Legal

Privacy Policy

Last updated: September 16, 2026

Amberis is a unified inbox and assistant made by Flairr. To do its job it reads the mail, messages and calendar events in the accounts you connect. That is a lot of trust, so this page says plainly what we take, why we take it, who else touches it, and how you get it deleted.

This policy covers the Amberis app and this website. If anything here is unclear, write to info@amberis.ai and we will answer in the same plain language.

The short version

  • We read the accounts you connect, and only the ones you connect.
  • Message content is processed by AI providers so we can rank threads, write drafts and answer your questions. It is not used to train their models.
  • We do not sell your data, and there are no ads in the product.
  • This website sets no cookies until you say yes to analytics and advertising measurement, and you can say no.
  • Disconnect a channel and its synced data is deleted after 30 days. Delete your account in Settings and everything goes immediately. No waiting on us.

Who we are

Amberis is a product of Flairr, which acts as the controller of the personal data described here. For questions, requests or complaints, contact info@amberis.ai.

What we access

Nothing is connected by default. Each source is authorised by you, one at a time, through that provider’s own consent screen, and you can revoke it at any point. How we connect walks through the same ground one channel at a time, including how to switch each one off.

Google (Gmail and Calendar)

  • Message headers, bodies, snippets, labels, read and starred state, and attachments in the mailbox you connect.
  • The ability to send and modify mail as you, so replies you approve actually go out and archiving in Amberis archives in Gmail.
  • Calendar events, but only if you separately add the calendar permission. It starts as read-only viewing of your calendars, and if you use scheduling, Google asks again for permission to create events, answer invitations and hold time. Both are optional and the product works without them.

Amberis’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft (Outlook and Teams)

  • Mail in the connected mailbox through Microsoft Graph: headers, bodies, folders, categories, read and flag state.
  • Permission to send and update mail, for the same reasons as above.
  • Calendar events, read and write: viewing the day’s events, and creating them, answering invitations and holding time when you schedule. Microsoft grants this at the first connect rather than when you first use it, because its consent system has no read-only step to upgrade from. Nothing is created or answered without your click.
  • Teams chats and channel messages that your own account can already see, also through Microsoft Graph, plus the directory entries needed to show who wrote what.

You can withdraw a Microsoft connection from Microsoft’s side as well as ours: personal accounts at account.live.com/consent/Manage, work and school accounts at myapps.microsoft.com.

Slack

  • Channels, group conversations and direct messages that your own Slack account can already see. Amberis connects with a user token, so it never sees more of a workspace than you do.
  • Message text, reactions, and the workspace directory entries (display name, email) needed to show who wrote what, plus the workspace name and its custom emoji so messages render as they do in Slack.
  • Files shared in those conversations, listed and fetched so attachments sit with the rest, and files you attach sent with your message.
  • Permission to send messages as you, add reactions, keep read state in step with Slack, and open a direct message when you start one. These are ordinary member permissions, not administrative ones, and nothing goes out without your click.

Derived and account data

  • Contacts built from the people you correspond with: name, email address, and statistics such as how often you reply to them and how quickly.
  • Your account: the email address you sign in with, your workspace name, teammates you invite, and their roles.
  • Product events: which threads you opened, archived, or re-prioritised, and which lists you were shown. These train the ranking on your behaviour. Search queries are deliberately excluded and are never logged.

Why we access it

Every permission above maps to something you can see in the product:

  • Ranking: scoring each thread by likely impact and writing the one-line reason under it.
  • Drafting: writing replies in your voice, learned from your own recent sent messages to that person.
  • The morning briefing: a daily rundown of what moved, plus the day’s meetings and who is in them.
  • Search and Ask: finding messages by meaning as well as keyword, and answering questions with the specific messages that support the answer.
  • Sending and syncing: putting approved replies into the real thread, and keeping read, archive and star state in step with the provider.

We do not use your message content to build products for anyone else, to profile you for advertising, or to train models of our own.

AI processing

Amberis sends message content (subjects, bodies, participant names, calendar event titles and times) to third-party large language model providers so it can score threads, summarise them, write drafts, generate the briefing, and answer questions in Ask. It also creates numerical embeddings of your messages so semantic search can work.

These providers process the content on our instruction and under their API terms, which do not permit using data submitted through the API to train their models. We send only what a given task needs: the thread in question plus a bounded amount of context, never your whole mailbox in one go.

AI output is a suggestion, not an action. No draft is sent, no thread is archived, and no calendar invitation goes out without an explicit click from you. Ranking has a deterministic layer underneath, so the product still orders your inbox if AI processing is unavailable.

Where it is stored

  • Synced mail, messages, contacts, briefings and chat history live in a managed Postgres database (Supabase) dedicated to Amberis.
  • Every table is protected by row-level security, so one workspace cannot read another’s rows even if application code asks it to.
  • OAuth tokens for Google, Microsoft and Slack are encrypted with AES-256-GCM before they are written, and are never stored in plaintext.
  • Calendar events are fetched live when you view them and are not kept, apart from point-in-time snapshots inside a briefing or a saved Ask answer.
  • Traffic to and from the service is encrypted in transit.

Signing in

Amberis uses magic-link sign-in: you enter your email address and we send a one-time link. Google sign-in is available as an alternative. We never store a password, because there is none to store. Sign-in is handled by Supabase Auth on our behalf.

Who else touches your data

We do not sell personal data, and we do not share it with anyone except the providers we need to run the service:

  • Supabase holds the database, authentication and storage.
  • Our AI providers do the ranking, drafting, briefings, embeddings and Ask.
  • Our hosting and email providers run the application and deliver sign-in links.
  • Google, Microsoft and Slack, the sources you connect, receive the actions you take (sending a reply, archiving a thread).

We may also disclose data if the law requires it, or to protect the service and its users from abuse. If Flairr is ever acquired, your data would move with the service and this policy would continue to apply until you are told otherwise.

How long we keep data, and how to delete it

We keep data only while it is doing a job for you. Three clocks govern all of it: the window we sync back to when you first connect, a 30-day grace period after you disconnect a channel, and immediate deletion when you delete your account.

What we hold, and for how long

  • Mail: at first connection we sync roughly the last 90 days from Gmail and Outlook, then keep up with new messages as they arrive. Synced mail is kept for as long as your account is open, because ranking, search and Ask are only useful with that history behind them.
  • Slack: we backfill about 180 days of the conversations your own Slack account can already see, then keep up with new ones. Same rule: kept while your account is open.
  • Calendar events are fetched live each time you view them and not stored, apart from the point-in-time copy that sits inside a briefing or a saved Ask answer.
  • Contacts, drafts, briefings, Ask history and product events are kept while your account is open.
  • OAuth tokens are held encrypted only while the connection is live, and deleted the moment you disconnect.

Disconnecting one channel: 30 days

When you disconnect the last account for a channel, we revoke the grant at the provider straight away and delete its stored tokens. The data already synced from that channel is held for 30 days and then deleted by a daily job: the threads, the messages, the embeddings behind semantic search, and, for Slack and Teams, the workspace directory entries.

You do not have to start in Amberis. Google grants can be removed at myaccount.google.com/permissions, Microsoft grants at account.live.com/consent/Manage for personal accounts or myapps.microsoft.com for work and school accounts, and Slack from your workspace’s own app management page under Settings & administration → Manage apps. The same 30-day clock then applies to the data we already hold.

Reconnect inside those 30 days and nothing is deleted. The window exists because an accidental disconnect would otherwise cost you a full re-sync; it is not a period in which we hold on to data you asked us to drop. If you want the channel gone now rather than in 30 days, delete your account or write to info@amberis.ai and we will purge it by hand.

Deleting your account: immediate

In the app, go to Settings → Workspace → Delete account and type DELETE to confirm. There is no grace period, no soft-delete state and no undo. Someone asking to be forgotten should not have to trust us to remember to forget. On confirmation we:

  • revoke every connected account at Google, Microsoft and Slack, so no live mailbox watch or subscription is left running;
  • delete your user record, which cascades every table holding your data: threads, messages, embeddings, contacts, events, briefings, drafts, Ask history, push subscriptions, connected accounts and retention stamps;
  • delete the login itself, so the sign-in identity is gone too.

Your actual mail is untouched. It stays in Gmail, Outlook and Slack exactly as it was. We are deleting our copy, not yours.

One exception: if you are the last owner or admin of a shared workspace, we refuse the deletion until you hand ownership to someone else. The alternative is stranding your teammates in a workspace nobody can administer, which nothing in the product can undo.

Prefer that we do it, or want an export of your data first? Write to info@amberis.ai. We act within 30 days at the outside, normally within a few days, and we confirm when it is done. There is no charge for it.

Backups and the tail end

Deleted rows can persist in encrypted database backups for up to 30 days before those rotate out. They are not restored into the live service and are not searchable. Server logs record request metadata rather than message content and are kept no longer than 30 days for security and debugging. Where the law obliges us to retain something, or where we need it to defend a legal claim, we keep the minimum for as long as that lasts and nothing beyond it.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing, and complain to your local data protection authority. Send any of these requests to info@amberis.ai and we will answer within 30 days. We will not charge you for making a request, and we will not treat you differently for it.

Erasure and portability do not require a request at all: account deletion is a button in Settings, and an export is one email away. Both are described under how long we keep data. If we ever need to verify who you are before acting, we will ask for the minimum to do it and use it for nothing else.

Other people in your mailbox

Your mail contains other people’s words and addresses. We process them only to give you the service you asked for: ranking, drafting, briefings, search. Never to market to them, and never to build a standalone profile of them. If someone you correspond with asks us about their data, we will normally refer them to you, because it is your mailbox.

Cookies on this website

This website sets no cookies until you choose. On your first visit a small card asks whether we may use Google Analytics and the OpenAI measurement pixel, and nothing from Google or OpenAI loads before you answer.

  • Strictly necessary: your answer is kept in your browser’s local storage (amberis_consent) for 12 months so we do not ask on every page. It holds a yes or no and a date, and it is never sent to us.
  • Analytics, only if you accept: Google Analytics 4 sets the _ga and _ga_* cookies (up to two years) to count visits and tell us which pages people read. Google truncates IP addresses before storing them, and we do not use the data for advertising. Google processes it on our behalf under its data processing terms.
  • Advertising measurement, only if you accept: we advertise Amberis in ChatGPT. The OpenAI measurement pixel sets the __oppref cookie (30 days) and __obref cookie (12 months) so that OpenAI can tell us when a visit that started from one of those ads led to a waitlist signup or a download. We send OpenAI the event and the page. When you join the waitlist we also send a one-way hash (SHA-256) of the email address you entered and of your signup's internal ID, so OpenAI can match the signup to the ad click; the address itself never leaves our site, and we do not use any of this to build a profile of you. OpenAI processes it under its data processing terms.
  • Changing your mind: the Cookies link in the footer reopens the card. Choosing Reject all switches both off at once and deletes the Google Analytics and OpenAI cookies from your browser.

Children

Amberis is a tool for work and is not intended for anyone under 16. We do not knowingly collect data from children.

Changes to this policy

When something that matters changes, say a new category of data, a new provider or a different retention period, we will update the date at the top and tell account holders by email before it takes effect.

Contact

Privacy questions, data requests and complaints: info@amberis.ai.