Legal
Privacy Policy
Last updated: 4 July 2026
1. What this policy covers
This Privacy Policy explains what data Issary — the desktop app and the issary.com website — collects, why, and what your rights are, particularly if you're in the EU/EEA/UK under the General Data Protection Regulation (GDPR).
2. Your email stays on your device
Issary connects directly from your device to your email provider's IMAP/SMTP servers using the credentials you provide. Those credentials, and your email content, are stored locally on your device and are never uploaded to or stored on Issary's servers.
Semantic search is powered by a local embedding model (Xenova/all-MiniLM-L6-v2) that runs entirely on your device, storing vectors in a local database in your data folder. That pipeline never sends email content anywhere.
3. What is sent off your device, and to whom
- AI drafting, rewriting, and summarization (Free / Pro plans): the relevant email content is sent to our managed AI provider to generate a response. We don't publicly name the specific provider, but it's a mainstream, reputable AI API vendor bound by a data processing agreement with us. Content sent for this purpose is not used to train models and is not retained by us beyond what's needed to serve the request and enforce reasonable usage limits.
- AI drafting, rewriting, and summarization (Unlimited plan): requests go directly from your device to the AI provider you configure with your own API key. Issary is not a party to that transmission or its provider's data handling — review that provider's own privacy terms.
- Account & billing: if you create an Issary account, your email address, display name, and subscription status are stored via Firebase (Google) so we can authenticate you and track your plan. Payment details are handled entirely by Stripe — we never see or store your card number.
- Content moderation: AI requests may be screened by an automated moderation API to detect abusive content before we process it, as part of keeping the managed service safe to operate.
4. Sub-processors
We rely on the following categories of sub-processor to run the Service:
- Google Firebase (Auth, Firestore, Analytics, Cloud Functions) — United States
- Stripe (payment processing) — United States/EU
- A managed AI API provider (Free/Pro plan requests only) — United States
- An automated content-moderation API (abuse prevention) — United States
Where data leaves the EU/EEA, we rely on the relevant provider's Standard Contractual Clauses or equivalent safeguards.
5. Website analytics
The issary.com website uses Firebase Analytics to understand aggregate site usage (e.g. page views). This is only enabled if you accept analytics cookies via the cookie banner — see Cookies below. If you reject or dismiss the banner without accepting, analytics stays off.
6. Legal basis and retention
We process account and billing data under contract (to provide the Service you've signed up for) and legitimate interest (fraud prevention, abuse prevention). We retain account data for as long as your account is active, and billing records for as long as required by tax law. Locally-stored email data and vectors are retained on your device until you delete them or uninstall the app.
7. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about your account;
- Request correction or deletion of that data;
- Request a portable copy of your account data;
- Object to or restrict certain processing;
- Withdraw analytics cookie consent at any time (see below).
To exercise any of these rights, email support@issary.com. If you're in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority — in Sweden, the Swedish Authority for Privacy Protection (IMY).
8. Cookies
The website (not the desktop app) uses the following cookies:
| Cookie | Purpose | Type |
|---|---|---|
| Firebase Authentication session | Keeps you signed in to your Issary account on the website (login, dashboard, billing). | Essential |
| Stripe fraud-prevention cookie | Set during checkout/billing-portal flows to detect fraudulent payment activity. | Essential |
| Firebase Analytics | Aggregate, anonymized site-usage statistics (page views, traffic sources). | Optional — requires consent |
You can change your choice at any time using "Cookie Preferences" in the footer of any page, which re-opens the consent banner.