Privacy Policy
This policy explains what data Lagible collects, why we collect it, how long we keep it, who we share it with, and what rights you have over it. It is written to satisfy GDPR for EU and UK residents, CCPA and CPRA for California residents, and the substantive obligations of most other major privacy regimes.
Effective 2026-06-08. Last updated 2026-06-08. Questions: ayushopchauhan@gmail.com.
1. Who is responsible for your data
The data controller for personal data processed via Lagible is AOC, a sole proprietorship registered in Vadodara, Gujarat, India, operating the lagible.com service. For purposes of GDPR Article 4(7), AOC determines the purposes and means of the processing. For purposes of CCPA, AOC is the “business”.
Controller contact: ayushopchauhan@gmail.com. Postal contact provided on request to that address.
EU representative (placeholder, appointed under GDPR Article 27): to be named. UK representative (placeholder, appointed under UK GDPR Article 27): to be named. Until an EU and UK representative is formally appointed, EU and UK data subjects may exercise rights directly via the ayushopchauhan@gmail.com contact.
2. What data we collect
We collect only the data we need to deliver the service. The table below lists every category, what it contains, and where it comes from.
| Category | Contents | Source |
|---|---|---|
| Identity | Account email, hashed user ID | You at signup |
| Contact | Display name, profile picture URL (from Google), billing address | Google OAuth + billing form |
| Email metadata | Sender, recipients, subject, timestamps, labels, thread IDs | Gmail API on connected inboxes |
| Email content (sensitive) | Full message bodies of messages in your connected inboxes | Gmail API on connected inboxes |
| AI inference output | Thread summaries, Q&A answers, generated when you click | OpenAI, processing your thread on your click |
| Payment metadata | Card last-4, brand, billing country, plan, charge history | Razorpay (we do not see full card numbers) |
| Usage and technical | IP address, user agent, page loads, click events, error stack traces | Your browser making requests |
| Audit log | Auth events, billing events, settings changes, admin actions | Our application code |
3. Lawful basis for processing (GDPR Article 6)
| Processing activity | Lawful basis |
|---|---|
| Sync and display your Gmail messages in the Lagible UI | Contract (Article 6(1)(b)): necessary to perform the service you signed up for |
| AI summary and Q&A when you click | Consent (Article 6(1)(a)): you affirmatively click to trigger AI processing |
| Billing and subscription management | Contract (Article 6(1)(b)) and Legal obligation (Article 6(1)(c)) for tax records |
| Audit logging, fraud prevention, abuse detection | Legitimate interest (Article 6(1)(f)): security of the service and other users |
| Operational alerts to the founder via Telegram | Legitimate interest (Article 6(1)(f)): operational continuity. Alerts carry aggregate counts only, no PII. |
| Affiliate attribution cookie | Legitimate interest (Article 6(1)(f)) for first-party attribution. ePrivacy strictly necessary. |
Special categories (Article 9): your email content may incidentally contain special- category data (health, religion, political opinion) that you or your correspondents chose to put in email. We do not solicit or systematically process such data. Where it appears, processing happens under the same contract basis as all other email content, because the service cannot exclude bytes by topic.
4. How long we keep your data
The authoritative retention schedule is published on the Security page. The summary below mirrors it. If the two ever diverge, the Security page wins because that is where the retention controls live in code.
- Message metadata: life of account, purged within 24 hours of deletion.
- Full message bodies, default tier: last 90 days rolling.
- Full message bodies, Extended Mirror (Scale opt-in): 24 months rolling.
- AI summary and Q&A output: life of account or per-thread delete.
- OAuth refresh tokens: life of inbox connection, immediate crypto erase on disconnect.
- Audit logs: 24 months rolling.
- Billing records: 7 years (tax law minimum).
- Backups containing any of the above: 30 days rolling.
5. Subprocessors
Lagible discloses your personal data to the following subprocessors strictly to deliver the service. This list is the canonical mirror of the table on the Security page. We notify customers in writing 30 days before adding a subprocessor.
| Subprocessor | Purpose | Data category | Region |
|---|---|---|---|
| Supabase Inc. | Postgres database, auth, file storage | All categories | us-east-1 (AWS) |
| Vercel Inc. | App hosting, edge network, secret store | Request payloads, identity, encrypted tokens | Global edge, us-east-1 origin |
| OpenAI | AI summaries and Q&A on user click | Thread contents at click time only | United States |
| Razorpay Software Pvt Ltd | Subscription billing, card vault, webhook delivery | Billing identity, plan, payment metadata | India |
| Telegram FZ-LLC | Founder-facing operational alerts | Aggregate counts only, no PII | Global |
6. Your rights
Under GDPR and UK GDPR, you have the right to:
- Access: receive a copy of all personal data we hold about you. Response within 30 days of request.
- Rectification: correct any inaccurate personal data.
- Erasure (right to be forgotten): delete your account and all associated data within 24 hours of confirmed request. Backups cycle out within 30 days.
- Restriction of processing: pause our processing while a dispute or correction is resolved.
- Portability: receive your data in a structured, machine-readable JSON format.
- Objection: object to processing based on legitimate interest. We will stop unless we demonstrate compelling legitimate grounds.
- Withdraw consent: where processing is based on consent (AI summary, marketing email), withdraw it at any time without affecting prior lawful processing.
- Lodge a complaint with your local supervisory authority. We will not retaliate.
Under CCPA and CPRA (California residents), you additionally have the right to know what personal information we have collected about you, the right to delete it, the right to correct it, the right to limit use of sensitive personal information (your email contents qualify), and the right to opt out of sale or sharing. We do not sell or share your personal information as those terms are defined under CCPA.
To exercise any right, email ayushopchauhan@gmail.com with the right you want to exercise. We may verify your identity before responding. Response SLA: 30 days for GDPR, 45 days for CCPA, extendable by 30 days with notice for complex requests.
7. International transfers
Lagible is operated from India. Our application hosting and Postgres database run in the United States (us-east-1 on AWS, via Vercel and Supabase). OpenAI processes thread content in the United States. If you are located outside India or the United States, your personal data is transferred internationally to those regions.
For transfers out of the EEA, UK, and Switzerland, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914) as the transfer mechanism. We have completed transfer impact assessments for our US subprocessors and apply supplementary measures (encryption in transit and at rest, scope minimisation, vendor selection by privacy posture). The executed SCCs are available on request via ayushopchauhan@gmail.com.
9. Children
Lagible is a B2B tool not directed to children. We do not knowingly collect personal data from anyone under 16. For California residents, we do not knowingly collect from anyone under 13 (COPPA). If you believe a child has provided us with personal data, email ayushopchauhan@gmail.com and we will delete it promptly.
10. Security
The full security posture, including encryption, retention controls, incident response, audit log retention, and SOC 2 commitment, is published on the Security page. Highlights: OAuth refresh tokens encrypted with AES-256-GCM, master key held only in Vercel encrypted environment variables, Postgres Row Level Security on every query, TLS 1.2+ for all transport, 72-hour breach notification per GDPR Article 33, named contact at ayushopchauhan@gmail.com.
11. Changes to this policy
We may update this policy. Material changes (new processing purposes, new categories of personal data, new subprocessors, changes to retention) will be notified by email to your billing contact at least 30 days before they take effect. Non-material changes (clarifications, contact-detail updates) take effect immediately on posting here.
Version history is preserved in the public git repository for the marketing site. The current version is always the one rendered at this URL.
12. Contact
Privacy questions and rights requests: ayushopchauhan@gmail.com
Confirmed security issues: ayushopchauhan@gmail.com
Legal and Terms questions: ayushopchauhan@gmail.com
Postal address: provided on request to ayushopchauhan@gmail.com.
Related documents
- Security: scope justification, encryption posture, retention schedule, CASA verification status, SOC 2 commitment.
- Terms of Service: acceptable use, billing, governing law, dispute resolution.
- Data Processing Addendum: Article 28 processor obligations, audit rights, breach notification timeline.