Privacy policy

Version 2026-09-28

This policy explains what 9512624 Canada Ltd., operating as Lemonbrand ("Lemonbrand", "we", "us"), does with personal information, and in particular with the email data people connect from Google Workspace and Microsoft 365. It covers the website lemonbrand.io and the Inbox Agent service at audit.lemonbrand.io (the "Service").

We are a small Canadian company in Ottawa, Ontario. If anything here is unclear, write to privacy@lemonbrand.io and a person will answer.

1. What the Service does

Organizations use the Service to understand how work moves through their email. A business (usually through a consulting firm we work with, called a "partner") connects its staff mailboxes with read-only access. Our software reads each message, classifies it, and builds views of the work: per person, per team and for the whole organization, updated as new mail arrives. It also produces a list of repetitive tasks that could be automated.

The Service never sends, edits, moves or deletes email, and never creates mail rules.

2. Who is responsible for what

If you are an employee whose mailbox was connected by your employer, your employer is your first point of contact. You can still write to us and we will help, or pass your request to your employer where the law requires that.

3. What we collect

Account information. Name, work email address, organization and role, for people who sign in to the Service.

Mailbox data from Google and Microsoft. When a person or an administrator connects a mailbox, we request only these permissions:

ProviderPermissionsWhy
Google (Gmail API)gmail.readonly, plus openid, email, profileRead messages and their metadata; identify the connected account
Microsoft (Microsoft Graph)Mail.Read, User.Read, plus offline_access, openid, profile, emailRead messages and their metadata; identify the connected account; keep reading as new mail arrives

From a connected mailbox we read, within the period and folders the organization has agreed to: sender, recipients, subject, dates, folder or label, and message body. We do not download or analyze attachments (their file names can appear in message data). Folders the organization excludes, and spam and trash, are not analyzed.

Information you give us. Business details, corrections to our findings, meeting transcripts an organization chooses to add, and messages you send us.

Website information. Standard server logs (IP address, browser, pages requested) kept for security. We do not use advertising or cross-site tracking cookies on lemonbrand.io or audit.lemonbrand.io.

4. How we use Google and Microsoft data

We use mailbox data only to provide the Service to the organization that connected it:

We do not use mailbox data, or anything derived from it, for any other purpose. In particular we never:

Google API Services User Data Policy. Lemonbrand's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

These commitments apply to the raw data we receive and to everything we derive from it, including summaries, classifications, counts, and aggregated or anonymized data.

5. Artificial intelligence

Messages are read by AI models so that every message can be classified. These models run on Amazon Bedrock in Lemonbrand's own Amazon Web Services account and act only on our instructions.

6. When people read your data

By default, no person at Lemonbrand reads the content of connected mail. Software produces the findings.

A person at Lemonbrand reads specific messages or excerpts only when:

  1. the organization has given explicit, affirmative agreement for a named purpose (for example, checking a finding before a report is delivered), recorded in the Service before any reading starts; or
  2. it is necessary for security purposes, such as investigating abuse or a vulnerability; or
  3. it is required to comply with applicable law; or
  4. the data has been aggregated and anonymized and is used only for our internal operations (for example, counting how many messages the system processed).

Inside the organization, people it authorizes in the Service see findings as counts and categories. They see quoted excerpts of a person's messages only if that person agreed, on a separate checkbox that is off by default, and only while that agreement stands: the person can withdraw it from their own view at any time. Findings on sensitive topics (health, legal, personal, human resources) are shown as counts, never quoted.

7. Who we share data with

We share mailbox data only with the service providers we use to run the Service (our "subprocessors"), each under a written contract that limits use to providing the Service, requires security, and requires deletion. For Google user data, that is Amazon Web Services (hosting, storage and the Bedrock models) and no one else. The current list, with what each receives and where, is at lemonbrand.io/subprocessors. We give organizations notice before adding a subprocessor that handles mailbox data.

We may also disclose information:

8. Where data is stored and how it is protected

Mailbox data and everything derived from it is stored in Canada, in Amazon Web Services' Canada (Central) region (ca-central-1), in infrastructure only Lemonbrand controls. AI processing runs on Amazon Bedrock in the same AWS account, through a Canadian inference profile that keeps requests in AWS's Canadian regions.

Our protections include:

No method of storage or transmission is perfectly secure. If a security incident affects your data, we will notify the organization responsible for it, and the authorities and providers the law and our agreements require.

9. How long we keep data

DataKept until
Google and Microsoft access tokensThe mailbox is disconnected, the grant is revoked, or the organization leaves the Service; then deleted
Message content (bodies, subjects)30 days after it is processed, unless the organization's agreement sets a shorter period
Derived records (classifications, counts, findings, reports)While the organization uses the Service, then deleted within 30 days of it leaving
BackupsExpire within 30 days of the source data being deleted
Account informationWhile the account is active, then up to 12 months for records we must keep

10. Your choices and how to delete your data

Stop access and delete. The person who connected a Gmail account can disconnect it from their own view in the Service. Disconnecting revokes our access at Google, stops reading and deletes that mailbox's data. Step by step: how to disconnect and delete your data.

You can also stop access from your provider at any time:

Removing access at the provider stops all new reading at the next sync. It does not by itself delete what was already collected: disconnect in the Service, or write to privacy@lemonbrand.io from the connected address. We confirm deletion in writing within 7 days of a verified request. Backups expire within 30 days after that.

Your rights. Depending on where you live, you may have the right to access the personal information we hold about you, correct it, have it deleted, withdraw consent, receive it in a portable format, and complain to a regulator. In Canada, that is the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information (cai.gouv.qc.ca). In the European Union or United Kingdom, it is your local data protection authority. We answer requests within 30 days. If the request concerns data an organization connected, we may pass it to that organization, which decides how to respond, unless the law requires us to answer directly.

11. Children

The Service is for businesses. It is not directed to children and we do not knowingly collect information from anyone under 16.

12. Changes to this policy

We will post any change here with a new version date, and tell organizations using the Service by email before a material change takes effect.

13. Contact and person responsible

The person responsible for the protection of personal information at Lemonbrand is Simon Bergeron, Managing Partner and Privacy Officer, 9512624 Canada Ltd. (Lemonbrand), Ottawa, Ontario, Canada, privacy@lemonbrand.io.