Skip to content
ClafkTrust Center

Privacy & Data

What happens to a message

Clafk processes customer data on the customer's instructions. This page follows an inbound message through the service and sets out what is handled and what is kept.

Data lifecycle

How a message moves through Clafk
  1. Step 1

    Mailbox provider

    Gmail or Microsoft 365, under an authorisation the user granted.

    • Message
    • Thread context
  2. Step 2

    Clafk processing

    Server-side systems classify the message and prepare what is needed.

    • Automated
    • Server-side
  3. Step 3

    AI processing where required

    Only the information needed for the operation is sent.

    • Limited data
  4. Step 4

    Product data retained where necessary

    What remains so the product works across sessions.

    • Metadata
    • Excerpts
    • Drafts

Generated drafts are saved to the connected mailbox as ordinary drafts and stay under the customer’s control. Clafk does not send a reply without an action by an authorised user.

What Clafk accesses

Access is limited to the mailbox the user authorised, and to what classification and drafting require.

  • The subject and body of incoming messages, and earlier messages in the same thread for context.
  • Sender and recipient addresses.
  • Labels, categories, and folders, so Clafk’s categorisation can be applied.
  • The account profile needed to identify which mailbox is connected.

What Clafk stores

Clafk may retain the following, to keep the product working across sessions.

  • Sender and message metadata needed to operate the service.
  • Limited message previews or excerpts required for product functionality.
  • Classification and workflow state.
  • Generated drafts, prepared for the customer to review.
  • Account and service usage metadata.

No searchable mailbox archive

Clafk stores what it needs to keep working. It does not build a searchable archive of the mailbox for browsing.

What is transient

Message content is processed for as long as classification and drafting require, and is not kept beyond that.

  • Complete inbound email bodies are not permanently stored.
  • Message content processed to produce a classification or a draft is used for that operation, not retained as a copy.

What Clafk does not retain or send onward

These boundaries explain what Clafk does not keep permanently or pass to certain providers.

  • Attachments are not retrieved, processed, transmitted, or stored.
  • Complete inbound email bodies are not permanently stored.
  • Complete inbound email bodies are not sent to AI providers.
  • Mailbox passwords are not received or stored, because access is granted through OAuth.
  • Diagnostic logging is designed to exclude email content.

Clafk also does not send email on a user’s behalf and does not delete customer email on the user’s behalf. See decision safety in the documentation.

Clafk does not ask customers to provide special categories of personal data as part of normal product setup. Customers decide what is in their own mailboxes.

Optional features

Two features process additional data, and only when the customer enables them.

Writing style profiles

When enabled, Clafk may retain a limited writing-style profile derived from selected sent messages so drafts can better match the user’s usual tone. Complete sent messages are not kept as part of it.

Knowledge base

Customer-uploaded knowledge base content is stored and used to retrieve relevant information during drafting. The customer decides what is uploaded.

Retention and deletion

Data is retained for as long as it is needed to provide the service.

  • Deleting an account deletes the associated records through Clafk’s deletion process and those of its infrastructure providers.
  • Disconnecting a mailbox removes that mailbox’s authorisation data.
  • Backups held by infrastructure providers follow those providers’ retention arrangements.
  • Clafk is established in Finland. Where data is transferred outside the European Economic Area, it is done on the basis of a recognised transfer mechanism such as Standard Contractual Clauses or an adequacy decision.

Last updated 3 August 2026. Legal and privacy information is governed by the Clafk Data Processing Agreement, Privacy Policy and Terms.