This article explains, in plain language, how SmartReplyAssistant handles your data and how that maps to the GDPR. It is meant to help you understand and configure the product. It is not legal advice and does not replace your own data protection assessment.
What data is processed
SmartReplyAssistant is built to touch as little data as possible, and only when you ask it to. Two kinds of content are involved:
- The email text you choose to assist. When you click to draft, summarize or translate, the relevant message text is sent to the AI model so it can produce a reply. Nothing is processed in the background and nothing is sent until you trigger an action.
- Your knowledge base. The answers, policies, prices and phrasings you save are stored so drafts can be grounded in your real content instead of generic prose.
We do not scan your whole mailbox, and the assistant skips no-reply and automated senders by default, so it only engages where a human reply is actually needed.
Your knowledge is per-workspace and you control it
Knowledge entries belong to a single workspace. They are not shared across tenants and are never used to train a shared model. Within a workspace, roles (owner, manager, editor, member) decide who can read or change entries, so a team keeps one consistent, controlled source of truth.
You can add, edit and delete knowledge entries at any time. Deleting an entry removes it from future drafts immediately - there is no hidden copy kept to keep generating from.
Cache hits do not re-send your data
To keep things fast and inexpensive, SmartReplyAssistant can reuse a previously computed result when the same input appears again. A cache hit means the answer is served from that stored result - your email text is not sent to the AI provider a second time. Less data in transit means a smaller processing footprint, which is good for both speed and privacy.
Managed AI vs. your own AI
You choose where the AI runs.
- Managed AI provider (default). Your selected message text is sent to a vetted AI provider to generate the draft. This is the simplest setup and requires no infrastructure from you.
- Your own AI (add-on). With this option the model runs on self-hosted Ollama on EU servers. In this mode no data leaves your infrastructure - the email text and knowledge stay entirely within systems you control. This is the strongest option for data sovereignty and strict GDPR setups.
Where data lives and how to remove it
Use this table as a quick map of what is processed, where it lives, and how you remove it.
| Data type | Where it lives | How to remove it |
|---|---|---|
| Email text you assist | Sent transiently to the AI provider (or your own Ollama); not stored as a mailbox copy | Nothing to delete on your side; with your own AI it never leaves your servers |
| Knowledge base entries | Within your workspace | Delete the entry, or delete the whole workspace |
| Cached results | Short-lived cache keyed to the input | Expires automatically; cleared when entries change |
| API / access token | Your account settings | Revoke or rotate the token in settings |
| Account & workspace | Your SmartReplyAssistant account | Delete the workspace or close the account |
Deleting your data or your token
You stay in control of everything you put in:
- Delete a knowledge entry to drop it from all future drafts at once.
- Delete a workspace to remove its entire knowledge base in one step.
- Revoke or rotate your token in account settings to cut off API access immediately - useful if a token was exposed or a team member leaves.
- Close your account to remove your data end to end.
Because email text is only processed transiently, there is no separate archive of your messages to purge.
DPA / privacy policy
For business use under the GDPR you will typically need a data processing agreement (DPA / AVV) with us. The DPA and our privacy policy describe the legal roles, sub-processors, retention and your rights in full. They are linked in the app footer and on the website - read them alongside this article, which only covers the practical product behaviour.
This article is informational and not legal advice. Your own GDPR obligations depend on your business and use case; please consult your data protection officer or legal counsel where needed.
Ready to try it with privacy built in? Create your free SmartReplyAssistant account and keep your knowledge - and your data - under your control.