LemonbrandInbox audit

Data and privacy

This notice applies to the inbox audit you start or join here.

What the audit reads

The audit reads email metadata and selected message text within the agreed review period and exclusions. The audit does not send, edit or delete email. Attachments and message text in protected folders are excluded.

Email backups you upload

A backup archive can contain older email, attachments and other records that the audit itself excludes. Upload only the intended mailbox. Files are encrypted in our Canadian worker storage and made available to the audit team for manual scope and coverage review. Uploading a backup does not start AI processing or grant ongoing mailbox access; processing approval is a separate step.

Incomplete uploads are also retained in encrypted storage. An upload session expires after 24 hours, but expiry does not delete files already received. Contact us using the address below for deletion or help with an interrupted upload.

Processing and storage

The default audit route uses OpenAI. Company records and reports are stored in encrypted storage in Canada. Selected email text and any meeting transcripts you add are sent to the OpenAI API to prepare and check the report. This processing may take place outside Canada. Mailbox connections are managed through Pipedream.

A workspace operator can separately approve the GLM audit route for a specific mailbox scope and spending limit. Selected business email text is sent through OpenRouter to providers serving GLM 5.3 to prepare and check this audit. Processing may occur outside Canada. Every request requires no training and zero data retention. Sources and reports remain in encrypted Canadian storage. Local filters exclude detected protected content before model processing.

Clerk handles sign-in and account membership; Convex handles permissions and audit-status metadata. Canadian storage applies to captured email content, review records and reports, not these hosted services.

Pipedream manages mailbox connections and relays requested mail records. Business details and corrections you supply can also inform the analysis.

Who can see the records

Workspace administrators and people granted access to the review can see its records and findings, including cited email text. Connecting an inbox does not give the inbox owner access to the audit workspace.

Retention and access

Captured records, including provider responses, working records, evidence and reports remain in encrypted storage after the review. They are not automatically deleted when a report is delivered.

For retention or deletion requests, contact hello@lemonbrand.io. You can revoke mailbox access in your email provider’s account settings. Revoking access does not delete records already captured.