Privacy policy
Version 2026-09-28
This policy explains what 9512624 Canada Ltd., operating as Lemonbrand ("Lemonbrand", "we", "us"), does with personal information, and in particular with the email data people connect from Google Workspace and Microsoft 365. It covers the website lemonbrand.io and the Inbox Agent service at audit.lemonbrand.io (the "Service").
We are a small Canadian company in Ottawa, Ontario. If anything here is unclear, write to privacy@lemonbrand.io and a person will answer.
1. What the Service does
Organizations use the Service to understand how work moves through their email. A business (usually through a consulting firm we work with, called a "partner") connects its staff mailboxes with read-only access. Our software reads each message, classifies it, and builds views of the work: per person, per team and for the whole organization, updated as new mail arrives. It also produces a list of repetitive tasks that could be automated.
The Service never sends, edits, moves or deletes email, and never creates mail rules.
2. Who is responsible for what
- When an organization connects its mailboxes, that organization decides which mailboxes are connected and why. It is responsible for that information under privacy law. We process it on its behalf, as a service provider, under a written data processing agreement. Where a partner provides the Service to the organization, we act as the partner's subprocessor.
- For our own accounts and website, we are responsible for the information we collect (for example your sign-in details or a message you send us).
If you are an employee whose mailbox was connected by your employer, your employer is your first point of contact. You can still write to us and we will help, or pass your request to your employer where the law requires that.
3. What we collect
Account information. Name, work email address, organization and role, for people who sign in to the Service.
Mailbox data from Google and Microsoft. When a person or an administrator connects a mailbox, we request only these permissions:
| Provider | Permissions | Why |
|---|---|---|
| Google (Gmail API) | gmail.readonly, plus openid, email, profile | Read messages and their metadata; identify the connected account |
| Microsoft (Microsoft Graph) | Mail.Read, User.Read, plus offline_access, openid, profile, email | Read messages and their metadata; identify the connected account; keep reading as new mail arrives |
From a connected mailbox we read, within the period and folders the organization has agreed to: sender, recipients, subject, dates, folder or label, and message body. We do not download or analyze attachments (their file names can appear in message data). Folders the organization excludes, and spam and trash, are not analyzed.
Information you give us. Business details, corrections to our findings, meeting transcripts an organization chooses to add, and messages you send us.
Website information. Standard server logs (IP address, browser, pages requested) kept for security. We do not use advertising or cross-site tracking cookies on lemonbrand.io or audit.lemonbrand.io.
4. How we use Google and Microsoft data
We use mailbox data only to provide the Service to the organization that connected it:
- to classify and analyze messages and show the organization its views, reports and automation list;
- to keep those views current as new mail arrives;
- to keep the Service secure, prevent abuse and fix faults;
- to comply with the law.
We do not use mailbox data, or anything derived from it, for any other purpose. In particular we never:
- use it for advertising, including retargeting, personalized or interest-based ads;
- sell it, rent it, or give it to data brokers or information resellers;
- use it to determine creditworthiness or for lending;
- use it to build a profile of a person for anyone other than the organization that connected the mailbox;
- combine one organization's data with another's, or use one organization's data to serve another.
Google API Services User Data Policy. Lemonbrand's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
These commitments apply to the raw data we receive and to everything we derive from it, including summaries, classifications, counts, and aggregated or anonymized data.
5. Artificial intelligence
Messages are read by AI models so that every message can be classified. These models run on Amazon Bedrock in Lemonbrand's own Amazon Web Services account and act only on our instructions.
- We do not use Google Workspace API data, or Microsoft 365 data, to develop, improve or train generalized or non-personalized AI or machine learning models.
- We go further: we do not use mailbox data to train or fine-tune any model at all, ours or a vendor's. The one exception is search indexes built for a single organization, used only for that organization and deleted with its data.
- On Amazon Bedrock, prompts and answers are not stored by the model service, are not used to train models, and are not shared with the companies that make the models.
6. When people read your data
By default, no person at Lemonbrand reads the content of connected mail. Software produces the findings.
A person at Lemonbrand reads specific messages or excerpts only when:
- the organization has given explicit, affirmative agreement for a named purpose (for example, checking a finding before a report is delivered), recorded in the Service before any reading starts; or
- it is necessary for security purposes, such as investigating abuse or a vulnerability; or
- it is required to comply with applicable law; or
- the data has been aggregated and anonymized and is used only for our internal operations (for example, counting how many messages the system processed).
Inside the organization, people it authorizes in the Service see findings as counts and categories. They see quoted excerpts of a person's messages only if that person agreed, on a separate checkbox that is off by default, and only while that agreement stands: the person can withdraw it from their own view at any time. Findings on sensitive topics (health, legal, personal, human resources) are shown as counts, never quoted.
7. Who we share data with
We share mailbox data only with the service providers we use to run the Service (our "subprocessors"), each under a written contract that limits use to providing the Service, requires security, and requires deletion. For Google user data, that is Amazon Web Services (hosting, storage and the Bedrock models) and no one else. The current list, with what each receives and where, is at lemonbrand.io/subprocessors. We give organizations notice before adding a subprocessor that handles mailbox data.
We may also disclose information:
- to the organization that connected the mailbox, and people it authorizes, under section 6;
- when the law requires it (we disclose only what is required and tell the organization first where the law allows);
- to protect the security of the Service or its users;
- as part of a merger, acquisition or sale of assets, with notice to affected organizations and under the same commitments as this policy.
8. Where data is stored and how it is protected
Mailbox data and everything derived from it is stored in Canada, in Amazon Web Services' Canada (Central) region (ca-central-1), in infrastructure only Lemonbrand controls. AI processing runs on Amazon Bedrock in the same AWS account, through a Canadian inference profile that keeps requests in AWS's Canadian regions.
Our protections include:
- encryption in transit (TLS) and at rest (AES-256, with keys held in AWS Key Management Service), plus a second layer of encryption for each stored message;
- access tokens for Google and Microsoft stored encrypted and never shown to people;
- separate storage for each organization;
- multi-factor authentication and least-privilege access for our staff and systems;
- logging of administrative access, and regular security testing.
No method of storage or transmission is perfectly secure. If a security incident affects your data, we will notify the organization responsible for it, and the authorities and providers the law and our agreements require.
9. How long we keep data
| Data | Kept until |
|---|---|
| Google and Microsoft access tokens | The mailbox is disconnected, the grant is revoked, or the organization leaves the Service; then deleted |
| Message content (bodies, subjects) | 30 days after it is processed, unless the organization's agreement sets a shorter period |
| Derived records (classifications, counts, findings, reports) | While the organization uses the Service, then deleted within 30 days of it leaving |
| Backups | Expire within 30 days of the source data being deleted |
| Account information | While the account is active, then up to 12 months for records we must keep |
10. Your choices and how to delete your data
Stop access and delete. The person who connected a Gmail account can disconnect it from their own view in the Service. Disconnecting revokes our access at Google, stops reading and deletes that mailbox's data. Step by step: how to disconnect and delete your data.
You can also stop access from your provider at any time:
- Google: go to myaccount.google.com/permissions, select the app, and choose remove access. A Google Workspace administrator can also remove the app for the whole organization in the Admin console (Security, then API controls).
- Microsoft: go to myapps.microsoft.com, open the app, and choose to remove it. A Microsoft 365 administrator can remove it for the whole organization in the Microsoft Entra admin center (Enterprise applications).
Removing access at the provider stops all new reading at the next sync. It does not by itself delete what was already collected: disconnect in the Service, or write to privacy@lemonbrand.io from the connected address. We confirm deletion in writing within 7 days of a verified request. Backups expire within 30 days after that.
Your rights. Depending on where you live, you may have the right to access the personal information we hold about you, correct it, have it deleted, withdraw consent, receive it in a portable format, and complain to a regulator. In Canada, that is the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information (cai.gouv.qc.ca). In the European Union or United Kingdom, it is your local data protection authority. We answer requests within 30 days. If the request concerns data an organization connected, we may pass it to that organization, which decides how to respond, unless the law requires us to answer directly.
11. Children
The Service is for businesses. It is not directed to children and we do not knowingly collect information from anyone under 16.
12. Changes to this policy
We will post any change here with a new version date, and tell organizations using the Service by email before a material change takes effect.
13. Contact and person responsible
The person responsible for the protection of personal information at Lemonbrand is Simon Bergeron, Managing Partner and Privacy Officer, 9512624 Canada Ltd. (Lemonbrand), Ottawa, Ontario, Canada, privacy@lemonbrand.io.