Trust & Safety
At Grey AI, our customers trust us with sensitive information. We take that trust seriously, and security isn't something we bolt on later. It's built into how we work from day one.
Connecting your inbox to anything is a real decision, and it deserves a real explanation rather than a wall of certifications you have to decode. So here is how we protect your data, in plain English — the short version first, then the detail behind each promise.
- Private by default. Your data is yours. We don't sell it, we don't share it, and we don't go looking through it.
- We never see your password. Connections are made through OAuth, and you can revoke them the moment you want to.
- Least privilege, always. Our team can reach only the systems their work actually requires.
- Encrypted coming and going. Your data is encrypted in transit and at rest across every provider we rely on. See the note on Telegram below.
- Never used to train AI models. Your data is not used to train AI models. Not by us, and not by the AI providers we build on.
Private by default
Your data is yours. We don't share or sell your information, and we don't access it beyond what's needed to deliver what you've asked us to build or operate.
That isn't a preference we could quietly change our minds about later. It's the boundary the whole service is built upon.
How we connect to your accounts
When our products connect to services like Gmail or Google Calendar, we use OAuth — an industry-standard authorization protocol that means we never see or store your password. You can revoke our access at any time.
It's the same mechanism you already use whenever you sign in to a site with Google. Your password is never typed into anything we control, and the connection ends the moment you decide it should.
Who on our team can see what
Team members only have access to the systems and data their work requires. We apply the principle of least privilege across every engagement — the fewest people, with the least access, for the shortest time that still gets the work done.
We use an enterprise password manager to store and share credentials securely.
Encryption
Your data is encrypted in transit and at rest through each of our sub-processors, as documented in the security pages linked below. In practice, that means your information is protected both while it moves between services and while it sits at rest in storage.
The companies we rely on
The platforms we rely on to run Grey AI — cloud hosting, databases, AI model providers — are established providers with independent security certifications.
You shouldn't have to take our word for any of this. Each one publishes its own security documentation, and you're welcome to read it:
Hostinger · Supabase · Anthropic · OpenAI · Google · Mistral AI · Twilio · Telegram
AI and model training
The AI providers we build on (such as OpenAI and Anthropic) do not train their models on your data under our commercial API terms.
Your family's email is not raw material for somebody else's model. It is used to run your assistant, and that is the end of it.
A note on Telegram
Exhale is also available via Telegram. Telegram encrypts data in transit and at rest, but Exhale conversations on Telegram are not end-to-end encrypted.
We'd rather tell you that plainly here than bury it in a footnote. If it matters to you, use Exhale on the web instead.
Questions, or something to report
Have a security concern or something to report? Reach us at privacy@greyai.ai. We would genuinely rather hear about a problem early than find out about it late.
For details on how we collect, use, and handle your personal information, see our Privacy Policy. For the shorter, more practical questions — what Exhale can see, what it costs, how to disconnect — see the FAQs.
← Back to home