Fantail

Privacy Policy

Effective 6 August 2026

Fantail sits on top of the mailbox your business already uses. That means the most sensitive thing we hold is not your account — it is your customers’ mail, which you have entrusted to us on their behalf. This policy is written to be read, not to be waved at a regulator, and it says plainly what we take, what we never take, how it is protected, and how you get all of it back.

It covers, in particular, the data Fantail receives from Google APIs and Microsoft APIs when you connect a mailbox. That is set out in full in section 3, and the security controls behind it in section 7.

On this page
  1. Two kinds of information
  2. What we collect
  3. Connecting your mailbox: permissions, and what we do with the data
  4. Attachments
  5. How AI is used
  6. Who processes your data
  7. Security, and how it is verified
  8. How long we keep it
  9. Export, delete, disconnect
  10. Your rights
  11. Your customers, and you
  12. Information about children
  13. Analytics and the website
  14. Changes to this policy
  15. Contact

1Two kinds of information, and why the difference matters

Almost every privacy policy has one subject: you. Fantail’s has two, and keeping them apart is the honest way to write this.

Your business’s own information — your account, your team, your billing, the topics you have taught Fantail to answer. You are our customer, we decide what happens to this information, and under the Privacy Act 2020 we are the agency responsible for it.

Your customers’ information — the enquiries that arrive in the mailbox you connected, and the replies that go back out. This is not ours and it is not really yours to give away either. We hold it on your behalf and we act on your instructions. You remain the agency your customers deal with; we are the service you have chosen to use to answer them. If you disconnect the mailbox, our licence to touch any of it ends.

Everything below tells you which of the two it is talking about.

2What we collect

Your account and workspace

Your customers’ messages

One thing worth knowing about Watch mode

During the two-week watch, Fantail reads and drafts but sends nothing. The reading is real: the same mail is processed and the same records are built. Watch mode limits what leaves, not what is seen. If you would rather nothing at all were read yet, do not connect the mailbox yet.

Usage information

Server logs (IP address, browser, timestamps, pages and endpoints) kept for security and debugging, and product events — a draft was approved, a topic was promoted, an export was run. Product events record that something happened and never the content of a message, a draft or a customer’s enquiry. Message bodies, attachment contents and OAuth tokens are never written to logs.

3Connecting your mailbox: the exact permissions, and what we do with the data

Fantail is deliberately not a helpdesk you migrate to. It attaches to the mailbox you already run, which means how we connect is the whole security story. There are three ways in — two OAuth connections and, for mailboxes on your own domain, a password connection — and each is set out in full below. There is nothing else, and there is no hidden second request later.

Before the consent screen

Fantail shows you an in-product disclosure before the Google or Microsoft consent screen appears. It names each permission being requested, in plain language, alongside the specific Fantail feature that needs it, and it lets you stop there. Nothing is requested silently, and no permission is requested at a moment when you cannot see what it is for.

Google (Gmail and Google Workspace)

Scope requestedWhat it lets Fantail doWhy nothing narrower works
gmail.readonlyRead incoming mail in the connected mailbox.Classifying an enquiry and drafting an answer both need the body of the message. Metadata-only access (gmail.metadata) can see that mail arrived but not what it asked, which makes the product impossible rather than merely worse.
gmail.sendSend a reply as you — one you have approved in Fantail, or one sent by a topic you have explicitly moved to Auto.The reply has to leave under your own address or it is not your reply. Nothing narrower can send — and nothing broader is needed, because the draft and the review both live in Fantail: we do not request, and do not hold, the ability to create anything inside your mailbox.
What we deliberately do not request

We do not request gmail.compose, gmail.modify, gmail.settings.basic, gmail.settings.sharing, gmail.labels or full mail.google.com access. Fantail therefore cannot delete your mail, cannot move, archive or relabel it, cannot alter your filters, forwarding or signature, cannot reach any mailbox other than the one you connected — and cannot so much as place a draft inside it. Drafts live in Fantail until the moment you send; what arrives in your mailbox is only finished, approved mail. This is not a policy promise we could quietly change — Google has not granted us the ability in the first place. If we ever needed a broader permission, you would see a fresh consent screen and could decline it.

How Fantail accesses, uses, stores, shares and deletes Google user data

Accesses. Only the mailbox you connected, only through Google’s official APIs, and only using the two scopes above. Access begins when you complete the consent screen and ends the moment you disconnect in Fantail or revoke in your Google Account.

Uses. Google user data is used for exactly three things: recognising what an incoming enquiry is about; drafting a reply against the answers your own business has approved; and building the customer record and audit trail you see in the app. It is used to provide and improve those user-facing features and for nothing else.

Stores. Message content, drafts and the records derived from them are stored encrypted on New Zealand infrastructure, partitioned by business, under the retention rules in section 8. The OAuth access and refresh tokens Google issues are encrypted at rest with keys held in a managed key service, are never written to logs, error reports or analytics, and are never exposed to another business.

Shares. Google user data is shared only with the processors listed in section 6, each under contract, and only to the extent needed to deliver the feature you asked for. It is never sold, never shared for advertising, and never used to train, fine-tune or evaluate any generalised or shared machine-learning model.

Deletes. Disconnecting the mailbox destroys the stored tokens within 24 hours and stops all further access immediately. Deleting a ticket, a customer or the whole account removes the underlying message content on the timetable in section 9 — from live systems immediately and from encrypted backups within 30 days. You can do all of this yourself; see section 9 for the exact route.

Google API Services Limited Use disclosure

Fantail’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and without qualification: Google user data is used only to provide or improve user-facing features that are prominent in the Fantail interface; it is never sold, and never transferred to anyone except as needed to provide those features, for security purposes, or where the law compels it. It is never used for advertising, ad targeting, personalisation or market research. No human at Fantail reads your Google user data except where you have given explicit consent for a specific message (for example, you send us a thread to help debug a bad draft), where it is necessary for security purposes such as investigating abuse, where it is required to comply with applicable law, or where the data has been aggregated and de-identified.

Google user data is never used to train, fine-tune, evaluate or otherwise develop any generalised or shared machine-learning or artificial-intelligence model, and is never transferred to any model vendor for that purpose. The AI requests described in section 5 are inference-only calls under contracts that prohibit training on submitted data.

Microsoft 365 and Outlook

Where you connect a Microsoft mailbox we request Mail.Read, Mail.Send (for replies you approve, and for topics you have switched to Auto), and offline_access so the connection survives without asking you to sign in each day. We do not request Mail.ReadWrite — the same point as above: no ability to create or change anything inside your mailbox, drafts included. Everything stated about access, use, storage, sharing, deletion and token handling applies to Microsoft data in the same way. You can revoke from your Microsoft account at any time.

Where drafts live — and two different kinds of promise

Drafts exist only inside Fantail. You read them, edit them and approve them there, and your mailbox receives only the finished article. We think that is the right shape for a review step: a half-written AI draft sitting in your own Drafts folder would blur the one distinction that matters — which words you actually approved.

It is worth being precise about what kind of promise this is on each connection. On Gmail and Microsoft, it is a technical guarantee: we never requested the permission to create drafts, so the platform has not given us the ability — there is nothing for us to refrain from. On a password-connected mailbox (IMAP), it is a promise of behaviour: a password could write to your Drafts folder, and we choose not to, for the product reason above. The distinction is the same one running through this whole section — where a platform can hold the fence, we let it; where it cannot, you are trusting our code and our audit log, and we say so plainly.

Your own domain’s mailbox — connecting with a password (IMAP/SMTP)

Mailboxes on your own domain — the info@yourbusiness.co.nz that came with your website, hosted on cPanel, Plesk or your own server — connect with your email address and password. This section is deliberately blunter than the two above, because a password is a heavier thing to hold than an OAuth permission, and you should decide with that in front of you.

What we store. Your email address, your mail server names, and your mailbox password. The password is stored encrypted with keys held in a managed key service — but it must be encryption we can reverse, because Fantail has to present the real password to your mail server every time it checks for new mail or sends a reply. We will not tell you we cannot read it; that would not be true. What is true: it is never written to logs, error reports or analytics; no Fantail staff member has standing access to it; and any human access to the credential store is logged, named and reviewed.

What it can do, honestly compared. On the Google and Microsoft paths, the limits are enforced by the provider: we hold narrow permissions, and Fantail cannot delete your mail or change your settings because we were never granted the ability. A password has no such fence — it opens the whole mailbox. On this path, the limits on what Fantail does are enforced by our code, our audit log and this policy, rather than by your mail provider. That difference is exactly why, when you type your address, we check where your domain’s mail actually lives (its MX records) first — and if it turns out to be hosted on Google or Microsoft, we refuse the password route entirely and send you to the one-click connection instead. That refusal is enforced on our servers, not just in the signup screen.

What we do with it. Sign in to this one mailbox to read incoming mail, import up to the last 12 months of history so your customer records start full rather than empty (you can shorten this window during setup), send the replies you or your automation rules approve, and file a copy of each sent reply into your own Sent folder so your mailbox stays a complete record. Nothing else: no folder reorganising, no rule changes, no deleting — and no writing drafts into your mailbox, a line the note above is honest about being a choice rather than an inability on this path.

Revoking, instantly and without us. Change your mailbox password and Fantail’s access ends that moment — you do not need to contact us or even sign in to Fantail. Disconnecting inside Fantail (Settings → Mailbox) also destroys the stored credential within 24 hours.

If you would rather not hand over a password, the forwarding option remains: you set a forwarding rule in your own mailbox, Fantail never signs in and never holds a credential, and sees only mail received from that day forward.

Revoking

Disconnect the mailbox in Fantail at any time, and independently revoke our access from your Google Account permissions page or your Microsoft account — or, for a password-connected mailbox, simply change the password. Any of these stops all processing immediately and none requires you to contact us; see section 9 for what then happens to what we already hold.

This policy is published at a stable public address on a domain we own and have verified with Google (fantailhq.com and its subdomains), is linked from our homepage and from the consent screen, and is readable without signing in or creating an account.

4Attachments — the one thing we deliberately do not read

When a customer attaches an invoice, a medical note or an incident report, Fantail stores the file, scans it for malware and shows it to you. It does not open it, does not run OCR over it, and never places its contents into an AI request.

The reason is not caution for its own sake. If a model cannot see a file, it cannot summarise it — and a confident sentence like “regarding the $320 on your invoice” that was invented rather than read is exactly the failure that would cost you a customer. Making it structurally impossible is more reliable than instructing a model not to do it.

Consequently a message with a real attachment can never be answered automatically. It is capped at a draft for you to approve, and where the file looks serious — legal, insurance, an incident, a complaint — Fantail writes only a short acknowledgement and leaves the substance to you.

Attachments are stored in New Zealand, partitioned by business, reachable only through signed links that expire in fifteen minutes or less, and are deleted when the ticket is deleted. They are never forwarded to any third party — not to a model vendor, not to another of your own mailboxes, and never attached to an outgoing Fantail reply.

5How AI is used, and what it is never given

Answering one enquiry involves three separate AI requests: one that classifies the message, one that drafts the reply against your own approved answers, and a third, independent one that checks the draft before you ever see it — because a model marking its own homework is not a check.

What goes into those requests is the message text, the relevant entries from your own knowledge base, and enough thread history to make the reply make sense. What never goes in: attachment contents, your billing details, your OAuth tokens, and any other business’s data.

On training

Our model providers are contractually bound not to use data submitted through their business APIs to train their models, and we do not train models on your data either. Fantail learns your business by storing your approved answers as your knowledge base and retrieving them — not by adjusting model weights. That is why what Fantail knows about your business stays inside your business, and why deleting a knowledge entry actually removes it from future replies.

Automation is earned, never assumed. Every topic starts in Watch. It moves to drafting, and only after a long run of clean approvals can it answer on its own — and some topics, such as anything about money, refunds, legal matters or a child’s wellbeing, are barred from ever answering automatically no matter how well they perform.

6Who processes your data

We use a small number of service providers. Each is bound by contract to process data only on our instructions, to keep it confidential, and to secure it to a standard comparable with this policy. We do not sell personal information, and we do not share it for advertising.

ProviderWhat it doesWhat it can see
AnthropicThe models that classify, draft and check repliesMessage text, your knowledge-base entries, thread context. No attachment contents. No tokens. No training on any of it.
Cloud hosting and object storageRuns the application; stores the database and attachmentsAll stored data, encrypted at rest. Primary region is New Zealand.
Email deliverySends replies and notifications from your own domainThe content of outgoing mail and its recipients.
Payment processorTakes subscription paymentsYour billing contact and card details, which it holds — not us. It never sees message content.
Error and uptime monitoringTells us when something breaksTechnical diagnostics only. Message bodies, attachment contents, customer addresses and tokens are stripped before they reach it.

We will publish an updated list here before adding any provider that can see customer message content or Google user data.

We may also disclose information where the law requires it, to protect someone’s safety, or to establish or defend a legal claim. If a lawful request compels us to hand over your data, we will tell you unless we are legally prevented from doing so.

If Fantail is ever sold or merged, your data may transfer to the acquirer — bound by this policy, and with notice to you in advance so that you can export and leave first.

7Security, and how it is verified

Fantail is built and operated in New Zealand, and customer messages and attachments are stored on New Zealand infrastructure by default. Some processing — the AI requests in section 5, and email delivery — necessarily happens offshore. Where information leaves New Zealand we rely on information privacy principle 12 of the Privacy Act 2020: the recipient is contractually required to protect it to a standard comparable to the Act.

How the data is protected

Who can reach it

How the software is kept secure

When something goes wrong

We keep a written incident response plan covering detection, containment, assessment and notification, and we rehearse it rather than filing it. No system is perfect. If a breach occurs that is likely to cause you or your customers serious harm, we will notify you without undue delay and notify the Office of the Privacy Commissioner as the Privacy Act 2020 requires, and we will tell you what happened rather than what we wish had happened. Where a breach involves data received from Google or Microsoft APIs, we will also notify that provider as its terms require.

Reporting a vulnerability. If you believe you have found a security flaw in Fantail, email hello@fantailhq.com with “security” in the subject line. We will acknowledge within two working days. We will not pursue legal action over good-faith research that stays within your own workspace, does not access another business’s data, does not degrade the service, and gives us a reasonable chance to fix the issue before it is published.

8How long we keep it

WhatKept for
Customer messages, drafts and ticketsAs long as your account is open, or until you delete them. You can set a shorter retention window in your workspace settings, after which threads are removed automatically.
AttachmentsWith their ticket. Deleted when the ticket is.
OAuth tokens (Google, Microsoft)Only while the mailbox is connected. Destroyed within 24 hours of disconnection or revocation.
Mailbox credentials (IMAP/SMTP connections)Only while the mailbox is connected, encrypted in a managed key service. Destroyed within 24 hours of disconnection — and useless the moment you change your password.
Your knowledge base and settingsAs long as your account is open.
Approval historyAs long as the topic exists — it is the evidence behind that topic’s automation level.
Server and security logsUp to 12 months. They contain no message content.
Encrypted backupsRolling 30 days. Deleted data is gone from backups within that window.
Invoices and tax recordsSeven years, as New Zealand tax law requires. These survive account deletion; nothing else does.

9Export, delete, disconnect

Three separate things, and you can do each of them yourself without emailing anyone.

Export

From Settings → Data, export your whole workspace — tickets, messages, drafts, customer records, knowledge base — in a machine-readable format, with attachments included. It is your data and the export exists so that leaving is a decision rather than a hostage negotiation.

Disconnect the mailbox

From Settings → Mailbox. Stops all reading and drafting immediately, and destroys the stored OAuth tokens within 24 hours. Nothing further is collected. What has already been collected stays until you delete it, which is what most people want when they are simply pausing.

Delete

From Settings → Data, delete a single ticket, a single customer record, or the entire account. Deleting the account removes your workspace, its messages, drafts, customer records and attachments — including all data received from Google and Microsoft APIs — from live systems immediately and from encrypted backups within 30 days. What survives is listed in section 8: invoices we are required by law to retain.

If a customer of yours asks you to delete their information, you can remove that customer record and its threads directly — you do not need our permission or our help to answer your own customer.

If you would rather a person did it, or you can no longer sign in, email hello@fantailhq.com from the address on the account. We will verify the request, action it, and confirm in writing when it is done.

10Your rights

Under the Privacy Act 2020 you may ask for access to the personal information we hold about you and ask us to correct it if it is wrong. Most of it is visible in the app already, and the export in section 9 is the fastest route to all of it. For anything the app does not cover, email us; we will respond within 20 working days, as the Act requires.

If you are not satisfied with how we have handled your privacy, tell us first — we would rather fix it. You also have the right to complain to the Office of the Privacy Commissioner at privacy.org.nz, and you do not need our agreement to do so.

11Your customers, and what this policy asks of you

The people writing to your business are not our customers — they are yours, and their relationship is with you. Three consequences follow, and they are yours rather than ours.

First, you must be entitled to connect the mailbox you connect. It should be your business’s mailbox, and if it belongs to an employee you should have their knowledge and agreement. Fantail cannot verify this for you.

Second, your own privacy statement should tell your customers that you use a service to help answer their enquiries, and your Fantail replies should not pretend otherwise. Fantail can add a footer line disclosing that a reply was drafted with AI assistance; on the smaller plans that line is on by default and cannot be removed.

Third, the mail in the connected mailbox should be your business’s correspondence. If you connect a mailbox that also carries a person’s private mail, that mail will be read by the system too — and that is a choice you made, not one we can undo for you.

If one of your customers asks us directly about information we hold, we will point them to you, because you are the agency that holds it — unless the law tells us to do otherwise.

12Information about children

Fantail is a business tool. It is not directed at children, is not marketed to them, and no one under 18 may hold an account.

In some of the industries Fantail serves — early childhood education, schools, clinics — the enquiries a business receives will inevitably contain information about a child, because a parent wrote in about their child. Fantail holds that information on the business’s behalf under exactly the same rules as everything else in this policy, and it is never used to train a model. In addition, topics touching a child’s wellbeing can never be answered automatically, no matter how well a topic has performed — they are permanently capped at a draft a person must read. That limit is in the product, not in a setting.

13Analytics and the website

fantailhq.com uses a privacy-preserving analytics tool that counts page views and referrers without cookies, without cross-site tracking and without building a profile of you. We set cookies only where they are strictly necessary — keeping you signed in, and keeping the app secure. There are no advertising or third-party tracking cookies, which is also why you are not being asked to click through a consent banner.

Fantail forms embedded on your website collect only what the form asks for and send it straight to your workspace. They do not set tracking cookies on your visitors.

14Changes to this policy

Products change and this page will change with them. If a change is meaningful — a new provider that can see message content, a new permission or API scope, a new use of your data — we will tell you in the app and by email before it takes effect, not afterwards, and any new permission will be requested through a fresh consent screen you can decline. The current version always lives at this address, with its effective date at the top.

15Contact

Fantail is operated by 02M LIMITED (NZBN 9429053859921), Auckland, Aotearoa New Zealand. 02M LIMITED is the agency responsible for personal information under the Privacy Act 2020.

Privacy questions, access requests, deletion requests, security reports and complaints: hello@fantailhq.com