Privacy Policy

Privacy Policy

This policy explains what data Lagible collects, why we collect it, how long we keep it, who we share it with, and what rights you have over it. It is written to satisfy GDPR for EU and UK residents, CCPA and CPRA for California residents, and the substantive obligations of most other major privacy regimes.

Effective 2026-06-08. Last updated 2026-06-08. Questions: ayushopchauhan@gmail.com.

1. Who is responsible for your data

The data controller for personal data processed via Lagible is AOC, a sole proprietorship registered in Vadodara, Gujarat, India, operating the lagible.com service. For purposes of GDPR Article 4(7), AOC determines the purposes and means of the processing. For purposes of CCPA, AOC is the “business”.

Controller contact: ayushopchauhan@gmail.com. Postal contact provided on request to that address.

EU representative (placeholder, appointed under GDPR Article 27): to be named. UK representative (placeholder, appointed under UK GDPR Article 27): to be named. Until an EU and UK representative is formally appointed, EU and UK data subjects may exercise rights directly via the ayushopchauhan@gmail.com contact.

2. What data we collect

We collect only the data we need to deliver the service. The table below lists every category, what it contains, and where it comes from.

CategoryContentsSource
IdentityAccount email, hashed user IDYou at signup
ContactDisplay name, profile picture URL (from Google), billing addressGoogle OAuth + billing form
Email metadataSender, recipients, subject, timestamps, labels, thread IDsGmail API on connected inboxes
Email content (sensitive)Full message bodies of messages in your connected inboxesGmail API on connected inboxes
AI inference outputThread summaries, Q&A answers, generated when you clickOpenAI, processing your thread on your click
Payment metadataCard last-4, brand, billing country, plan, charge historyRazorpay (we do not see full card numbers)
Usage and technicalIP address, user agent, page loads, click events, error stack tracesYour browser making requests
Audit logAuth events, billing events, settings changes, admin actionsOur application code

3. Lawful basis for processing (GDPR Article 6)

Processing activityLawful basis
Sync and display your Gmail messages in the Lagible UIContract (Article 6(1)(b)): necessary to perform the service you signed up for
AI summary and Q&A when you clickConsent (Article 6(1)(a)): you affirmatively click to trigger AI processing
Billing and subscription managementContract (Article 6(1)(b)) and Legal obligation (Article 6(1)(c)) for tax records
Audit logging, fraud prevention, abuse detectionLegitimate interest (Article 6(1)(f)): security of the service and other users
Operational alerts to the founder via TelegramLegitimate interest (Article 6(1)(f)): operational continuity. Alerts carry aggregate counts only, no PII.
Affiliate attribution cookieLegitimate interest (Article 6(1)(f)) for first-party attribution. ePrivacy strictly necessary.

Special categories (Article 9): your email content may incidentally contain special- category data (health, religion, political opinion) that you or your correspondents chose to put in email. We do not solicit or systematically process such data. Where it appears, processing happens under the same contract basis as all other email content, because the service cannot exclude bytes by topic.

4. How long we keep your data

The authoritative retention schedule is published on the Security page. The summary below mirrors it. If the two ever diverge, the Security page wins because that is where the retention controls live in code.

  • Message metadata: life of account, purged within 24 hours of deletion.
  • Full message bodies, default tier: last 90 days rolling.
  • Full message bodies, Extended Mirror (Scale opt-in): 24 months rolling.
  • AI summary and Q&A output: life of account or per-thread delete.
  • OAuth refresh tokens: life of inbox connection, immediate crypto erase on disconnect.
  • Audit logs: 24 months rolling.
  • Billing records: 7 years (tax law minimum).
  • Backups containing any of the above: 30 days rolling.

5. Subprocessors

Lagible discloses your personal data to the following subprocessors strictly to deliver the service. This list is the canonical mirror of the table on the Security page. We notify customers in writing 30 days before adding a subprocessor.

SubprocessorPurposeData categoryRegion
Supabase Inc.Postgres database, auth, file storageAll categoriesus-east-1 (AWS)
Vercel Inc.App hosting, edge network, secret storeRequest payloads, identity, encrypted tokensGlobal edge, us-east-1 origin
OpenAIAI summaries and Q&A on user clickThread contents at click time onlyUnited States
Razorpay Software Pvt LtdSubscription billing, card vault, webhook deliveryBilling identity, plan, payment metadataIndia
Telegram FZ-LLCFounder-facing operational alertsAggregate counts only, no PIIGlobal

6. Your rights

Under GDPR and UK GDPR, you have the right to:

  • Access: receive a copy of all personal data we hold about you. Response within 30 days of request.
  • Rectification: correct any inaccurate personal data.
  • Erasure (right to be forgotten): delete your account and all associated data within 24 hours of confirmed request. Backups cycle out within 30 days.
  • Restriction of processing: pause our processing while a dispute or correction is resolved.
  • Portability: receive your data in a structured, machine-readable JSON format.
  • Objection: object to processing based on legitimate interest. We will stop unless we demonstrate compelling legitimate grounds.
  • Withdraw consent: where processing is based on consent (AI summary, marketing email), withdraw it at any time without affecting prior lawful processing.
  • Lodge a complaint with your local supervisory authority. We will not retaliate.

Under CCPA and CPRA (California residents), you additionally have the right to know what personal information we have collected about you, the right to delete it, the right to correct it, the right to limit use of sensitive personal information (your email contents qualify), and the right to opt out of sale or sharing. We do not sell or share your personal information as those terms are defined under CCPA.

To exercise any right, email ayushopchauhan@gmail.com with the right you want to exercise. We may verify your identity before responding. Response SLA: 30 days for GDPR, 45 days for CCPA, extendable by 30 days with notice for complex requests.

7. International transfers

Lagible is operated from India. Our application hosting and Postgres database run in the United States (us-east-1 on AWS, via Vercel and Supabase). OpenAI processes thread content in the United States. If you are located outside India or the United States, your personal data is transferred internationally to those regions.

For transfers out of the EEA, UK, and Switzerland, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914) as the transfer mechanism. We have completed transfer impact assessments for our US subprocessors and apply supplementary measures (encryption in transit and at rest, scope minimisation, vendor selection by privacy posture). The executed SCCs are available on request via ayushopchauhan@gmail.com.

8. Cookies and similar technologies

Lagible uses a minimal cookie set, all classified as strictly necessary under ePrivacy:

  • sb-access-token, sb-refresh-token: Supabase authentication, session.
  • inboxchat_ref: 60-day affiliate attribution cookie, set only when a referral link is followed.

We do not use analytics cookies, advertising cookies, cross-site tracking, fingerprinting, or third-party trackers. We do not use Google Analytics, Meta Pixel, or any third-party advertising network on lagible.com.

9. Children

Lagible is a B2B tool not directed to children. We do not knowingly collect personal data from anyone under 16. For California residents, we do not knowingly collect from anyone under 13 (COPPA). If you believe a child has provided us with personal data, email ayushopchauhan@gmail.com and we will delete it promptly.

10. Security

The full security posture, including encryption, retention controls, incident response, audit log retention, and SOC 2 commitment, is published on the Security page. Highlights: OAuth refresh tokens encrypted with AES-256-GCM, master key held only in Vercel encrypted environment variables, Postgres Row Level Security on every query, TLS 1.2+ for all transport, 72-hour breach notification per GDPR Article 33, named contact at ayushopchauhan@gmail.com.

11. Changes to this policy

We may update this policy. Material changes (new processing purposes, new categories of personal data, new subprocessors, changes to retention) will be notified by email to your billing contact at least 30 days before they take effect. Non-material changes (clarifications, contact-detail updates) take effect immediately on posting here.

Version history is preserved in the public git repository for the marketing site. The current version is always the one rendered at this URL.

12. Contact

Privacy questions and rights requests: ayushopchauhan@gmail.com
Confirmed security issues: ayushopchauhan@gmail.com
Legal and Terms questions: ayushopchauhan@gmail.com

Postal address: provided on request to ayushopchauhan@gmail.com.

Related documents

  • Security: scope justification, encryption posture, retention schedule, CASA verification status, SOC 2 commitment.
  • Terms of Service: acceptable use, billing, governing law, dispute resolution.
  • Data Processing Addendum: Article 28 processor obligations, audit rights, breach notification timeline.