Pre-launch preview — not yet operational. Launching late 2026–2027.

AlecRae

Legal

AI Transparency & Responsible AI

Effective Date: April 16, 2026 · Last Updated: April 16, 2026

AlecRae is an AI-native product. This page describes every AI system we use, how we govern it, and the controls you have over automated decisions. It is intended to satisfy the transparency obligations of the EU AI Act (Regulation (EU) 2024/1689), GDPR Article 22, the NIST AI Risk Management Framework and the ISO/IEC 42001 AI Management System standard.

1. Our responsible-AI principles

Human-in-the-loop by default. Irreversible or consequential actions (sending, deleting, unsubscribing, paying) always require explicit human confirmation.

Transparency. Every AI-generated draft, summary, classification or action is labelled.

Opt-out without degradation. Every non-essential AI feature can be disabled without losing access to core email.

No advertising use. Your email is never used to train ad-targeting models.

No silent training on customer content. Individual writing-style models are private to your account and are not used to train other users' models.

Right to object. Any automated decision with significant effect on you can be contested and reviewed by a human within 5 business days.

2. AI systems inventory

Spam & phishing classifier

Purpose: protect all users. Model: AlecRae-tuned text classifier + signals from SPF/DKIM/DMARC/ARC. Essential — cannot be disabled. EU AI Act risk tier: limited.

Priority inbox / triage

Purpose: rank incoming email by importance. Model: Claude Haiku. Optional. Tier: limited risk.

AI compose & voice profile

Purpose: generate draft replies in the user's style. Models: Claude Haiku / Sonnet / Opus (tier-dependent) + local WebGPU inference when available. Optional. Tier: minimal risk.

Grammar & spell agent

Purpose: proofread outgoing text. Runs locally on the user device via Transformers.js / WebLLM. Tier: minimal risk.

Sender trust & phishing explainer

Purpose: explain why an email is suspicious. Model: Claude Sonnet + DNS + WHOIS signals. Tier: limited risk.

Dictation & transcription

Purpose: speech-to-text for voice composition and voice messages. Model: OpenAI Whisper. Optional. Tier: minimal risk.

Inbox agent (overnight)

Purpose: draft replies and batch morning briefing. Outputs are proposals only and require human approval. Tier: limited risk.

Semantic search

Purpose: natural-language email retrieval. Model: embeddings + Claude Haiku. Optional. Tier: minimal risk.

3. Automated decision-making (GDPR Article 22)

Where an AlecRae system makes an automated decision that produces legal or similarly significant effects on you (for example, classifying a message as spam or blocking a sender), you have the right to:

• Request meaningful information about the logic of the decision.

• Express your point of view and contest the decision.

• Obtain human review within 5 business days of a written request.

Exercise these rights by emailing [email protected].

4. Training data and fine-tuning

• We do not use your individual email content as training data for foundation models.

• We may use aggregated, anonymised patterns (e.g., spam signatures) to improve our own classifiers. You can opt out at Settings > Privacy > AI training.

• Your personal voice-profile fingerprints are stored encrypted and scoped to your account.

• Our third-party model providers (Anthropic, OpenAI) are contractually barred from training their models on our production API traffic.

5. EU AI Act status

AlecRae is a deployer and provider of limited-risk AI systems under the EU AI Act. We maintain:

• An internal AI System Register mapping each model to its risk tier.

• A risk-management process aligned to ISO/IEC 42001 and NIST AI RMF.

• Incident-response procedures to report serious incidents within the 15-day window under Article 62.

• Ongoing monitoring for bias, drift and performance degradation.

6. Reporting an AI harm

If you believe an AlecRae AI system has caused you harm — for example, a critical email was mis-classified as spam and caused you loss — please email [email protected]. We will investigate, respond within 10 business days, and publish an anonymised summary in our annual Responsible AI report.