• Human-in-the-loop by default. Irreversible or consequential actions (sending, deleting, unsubscribing, paying) always require explicit human confirmation.
• Transparency. Every AI-generated draft, summary, classification or action is labelled.
• Opt-out without degradation. Every non-essential AI feature can be disabled without losing access to core email.
• No advertising use. Your email is never used to train ad-targeting models.
• No silent training on customer content. Individual writing-style models are private to your account and are not used to train other users' models.
• Right to object. Any automated decision with significant effect on you can be contested and reviewed by a human within 5 business days.