlook add-in, we request the following delegated Microsoft Graph permissions:
- Mail.Read — We read the contents of your Sent Items folder to learn your personal writing voice and build a style model used to draft replies. When you draft a reply, we may also read the messages of that conversation to give the draft context.
- offline_access — Lets us obtain a refresh token so we can sync newly sent mail while your account stays connected, without asking you to sign in again each time.
- openid and profile — Standard sign-in scopes used only to authenticate you and identify your account; we do not build advertising or marketing profiles from them.
We request read-only mail access — we do not request Mail.Send,
Mail.ReadWrite, or any write permission. We never send mail on your behalf; drafts are
inserted into your compose window for you to review and send yourself. We do not access your received
inbox beyond the conversation you are replying to, and we do not access your calendar, contacts, files,
or any other Microsoft account data.
How it is used, stored, and protected
Microsoft user data accessed through this permission is used solely to generate email drafts in your writing voice inside Outlook. We store cleaned sent-email text, basic metadata (recipients, subject, date), and derived style signals (numeric style profiles and embeddings). OAuth tokens are encrypted at rest with AES-256-GCM. New sent mail syncs when you use the add-in, plus a daily background check while your account is connected.
- Purpose-limited use — Data obtained via Microsoft Graph is used only to provide and improve the Outlook drafting feature visible to you.
- No transfer or sale — Your Microsoft user data is not transferred, sold, or disclosed to third parties, except as strictly necessary to operate the service (the same sub-processors listed in Section 9) or as required by law.
- No advertising — Your Microsoft user data is never used for advertising.
- No human reading — Husia staff do not read your email content, except with your explicit consent, to investigate a security incident, or as required by applicable law.
- No AI/ML model training — Your Microsoft user data is never used to develop, train, or improve generalized or non-personalized AI/ML models; it is used only to build the personal style model that drafts your replies.
Retention and deletion
Sent-email content retrieved to build your writing style model is stored for as long as your Microsoft account remains connected to Husia. Disconnecting your Microsoft account from the add-in immediately deletes your stored Outlook-sourced email content and encrypted tokens; deleting your Husia account removes all stored email content. You can also revoke Husia's access at any time from your Microsoft account's privacy settings (account.microsoft.com/privacy), and you may request deletion at [email protected] — we process such requests within 30 days.