Privacy questions to ask before turning on AI in email
Privacy questions to ask any vendor before AI reads your team's email: model training, sub-processors, retention, location, admin controls and deletion.

On this page(12 sections)
- Is our email used to train AI models?
- Which third parties process our email?
- How long are prompts and outputs kept?
- Where is the processing done?
- Can admins turn AI features off?
- What can the AI actually do with our mail?
- Is there an audit log?
- Who at the vendor can see our email?
- What happens to our data if we leave?
- Can we connect AI assistants like Claude or ChatGPT, and how is that controlled?
- A one-page vendor checklist
- Key takeaways
Your inbox holds contracts, customer complaints, invoices, password resets and the occasional message you'd rather nobody else read. Turning on an AI feature means some of that text gets processed by a model, possibly one run by a company you've never heard of.
That's not a reason to avoid AI in email. It's a reason to ask good questions first. This FAQ covers the questions worth asking any vendor, what a reassuring answer looks like, and what should make you pause. It's practical guidance, not legal advice; if you have specific regulatory obligations, involve whoever handles compliance for you.
Is our email used to train AI models?
Why it matters: If your messages are used to train a model, fragments of their content could, in principle, influence outputs for other customers. Even when the risk is small, many organizations simply don't want their correspondence used that way.
A good answer: A clear, written statement that customer email content is not used to train models, either the vendor's own or a third party's. Check whether this applies by default or only if you opt out.
Pause if: The answer is vague ("we may use data to improve our services"), or the no-training promise only covers some features.
Which third parties process our email?
Why it matters: Many AI features call models hosted by another company. Your email text travels to that company's servers for processing. You should know who they are.
A good answer: A published list of sub-processors, including the AI model provider, with what each does. Ideally, a commitment that those providers also don't train on your data and don't retain it longer than needed.
Pause if: The vendor won't name its model provider, or the sub-processor list is missing or outdated.
How long are prompts and outputs kept?
Why it matters: When the AI summarizes a thread or drafts a reply, the vendor (and its model provider) may log the input and output. Those logs are copies of your email content living somewhere new.
A good answer: A specific retention period for AI inputs and outputs, ideally short, plus whether logs are used for debugging and who can see them.
Pause if: There's no stated retention period, or logs are kept indefinitely "for quality purposes."
Where is the processing done?
Why it matters: Some organizations have requirements about which countries their data can be processed in. Even without formal requirements, you may have customers who ask.
A good answer: A clear statement of the regions where email is stored and where AI processing happens. These can differ: mail might be stored in one region and sent to a model elsewhere.
Pause if: Storage location is documented but AI processing location isn't.
Can admins turn AI features off?
Why it matters: Not every mailbox should be processed by AI. Legal, HR or finance mailboxes might need to be excluded, and some team members may need to opt out.
A good answer: Admin controls at the workspace level, and ideally per mailbox or per feature. Turning it off should take effect immediately.
Pause if: AI is always on, or can only be disabled by contacting support.
What can the AI actually do with our mail?
Why it matters: Privacy isn't only about who reads the data; it's also about what the system can do. A feature that can only read and summarize is a very different risk from one that can send, forward or delete.
A good answer: A clear list of capabilities. Look for whether AI can send email on its own, forward messages, or take actions without a human approving them. Tools that keep a human click before anything is sent limit the damage from both errors and manipulation.
Pause if: The AI can send or forward autonomously and there's no way to restrict that.
Is there an audit log?
Why it matters: If something goes wrong, you'll want to know what the AI accessed and did, and when. Logs also help you check that admin controls work as described.
A good answer: A log of AI actions (which feature ran, on which thread, when, for which user) that admins can review. It doesn't need to store email content to be useful.
Pause if: There's no record of AI activity at all.
Who at the vendor can see our email?
Why it matters: AI aside, support staff and engineers at the vendor may have some level of access to customer data.
A good answer: Access limited to specific roles, granted only for support cases with your permission, and logged.
Pause if: Broad internal access without logging or customer consent.
What happens to our data if we leave?
Why it matters: You should be able to get your mail out and have it deleted, including any AI-derived data such as summaries or classifications.
A good answer: An export option, a deletion process with a stated timeline, and confirmation that AI logs and derived data are included.
Pause if: Deletion covers mailboxes but not AI logs, or there's no timeline.
Can we connect AI assistants like Claude or ChatGPT, and how is that controlled?
Why it matters: Increasingly, email platforms let external AI assistants connect to your mailbox. That's another party with access.
A good answer: Connections use a standard authorization flow where each user approves access explicitly, the permissions are described in plain words, admins can disable the capability workspace-wide, and connections can be revoked at any time.
Pause if: Connections use shared passwords or long-lived keys that can't be revoked individually.
A one-page vendor checklist
Copy this into your evaluation notes:
| Question | Answer | OK? |
|---|---|---|
| No training on our email content (in writing) | ||
| Sub-processors named, including AI provider | ||
| Retention period for AI inputs and outputs | ||
| Storage and processing regions | ||
| Admin can disable AI, per workspace and per mailbox | ||
| AI cannot send or forward without a human | ||
| Audit log of AI actions | ||
| Vendor staff access limited and logged | ||
| Export and deletion, including AI data | ||
| External assistant connections revocable |
Ask for answers in writing, and link to the vendor's documentation where possible. Marketing pages change; documented policies and contracts are what count.
Key takeaways
- Ask whether email is used for training, and get the answer in writing.
- Know which third parties process your mail and how long AI inputs are kept.
- Check where processing happens, not just where mail is stored.
- Look for admin controls, an audit log, and limits on what the AI can do.
- Make sure deletion covers AI-derived data, and that assistant connections can be revoked.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


