Privacy information
Privacy notice.
How Ente processes personal data across the website, application, and optional integrations.
1. Controller and roles
The controller for Ente's own processing is TiVA Digital – Valentin Döring, a sole proprietorship / Einzelunternehmen, represented by Valentin Döring. Contact: ente@agentmail.to.
This notice covers ente.fast, app.ente.fast, support, pilot administration, and optional integrations. For content in customer workspaces, Ente generally acts as a processor for the business customer. For website operation, account administration, contract and support communication, security, and Ente's own business records, Ente may act as controller. The order form and DPA govern any different allocation.
2. Data categories
- Account, profile, authentication, role, and workspace data.
- Company knowledge such as people, organizations, projects, activities, notes, messages, tasks, relationships, and user-authored content.
- Files, recordings, audio, transcripts, summaries, and export artifacts.
- Data from optional connected systems, including OAuth identity, credentials, email, calendar, and Plaud data.
- AI data such as prompts, selected context, model output, tool calls, and technical usage data.
- Support messages, feedback, attachments, and technical request, device, error, and security data.
3. Purposes and legal bases
Ente processes data to provide and secure accounts; store, organize, search, relate, share, and export company knowledge; run requested integrations; transcribe and structure recordings; provide AI features and notifications; respond to requests; and administer B2B pilots and contracts.
Depending on the processing, the legal basis may be Article 6(1)(b) GDPR (contract or pre-contract steps), Article 6(1)(c) (legal obligation), Article 6(1)(f) (legitimate interests in secure operation and support), or—only for a voluntary and revocable choice—Article 6(1)(a) (consent). As processor, Ente acts on the customer's documented instructions; the customer is responsible for its legal basis and notices to employees, contacts, and meeting participants.
4. Infrastructure, authentication, and contact
Ente uses Convex for authentication, database and file storage, and server-side functions. The website and web application are delivered through Netlify. These services receive data such as IP address, request details, and device information. Messages to ente@agentmail.to are processed by AgentMail in the United States and remain in the mailbox until deleted.
Account, session, and authorization data are processed for sign-in. Credentials for optional integrations are stored only when a connection is enabled; the application code supports encrypted credential storage.
5. Optional integrations
Google Workspace, Microsoft/Outlook, user-selected IMAP/SMTP or CalDAV services, Plaud, LaMetric, browser push services, and import tools process data only when a user connects or invokes them. Scope, location, and other parties depend on the service selected. Disconnecting removes the connection credentials and, where implemented, local caches; information deliberately imported as Ente content may remain.
6. AI, recordings, and agents
Depending on the feature selected, Ente may send audio, transcripts, prompts, selected workspace context, and tool results to OpenAI, Anthropic, or models made available through Amazon Bedrock. These providers support transcription, structuring, search, summaries, and agent features. Output may be wrong and must be reviewed before use or disclosure.
Recordings may be captured by microphone, uploaded, or imported from Plaud. Users must provide any notices and obtain any permission or other legal basis required before recording. Mood, valence, and arousal analysis fields are disabled by default and are not offered in the B2B pilot without separate legal and technical approval.
7. Product analytics and browser storage
Ente uses PostHog for coarse product-usage analytics. The deployed application code permits only a product-surface event with an ephemeral identifier and excludes stable Ente account IDs, email address, name, full URL, and user-authored text. Necessary browser storage and session mechanisms are used for sign-in, security, and requested features.
8. Recipients and international transfers
Recipients may include authorized members of a customer workspace, providers on the subprocessor page, customer-connected systems, and legally authorized authorities or advisers. Several providers are established in or process data in the United States or other countries outside the EEA. Depending on the provider, transfers rely on adequacy decisions, Standard Contractual Clauses, or another lawful mechanism.
9. Retention and deletion
Data is generally kept while the account, customer workspace, requested feature, or a legal retention duty requires it. Some features use shorter cache periods; Gmail periods are set out in the Google section below. Shared customer content may remain under the business customer's control after one user leaves.
Self-service full-account deletion is not yet available. Access or deletion requests can be sent to ente@agentmail.to. Legal retention duties, third-party rights, and shared content controlled by a customer may limit what can be deleted.
10. Data-subject rights
Depending on the conditions, people may request access, correction, deletion, restriction, portability, objection, and withdrawal of consent, and may complain to a data protection authority. If Ente processes data for a business customer, a request will normally be referred to or handled on instructions from that customer.
11. Google Workspace data
Gmail and Google Calendar are optional integrations. Ente accesses Google data only after a user deliberately connects the relevant service and approves access at Google.
| Permission | Access and purpose |
|---|---|
gmail.modifyuserinfo.email | Lets Ente identify the connected email address and read and search Gmail messages, threads, headers, bodies, attachments, and labels. On an explicit user action, Ente can create and send drafts or messages and can archive, trash, restore, mark read or unread, star, and relabel messages. |
openid, email, profilecalendar.readonlycalendar.events | Lets Ente identify the connected Google account, list and search calendars and events, and—when selected by the user—create, update, or delete events. |
Storage and retention
- Gmail: Ente stores connection and synchronization data, message and thread metadata, and fetched message bodies in its Convex backend. Metadata is normally retained for a 90-day synchronization window; fetched bodies for 30 days; search results for 15 minutes. An attachment access token lasts two minutes. Attachment bytes are streamed from Gmail and are not stored as a separate Ente file.
- Google Calendar: Ente stores connection data and the selection and basic metadata of selected calendars while the connection remains active. Events are fetched from Google when needed and are not kept as a complete persistent calendar copy. Content a user deliberately imports into Ente may then become ordinary Ente content.
- OAuth credentials are stored by Ente so the requested connection can operate. The application code supports encrypted storage. A user can revoke Ente's access at any time in their Google Account.
Sharing, AI, and training
Ente shares Google data only as needed for a user-requested feature, contracted infrastructure, or a legal requirement. Gmail change notifications are delivered through Google Cloud Pub/Sub. If a user expressly asks an Ente AI agent to perform a Calendar action, the event details and tool results needed for that action may be sent to the configured AI service provider. Gmail content is not exposed as an AI-agent tool in the currently reviewed implementation.
Ente does not use Google user data to develop, improve, or train generalized or shared AI or machine-learning models.
Disconnecting, revocation, and deletion
Disconnecting Gmail deletes the relevant Ente connection credential and starts bounded cleanup of the local Gmail cache. Disconnecting Google Calendar deletes the connection and stored calendar selection. Because Gmail and Calendar can share one Google grant, disconnecting a single feature does not automatically revoke that grant at Google; revocation is available in Google Account permissions.
A user may request deletion of Google data associated with their account at ente@agentmail.to. Shared content may remain under the business customer's control. Self-service full-account deletion is not yet available.
Google API Limited Use
Ente's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google API Services User Data Policy.
12. Changes
Material changes will be published with a new revision date and, where required, communicated through an appropriate channel.