Legal

Privacy Policy

Last updated: June 26, 2026

1. Information We Collect

Account Information

We collect your email address when you create an account. This is used for authentication and account management.

Content Data

We process documents and text you upload to analyze writing style and generate content. This includes:

2. How We Use Your Information

Your information is used exclusively to provide and improve the Husia service. We never sell your data to third parties.

Your information is used to:

3. Data Storage and Security

Your data is stored securely on our servers. We implement industry-standard security measures including:

4. Third-Party Services

We use OpenAI's API to process your content for style analysis and generation. Your content is transmitted securely and processed according to OpenAI's privacy policy.

5. Data Retention

We retain your account information and uploaded content as long as your account is active. You may delete your account and data at any time.

6. Your Rights & Choices

Depending on where you live, you have rights over your personal data, including the right to:

You can exercise most of these directly from your account page (including deleting your email-voice data or your entire account), or by emailing [email protected]. If you are in the EU/UK (GDPR) or California (CCPA/CPRA), these rights apply to you, we respond within the timeframes the law requires, and you may also lodge a complaint with your local data-protection authority. We do not use your data for automated decision-making that produces legal effects.

Children's privacy

Husia is intended for users 18 and older and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact [email protected] and we will delete it.

International data transfers

Husia is operated from, and stores data in, the United States. If you access the Service from outside the U.S., your information may be transferred to and processed in the U.S. and other countries where we or our sub-processors operate, which may have different data-protection laws. We rely on appropriate safeguards (such as standard contractual clauses where required) for such transfers.

Cookies & local storage

We use only a minimal set of cookies and browser local storage that are strictly necessary to operate the Service — for example, to keep you signed in (an authentication token) and remember your selected writing style. We do not use third-party advertising or cross-site tracking cookies. Our hosting/CDN provider may set basic operational cookies for security and performance.

7. Changes to This Policy

We may update this privacy policy occasionally. We will notify users of significant changes through the application.

8. Contact Us

Husia is operated by Cai and Vitaldevara Holdings LLC, a California limited liability company (United States), which is the data controller for the personal data described in this policy. For privacy-related questions or requests, contact us at [email protected].

9. Google User Data & Limited Use

Last updated: 2026-06-26

What Google data we access

When you connect your Google account to use the Husia Gmail add-on, we request a single restricted scope:

The Husia Gmail add-on inserts the generated draft into your Gmail compose window using Google's narrow add-on action scope (gmail.addons.current.action.compose), limited to the message you are actively composing — it inserts editable draft text only and never sends mail. We do not request send, modify, delete, full-mailbox, or broad compose scopes, and we do not access your received inbox, labels, contacts, calendar, Drive, or any other Google account data.

How it is used

Google user data accessed through these scopes is used solely to generate email drafts in your writing voice inside Gmail. Husia's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

Limited Use commitments

In accordance with Google's Limited Use requirements, we commit to the following:

How it is stored and protected

OAuth tokens for your Google account are encrypted at rest with AES-256-GCM; we never log tokens, OAuth codes, or email bodies. Retrieved sent-email content, derived numeric style profiles, and embeddings are stored in our database (Supabase) with encryption at rest, and all data in transit is protected with HTTPS/TLS.

Retention and deletion

Sent-email content retrieved to build your writing style model is stored in our database for as long as your Google account remains connected to Husia. When you disconnect your Google account, we make a best-effort call to revoke our token at Google and immediately delete the stored sent-email content from our database; the same purge occurs when you delete your Husia account. In all cases, deletion completes within 30 days at the latest.

You can also revoke Husia's access at any time from your Google Account at myaccount.google.com/permissions. To request deletion of your Google user data, contact us at [email protected] and we will process the request within 30 days.

Sub-processors that handle Google user data

10. Microsoft User Data (Outlook Add-in)

Last updated: 2026-06-26

What Microsoft data we access

When you connect your Microsoft account to use the Husia Outlook add-in, we request the following delegated Microsoft Graph permissions:

We request read-only mail access — we do not request Mail.Send, Mail.ReadWrite, or any write permission. We never send mail on your behalf; drafts are inserted into your compose window for you to review and send yourself. We do not access your received inbox beyond the conversation you are replying to, and we do not access your calendar, contacts, files, or any other Microsoft account data.

How it is used, stored, and protected

Microsoft user data accessed through this permission is used solely to generate email drafts in your writing voice inside Outlook. We store cleaned sent-email text, basic metadata (recipients, subject, date), and derived style signals (numeric style profiles and embeddings). OAuth tokens are encrypted at rest with AES-256-GCM. New sent mail syncs when you use the add-in, plus a daily background check while your account is connected.

Retention and deletion

Sent-email content retrieved to build your writing style model is stored for as long as your Microsoft account remains connected to Husia. Disconnecting your Microsoft account from the add-in immediately deletes your stored Outlook-sourced email content and encrypted tokens; deleting your Husia account removes all stored email content. You can also revoke Husia's access at any time from your Microsoft account's privacy settings (account.microsoft.com/privacy), and you may request deletion at [email protected] — we process such requests within 30 days.