Privacy Policy
Effective 6 August 2026
Fantail sits on top of the mailbox your business already uses. That means the most sensitive thing we hold is not your account — it is your customers’ mail, which you have entrusted to us on their behalf. This policy is written to be read, not to be waved at a regulator, and it says plainly what we take, what we never take, how it is protected, and how you get all of it back.
It covers, in particular, the data Fantail receives from Google APIs and Microsoft APIs when you connect a mailbox. That is set out in full in section 3, and the security controls behind it in section 7.
- Two kinds of information
- What we collect
- Connecting your mailbox: permissions, and what we do with the data
- Attachments
- How AI is used
- Who processes your data
- Security, and how it is verified
- How long we keep it
- Export, delete, disconnect
- Your rights
- Your customers, and you
- Information about children
- Analytics and the website
- Changes to this policy
- Contact
1Two kinds of information, and why the difference matters
Almost every privacy policy has one subject: you. Fantail’s has two, and keeping them apart is the honest way to write this.
Your business’s own information — your account, your team, your billing, the topics you have taught Fantail to answer. You are our customer, we decide what happens to this information, and under the Privacy Act 2020 we are the agency responsible for it.
Your customers’ information — the enquiries that arrive in the mailbox you connected, and the replies that go back out. This is not ours and it is not really yours to give away either. We hold it on your behalf and we act on your instructions. You remain the agency your customers deal with; we are the service you have chosen to use to answer them. If you disconnect the mailbox, our licence to touch any of it ends.
Everything below tells you which of the two it is talking about.
2What we collect
Your account and workspace
- Your work email address, name and the business name you sign up with; a password hash, or an identifier from the sign-in provider you chose.
- The teammates you invite, their email addresses and the role you give them.
- Your workspace settings: the industry you picked at signup, your business hours, your booking link and availability sentence, your signature and reply tone, and which topics you have moved to Watch, Suggest or Auto.
- Billing information — plan, invoices, GST details. Card numbers never reach Fantail. They are entered directly with our payment processor, which returns us a token and the last four digits.
Your customers’ messages
- The content of enquiries that reach the connected mailbox or a Fantail form on your website: sender address and name, subject, message body, headers needed for threading, timestamps, and any attachments (see section 4). On a password-connected mailbox this includes the imported history described in section 3 — up to the last 12 months, and only with your say-so at setup.
- The drafts Fantail writes, the edits you make to them, and whether you approved, rewrote or discarded each one. This record is what earns a topic its way up the trust ladder, so it is central to the product rather than incidental to it.
- The customer record Fantail assembles from those threads — contact details, past enquiries, what was quoted or promised — so that the next reply knows what the last one said.
During the two-week watch, Fantail reads and drafts but sends nothing. The reading is real: the same mail is processed and the same records are built. Watch mode limits what leaves, not what is seen. If you would rather nothing at all were read yet, do not connect the mailbox yet.
Usage information
Server logs (IP address, browser, timestamps, pages and endpoints) kept for security and debugging, and product events — a draft was approved, a topic was promoted, an export was run. Product events record that something happened and never the content of a message, a draft or a customer’s enquiry. Message bodies, attachment contents and OAuth tokens are never written to logs.
3Connecting your mailbox: the exact permissions, and what we do with the data
Fantail is deliberately not a helpdesk you migrate to. It attaches to the mailbox you already run, which means how we connect is the whole security story. There are three ways in — two OAuth connections and, for mailboxes on your own domain, a password connection — and each is set out in full below. There is nothing else, and there is no hidden second request later.
Before the consent screen
Fantail shows you an in-product disclosure before the Google or Microsoft consent screen appears. It names each permission being requested, in plain language, alongside the specific Fantail feature that needs it, and it lets you stop there. Nothing is requested silently, and no permission is requested at a moment when you cannot see what it is for.
Google (Gmail and Google Workspace)
| Scope requested | What it lets Fantail do | Why nothing narrower works |
|---|---|---|
gmail.readonly | Read incoming mail in the connected mailbox. | Classifying an enquiry and drafting an answer both need the body of the message. Metadata-only access (gmail.metadata) can see that mail arrived but not what it asked, which makes the product impossible rather than merely worse. |
gmail.send | Send a reply as you — one you have approved in Fantail, or one sent by a topic you have explicitly moved to Auto. | The reply has to leave under your own address or it is not your reply. Nothing narrower can send — and nothing broader is needed, because the draft and the review both live in Fantail: we do not request, and do not hold, the ability to create anything inside your mailbox. |
We do not request gmail.compose, gmail.modify, gmail.settings.basic, gmail.settings.sharing, gmail.labels or full mail.google.com access. Fantail therefore cannot delete your mail, cannot move, archive or relabel it, cannot alter your filters, forwarding or signature, cannot reach any mailbox other than the one you connected — and cannot so much as place a draft inside it. Drafts live in Fantail until the moment you send; what arrives in your mailbox is only finished, approved mail. This is not a policy promise we could quietly change — Google has not granted us the ability in the first place. If we ever needed a broader permission, you would see a fresh consent screen and could decline it.
How Fantail accesses, uses, stores, shares and deletes Google user data
Accesses. Only the mailbox you connected, only through Google’s official APIs, and only using the two scopes above. Access begins when you complete the consent screen and ends the moment you disconnect in Fantail or revoke in your Google Account.
Uses. Google user data is used for exactly three things: recognising what an incoming enquiry is about; drafting a reply against the answers your own business has approved; and building the customer record and audit trail you see in the app. It is used to provide and improve those user-facing features and for nothing else.
Stores. Message content, drafts and the records derived from them are stored encrypted on New Zealand infrastructure, partitioned by business, under the retention rules in section 8. The OAuth access and refresh tokens Google issues are encrypted at rest with keys held in a managed key service, are never written to logs, error reports or analytics, and are never exposed to another business.
Shares. Google user data is shared only with the processors listed in section 6, each under contract, and only to the extent needed to deliver the feature you asked for. It is never sold, never shared for advertising, and never used to train, fine-tune or evaluate any generalised or shared machine-learning model.
Deletes. Disconnecting the mailbox destroys the stored tokens within 24 hours and stops all further access immediately. Deleting a ticket, a customer or the whole account removes the underlying message content on the timetable in section 9 — from live systems immediately and from encrypted backups within 30 days. You can do all of this yourself; see section 9 for the exact route.
Google API Services Limited Use disclosure
Fantail’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and without qualification: Google user data is used only to provide or improve user-facing features that are prominent in the Fantail interface; it is never sold, and never transferred to anyone except as needed to provide those features, for security purposes, or where the law compels it. It is never used for advertising, ad targeting, personalisation or market research. No human at Fantail reads your Google user data except where you have given explicit consent for a specific message (for example, you send us a thread to help debug a bad draft), where it is necessary for security purposes such as investigating abuse, where it is required to comply with applicable law, or where the data has been aggregated and de-identified.
Google user data is never used to train, fine-tune, evaluate or otherwise develop any generalised or shared machine-learning or artificial-intelligence model, and is never transferred to any model vendor for that purpose. The AI requests described in section 5 are inference-only calls under contracts that prohibit training on submitted data.
Microsoft 365 and Outlook
Where you connect a Microsoft mailbox we request Mail.Read, Mail.Send (for replies you approve, and for topics you have switched to Auto), and offline_access so the connection survives without asking you to sign in each day. We do not request Mail.ReadWrite — the same point as above: no ability to create or change anything inside your mailbox, drafts included. Everything stated about access, use, storage, sharing, deletion and token handling applies to Microsoft data in the same way. You can revoke from your Microsoft account at any time.
Where drafts live — and two different kinds of promise
Drafts exist only inside Fantail. You read them, edit them and approve them there, and your mailbox receives only the finished article. We think that is the right shape for a review step: a half-written AI draft sitting in your own Drafts folder would blur the one distinction that matters — which words you actually approved.
It is worth being precise about what kind of promise this is on each connection. On Gmail and Microsoft, it is a technical guarantee: we never requested the permission to create drafts, so the platform has not given us the ability — there is nothing for us to refrain from. On a password-connected mailbox (IMAP), it is a promise of behaviour: a password could write to your Drafts folder, and we choose not to, for the product reason above. The distinction is the same one running through this whole section — where a platform can hold the fence, we let it; where it cannot, you are trusting our code and our audit log, and we say so plainly.
Your own domain’s mailbox — connecting with a password (IMAP/SMTP)
Mailboxes on your own domain — the info@yourbusiness.co.nz that came with your website, hosted on cPanel, Plesk or your own server — connect with your email address and password. This section is deliberately blunter than the two above, because a password is a heavier thing to hold than an OAuth permission, and you should decide with that in front of you.
What we store. Your email address, your mail server names, and your mailbox password. The password is stored encrypted with keys held in a managed key service — but it must be encryption we can reverse, because Fantail has to present the real password to your mail server every time it checks for new mail or sends a reply. We will not tell you we cannot read it; that would not be true. What is true: it is never written to logs, error reports or analytics; no Fantail staff member has standing access to it; and any human access to the credential store is logged, named and reviewed.
What it can do, honestly compared. On the Google and Microsoft paths, the limits are enforced by the provider: we hold narrow permissions, and Fantail cannot delete your mail or change your settings because we were never granted the ability. A password has no such fence — it opens the whole mailbox. On this path, the limits on what Fantail does are enforced by our code, our audit log and this policy, rather than by your mail provider. That difference is exactly why, when you type your address, we check where your domain’s mail actually lives (its MX records) first — and if it turns out to be hosted on Google or Microsoft, we refuse the password route entirely and send you to the one-click connection instead. That refusal is enforced on our servers, not just in the signup screen.
What we do with it. Sign in to this one mailbox to read incoming mail, import up to the last 12 months of history so your customer records start full rather than empty (you can shorten this window during setup), send the replies you or your automation rules approve, and file a copy of each sent reply into your own Sent folder so your mailbox stays a complete record. Nothing else: no folder reorganising, no rule changes, no deleting — and no writing drafts into your mailbox, a line the note above is honest about being a choice rather than an inability on this path.
Revoking, instantly and without us. Change your mailbox password and Fantail’s access ends that moment — you do not need to contact us or even sign in to Fantail. Disconnecting inside Fantail (Settings → Mailbox) also destroys the stored credential within 24 hours.
If you would rather not hand over a password, the forwarding option remains: you set a forwarding rule in your own mailbox, Fantail never signs in and never holds a credential, and sees only mail received from that day forward.
Revoking
Disconnect the mailbox in Fantail at any time, and independently revoke our access from your Google Account permissions page or your Microsoft account — or, for a password-connected mailbox, simply change the password. Any of these stops all processing immediately and none requires you to contact us; see section 9 for what then happens to what we already hold.
This policy is published at a stable public address on a domain we own and have verified with Google (fantailhq.com and its subdomains), is linked from our homepage and from the consent screen, and is readable without signing in or creating an account.
4Attachments — the one thing we deliberately do not read
When a customer attaches an invoice, a medical note or an incident report, Fantail stores the file, scans it for malware and shows it to you. It does not open it, does not run OCR over it, and never places its contents into an AI request.
The reason is not caution for its own sake. If a model cannot see a file, it cannot summarise it — and a confident sentence like “regarding the $320 on your invoice” that was invented rather than read is exactly the failure that would cost you a customer. Making it structurally impossible is more reliable than instructing a model not to do it.
Consequently a message with a real attachment can never be answered automatically. It is capped at a draft for you to approve, and where the file looks serious — legal, insurance, an incident, a complaint — Fantail writes only a short acknowledgement and leaves the substance to you.
Attachments are stored in New Zealand, partitioned by business, reachable only through signed links that expire in fifteen minutes or less, and are deleted when the ticket is deleted. They are never forwarded to any third party — not to a model vendor, not to another of your own mailboxes, and never attached to an outgoing Fantail reply.
5How AI is used, and what it is never given
Answering one enquiry involves three separate AI requests: one that classifies the message, one that drafts the reply against your own approved answers, and a third, independent one that checks the draft before you ever see it — because a model marking its own homework is not a check.
What goes into those requests is the message text, the relevant entries from your own knowledge base, and enough thread history to make the reply make sense. What never goes in: attachment contents, your billing details, your OAuth tokens, and any other business’s data.
Our model providers are contractually bound not to use data submitted through their business APIs to train their models, and we do not train models on your data either. Fantail learns your business by storing your approved answers as your knowledge base and retrieving them — not by adjusting model weights. That is why what Fantail knows about your business stays inside your business, and why deleting a knowledge entry actually removes it from future replies.
Automation is earned, never assumed. Every topic starts in Watch. It moves to drafting, and only after a long run of clean approvals can it answer on its own — and some topics, such as anything about money, refunds, legal matters or a child’s wellbeing, are barred from ever answering automatically no matter how well they perform.
6Who processes your data
We use a small number of service providers. Each is bound by contract to process data only on our instructions, to keep it confidential, and to secure it to a standard comparable with this policy. We do not sell personal information, and we do not share it for advertising.
| Provider | What it does | What it can see |
|---|---|---|
| Anthropic | The models that classify, draft and check replies | Message text, your knowledge-base entries, thread context. No attachment contents. No tokens. No training on any of it. |
| Cloud hosting and object storage | Runs the application; stores the database and attachments | All stored data, encrypted at rest. Primary region is New Zealand. |
| Email delivery | Sends replies and notifications from your own domain | The content of outgoing mail and its recipients. |
| Payment processor | Takes subscription payments | Your billing contact and card details, which it holds — not us. It never sees message content. |
| Error and uptime monitoring | Tells us when something breaks | Technical diagnostics only. Message bodies, attachment contents, customer addresses and tokens are stripped before they reach it. |
We will publish an updated list here before adding any provider that can see customer message content or Google user data.
We may also disclose information where the law requires it, to protect someone’s safety, or to establish or defend a legal claim. If a lawful request compels us to hand over your data, we will tell you unless we are legally prevented from doing so.
If Fantail is ever sold or merged, your data may transfer to the acquirer — bound by this policy, and with notice to you in advance so that you can export and leave first.
7Security, and how it is verified
Fantail is built and operated in New Zealand, and customer messages and attachments are stored on New Zealand infrastructure by default. Some processing — the AI requests in section 5, and email delivery — necessarily happens offshore. Where information leaves New Zealand we rely on information privacy principle 12 of the Privacy Act 2020: the recipient is contractually required to protect it to a standard comparable to the Act.
How the data is protected
- Encrypted in transit with TLS 1.2 or better, and encrypted at rest.
- Separation between businesses is enforced at the database query layer, not in application code. This is a deliberate architectural choice: a bug in a screen cannot leak another business’s mail, because the query could not have returned it.
- OAuth tokens, API keys and other secrets are held in a managed key service, never in source control, and never written to logs, analytics or error reports.
- Attachment links are signed and short-lived; a link cannot be reused across businesses or after it expires.
- Inbound files are scanned for malware and quarantined on failure.
- Backups are encrypted, and restores are tested rather than assumed.
Who can reach it
- Access inside Fantail is role-based and granted to the smallest number of people who need it.
- Multi-factor authentication is mandatory on every Fantail staff account and on all administrative access to production systems.
- There is no standing access to customer message content. Access for a specific support or security purpose is time-limited, recorded, and reviewed.
- Production customer data is never copied into development or test environments.
- Staff access is removed on the day someone leaves.
How the software is kept secure
- Changes are peer-reviewed before release, and automated static and dependency scanning runs on every build.
- Dependencies are patched on a defined timetable, with critical vulnerabilities prioritised over feature work.
- The application is scanned for common web vulnerabilities, and findings are tracked to closure.
- Fantail’s access to Google user data is subject to an annual independent security assessment under Google’s Cloud Application Security Assessment (CASA) framework, at Tier 2, which validates the application against the OWASP Application Security Verification Standard. The assessment is repeated every year for as long as we hold restricted-scope access, and Google may withdraw that access if we do not pass it.
When something goes wrong
We keep a written incident response plan covering detection, containment, assessment and notification, and we rehearse it rather than filing it. No system is perfect. If a breach occurs that is likely to cause you or your customers serious harm, we will notify you without undue delay and notify the Office of the Privacy Commissioner as the Privacy Act 2020 requires, and we will tell you what happened rather than what we wish had happened. Where a breach involves data received from Google or Microsoft APIs, we will also notify that provider as its terms require.
Reporting a vulnerability. If you believe you have found a security flaw in Fantail, email hello@fantailhq.com with “security” in the subject line. We will acknowledge within two working days. We will not pursue legal action over good-faith research that stays within your own workspace, does not access another business’s data, does not degrade the service, and gives us a reasonable chance to fix the issue before it is published.
8How long we keep it
| What | Kept for |
|---|---|
| Customer messages, drafts and tickets | As long as your account is open, or until you delete them. You can set a shorter retention window in your workspace settings, after which threads are removed automatically. |
| Attachments | With their ticket. Deleted when the ticket is. |
| OAuth tokens (Google, Microsoft) | Only while the mailbox is connected. Destroyed within 24 hours of disconnection or revocation. |
| Mailbox credentials (IMAP/SMTP connections) | Only while the mailbox is connected, encrypted in a managed key service. Destroyed within 24 hours of disconnection — and useless the moment you change your password. |
| Your knowledge base and settings | As long as your account is open. |
| Approval history | As long as the topic exists — it is the evidence behind that topic’s automation level. |
| Server and security logs | Up to 12 months. They contain no message content. |
| Encrypted backups | Rolling 30 days. Deleted data is gone from backups within that window. |
| Invoices and tax records | Seven years, as New Zealand tax law requires. These survive account deletion; nothing else does. |
9Export, delete, disconnect
Three separate things, and you can do each of them yourself without emailing anyone.
Export
From Settings → Data, export your whole workspace — tickets, messages, drafts, customer records, knowledge base — in a machine-readable format, with attachments included. It is your data and the export exists so that leaving is a decision rather than a hostage negotiation.
Disconnect the mailbox
From Settings → Mailbox. Stops all reading and drafting immediately, and destroys the stored OAuth tokens within 24 hours. Nothing further is collected. What has already been collected stays until you delete it, which is what most people want when they are simply pausing.
Delete
From Settings → Data, delete a single ticket, a single customer record, or the entire account. Deleting the account removes your workspace, its messages, drafts, customer records and attachments — including all data received from Google and Microsoft APIs — from live systems immediately and from encrypted backups within 30 days. What survives is listed in section 8: invoices we are required by law to retain.
If a customer of yours asks you to delete their information, you can remove that customer record and its threads directly — you do not need our permission or our help to answer your own customer.
If you would rather a person did it, or you can no longer sign in, email hello@fantailhq.com from the address on the account. We will verify the request, action it, and confirm in writing when it is done.
10Your rights
Under the Privacy Act 2020 you may ask for access to the personal information we hold about you and ask us to correct it if it is wrong. Most of it is visible in the app already, and the export in section 9 is the fastest route to all of it. For anything the app does not cover, email us; we will respond within 20 working days, as the Act requires.
If you are not satisfied with how we have handled your privacy, tell us first — we would rather fix it. You also have the right to complain to the Office of the Privacy Commissioner at privacy.org.nz, and you do not need our agreement to do so.
11Your customers, and what this policy asks of you
The people writing to your business are not our customers — they are yours, and their relationship is with you. Three consequences follow, and they are yours rather than ours.
First, you must be entitled to connect the mailbox you connect. It should be your business’s mailbox, and if it belongs to an employee you should have their knowledge and agreement. Fantail cannot verify this for you.
Second, your own privacy statement should tell your customers that you use a service to help answer their enquiries, and your Fantail replies should not pretend otherwise. Fantail can add a footer line disclosing that a reply was drafted with AI assistance; on the smaller plans that line is on by default and cannot be removed.
Third, the mail in the connected mailbox should be your business’s correspondence. If you connect a mailbox that also carries a person’s private mail, that mail will be read by the system too — and that is a choice you made, not one we can undo for you.
If one of your customers asks us directly about information we hold, we will point them to you, because you are the agency that holds it — unless the law tells us to do otherwise.
12Information about children
Fantail is a business tool. It is not directed at children, is not marketed to them, and no one under 18 may hold an account.
In some of the industries Fantail serves — early childhood education, schools, clinics — the enquiries a business receives will inevitably contain information about a child, because a parent wrote in about their child. Fantail holds that information on the business’s behalf under exactly the same rules as everything else in this policy, and it is never used to train a model. In addition, topics touching a child’s wellbeing can never be answered automatically, no matter how well a topic has performed — they are permanently capped at a draft a person must read. That limit is in the product, not in a setting.
13Analytics and the website
fantailhq.com uses a privacy-preserving analytics tool that counts page views and referrers without cookies, without cross-site tracking and without building a profile of you. We set cookies only where they are strictly necessary — keeping you signed in, and keeping the app secure. There are no advertising or third-party tracking cookies, which is also why you are not being asked to click through a consent banner.
Fantail forms embedded on your website collect only what the form asks for and send it straight to your workspace. They do not set tracking cookies on your visitors.
14Changes to this policy
Products change and this page will change with them. If a change is meaningful — a new provider that can see message content, a new permission or API scope, a new use of your data — we will tell you in the app and by email before it takes effect, not afterwards, and any new permission will be requested through a fresh consent screen you can decline. The current version always lives at this address, with its effective date at the top.
15Contact
Fantail is operated by 02M LIMITED (NZBN 9429053859921), Auckland, Aotearoa New Zealand. 02M LIMITED is the agency responsible for personal information under the Privacy Act 2020.
Privacy questions, access requests, deletion requests, security reports and complaints: hello@fantailhq.com