The honest version, badges and all
Is AI Email Safe?
Letting software read your inbox is a real trust decision, and it deserves a real answer. Here is where your data goes, what protects it, what the law asks of you — and what we do not claim.
The Honest Answer: It Depends on Three Things
“Is AI email safe?” is the right question, and it has a real answer rather than a reassuring one.
Letting an AI handle your inbox means the contents of that inbox — client details, commercial terms, sometimes health or financial information — pass through the system that reads and drafts. That is not a reason to avoid it; it is a reason to ask exactly the questions you would ask before handing those emails to any third party. Whether it is safe comes down to three things: where your data goes, who can reach it, and whether a human stays in control of what gets sent.
On the first, our answer is Australian data centres — processing and storage onshore, so the correspondence does not leave the country to be read. On the second, encryption in transit and at rest, access controls, and an audit trail of what the system did. On the third, a human-in-the-loop model where the AI drafts and a person approves, so nothing goes out in your name unless you decided it should.
We will also tell you what we are not. We are a small independent Australian business, and we do not hold SOC 2 or ISO 27001 certification. If your procurement demands a certified provider, choose one — we would rather say so here than after you sign. What we offer instead is genuine transparency: we put the architecture and the data handling in writing, and we answer the awkward questions directly, including the one most vendors dodge.
What Actually Protects Your Email
The controls that matter, stated as what they are rather than dressed up as more than they are.
Australian Data Residency
Processing and storage in Australian data centres. Your inbox is not shipped offshore to be read, which keeps you on the right side of the questions a client or auditor will ask.
- Processing and storage onshore, in Australia
- No offshore round-trip to read your email
- Documented in writing for sign-off
- Matters most for regulated and confidential work
Encryption In Transit & At Rest
Email is encrypted while it moves and while it is stored, so intercepted or accessed data is unreadable without the keys. Standard practice, done properly.
- Encrypted connections for data in transit
- Encryption at rest for stored data
- Secure OAuth — we never see your password
- Keys managed, not left lying in config
Human-in-the-Loop by Default
The AI drafts; a person approves. Nothing sends in your name unless you configured that category to auto-send. This is the control that makes AI email safe to trust.
- Draft-first mode with one-click approval
- Auto-send only where you deliberately enable it
- Recommended default for sensitive correspondence
- You stay accountable for what leaves the building
Your Data Trains Nothing Else
Your email serves your assistant and no one else. It is not pooled with other customers or used to train models for other businesses. Your correspondence stays yours.
- Not used to train models for other customers
- Not pooled with other businesses’ data
- Used only to run your inbox
- A question worth asking every vendor
Access Controls & Audit Trail
Access to your data is controlled and logged. You can see what the system did — what it read, categorised, drafted and sent — rather than trusting a black box.
- Role-based access to your data
- Audit trail of processing and sends
- Visibility into what the AI did and when
- Supports your own compliance record-keeping
Privacy Act 1988 Alignment
Built around the Australian Privacy Act 1988 and the Australian Privacy Principles — including the offshore-disclosure obligation under APP 8 that a lot of AI email marketing quietly skips.
- Handling aligned to the APPs
- APP 8 offshore-disclosure position stated in writing
- Retention configured to your obligations
- General information, not legal advice
What We Do Not Claim
A security page is more trustworthy for what it refuses to overstate. So here is the honest ledger.
What we do provide
- Processing and storage in Australian data centres
- Encryption in transit and at rest
- Human-in-the-loop approval before sending
- Access controls and an audit trail
- Handling aligned to the Privacy Act 1988 and APPs
- The data architecture, documented in writing
What we do not claim
- We do not hold SOC 2 certification
- We do not hold ISO 27001 certification
- We are not IRAP-assessed
- We do not process data classified PROTECTED or above
- We do not promise a specific uptime SLA figure here
- We will point you elsewhere if your rules require the above
If your procurement hard-requires a certification we do not hold, choose a provider who has it — we would rather tell you that in the first conversation than win work we should not. Where those certifications are not mandated, the controls above are what genuinely protect your email, and we will show you exactly how they work.
Three Questions to Ask Any AI Email Vendor
Use these on us, and on everyone else you shortlist. A straight answer is itself a signal.
Where does my email actually go?
Ask whether processing and storage are onshore, and specifically whether your email is disclosed to an overseas model provider. Under APP 8 that is your accountability. If the answer is vague or the offshore step is glossed over, treat that as the answer.
What certifications do you hold — really?
Ask directly, and watch for badges implied rather than held. A vendor willing to say plainly what it does not hold is usually more trustworthy than one displaying logos it cannot substantiate. Ours: Australian data residency and documented handling, not SOC 2 or ISO 27001.
Can it send without a human, and is my data training your models?
Confirm you control what auto-sends, and confirm your correspondence is not used to train models for other customers. The safe default is human-in-the-loop and no cross-customer training — anything looser should be a deliberate, informed choice, not a surprise in the terms.
Read Further
How AI Inbox Triage Works
The mechanism behind the reading and sorting — and how triage stays a sorting tool, never a deciding one.
Learn moreAI Email for Healthcare
The industry where the data question is sharpest — how patient email is handled under the Privacy Act with health information in play.
Learn moreOur Privacy Policy
The formal detail on how we collect, use, store and protect your information — the document behind the plain-English answers here.
Read the policyFrequently Asked Questions
The data, privacy and security questions businesses ask before letting an AI touch the inbox.
In Australian data centres. Both the processing — the reading, categorising and drafting the AI does — and the storage of what it needs to keep occur onshore, not in the United States or elsewhere. This matters because letting an AI handle your inbox means the contents of that inbox pass through whatever model does the work, and where that model sits is a real privacy question, not a technicality. Under the Australian Privacy Act 1988 and the Australian Privacy Principles, your business remains accountable for personal information in your email regardless of who processes it, so we keep the processing where you can answer for it. We will document the specifics in writing during the free consultation for anyone who needs to sign it off.
No, and we are going to say that plainly rather than let a security page imply otherwise. Yes AI is a small independent Australian business and we do not currently hold SOC 2 or ISO 27001 certification. Plenty of vendors display those badges, and if your procurement process hard-requires a certified provider then you should choose one — we would rather tell you that now than have you discover the gap after signing. What we do provide are the controls those frameworks exist to assure: processing and storage in Australian data centres, encryption in transit and at rest, access controls and audit trails, a human-in-the-loop approval model, and a written account of exactly how your data is handled. We compete on being genuinely transparent about the architecture, not on a logo we have not earned.
Your email is used to serve you — to triage your inbox, learn your writing voice, and draft your replies — and it is not pooled with other customers’ data or used to train models that serve other businesses. Your correspondence is yours. This is a question worth asking every AI vendor directly, because the answer varies enormously and some consumer-grade tools reserve broad rights to use your content, so read the terms rather than assume. Ours is straightforward: your data trains nothing beyond your own assistant’s understanding of how you work, and it is not a training corpus for anyone else.
It is one of the most real and least-discussed issues in AI email, so here is the plain version. Many AI email tools route your messages through large overseas model providers, typically in the United States. Under Australian Privacy Principle 8, disclosing personal information to an overseas recipient is a disclosure you are accountable for, with obligations attached — it is not merely a hosting choice, and for regulated industries or government-adjacent work it can be a genuine compliance problem or a contract breach. The uncomfortable truth is that a lot of "AI email" marketing quietly skips over this. Our position is to process onshore and to put our offshore-disclosure stance in writing, so you are not taking a reassuring sentence on trust. This is general information about how the obligation typically applies, not legal advice — take the specifics to whoever owns privacy in your business.
Only if you explicitly configure it to, and even then only for the categories you choose. The default posture is human-in-the-loop: the AI drafts, a person approves, and only then does the message send. For sensitive, regulated or high-stakes correspondence we recommend keeping it that way — draft-first mode with one-click approval means nothing goes out in your name until you have decided it should. Some businesses do choose to auto-send certain low-risk, high-volume categories once they trust the drafts, and that is your call to make deliberately, category by category, rather than a default we impose. You are always accountable for what leaves your business, so the system is built to keep you in control of it.
Your data is handled according to the retention terms you set, and on cancellation it is deleted rather than retained indefinitely — you are not signing up to have your correspondence sit on someone’s servers forever. During onboarding we configure retention to suit your industry’s obligations, which for some regulated sectors means keeping records for a defined period and for others means minimising what is kept at all. If you leave, the offboarding covers deletion and, where relevant, export. As with the rest of this page, we will put the specifics in writing rather than ask you to trust a summary, and this is general information rather than legal advice about your particular retention obligations.
Ask the Awkward Questions. We Will Answer Them.
Bring your privacy and security requirements to the free consultation and you will get the architecture in writing — including a straight answer on whether we fit your obligations, or whether you need a certified provider instead.
Prefer to talk it through first? Call (03) 9999 7402 or send us a message.