FairleadBack to sign in

Privacy Policy

Last updated: 19 September 2026

This policy explains what Fairlead does with your information, and in particular what it does with the email, calendar and spreadsheet data you choose to connect. We have tried to write it in plain English rather than legal boilerplate.

Who we are

Fairlead provides a business assistant that helps small businesses manage day-to-day administration. In this policy, “Fairlead”, “we” and “us” mean Fairlead; “you” means the business, and the people at that business, using the service. We are the data controller for the information described below. You can reach us at support@fairlead.uk about anything in this policy, including any request to access or delete your data.

What we collect

  • Account information — your username, your display name, the name and type of your business, and your workspace settings such as working hours and priority contacts.
  • Your conversations with the assistant — the messages you send and the replies it gives, so that your history is there when you come back. These can contain content drawn from your email, calendar and spreadsheets.
  • Files you attach in the chat — when you attach a document, we extract its text and store that text with the conversation. We also keep the file itself for 24 hours, and only so that you can ask the assistant to email it on — “send this quote to Dave”. After a day the file is deleted and the extracted text remains. The text is only sent to our AI provider when the assistant actually reads the document to answer you; the file itself never is. Deleting the conversation deletes both, and a file you upload but never send is removed the next time you attach one, and in any event when your workspace is deleted.
  • Attachments on your own email — when you ask the assistant about a message that has a document attached, it can open that attachment to answer you: a supplier invoice, a quote, a spreadsheet sent by a customer. We extract its text and store only that; the file itself stays in your mailbox and we keep no copy of it, not even for a day. It is read only when answering you needs it.
  • Photographs and scans — if a document arrives as a picture rather than as text, such as a photographed receipt or a scanned invoice, we can read the words out of the image. That reading is done by software running on our own servers, described under Code the assistant runs below. The image is not sent to any third-party image-recognition or OCR service. We keep the text it produced, and the date and time your camera recorded inside the file, so that your assistant can tell you when a photo was taken if you ask it; that date is kept alongside the text, for as long as the conversation is. Where the photo was taken is not read: a photo from a phone often carries the position it was standing in, and we neither look at it nor take it out of the file. The picture itself — and everything else your camera wrote into it — is kept only where the two points above say so: 24 hours for one you attach in the chat, not at all for one that arrived on your email.
  • Connected account data — email, calendar and spreadsheet data from the account you connect, described in detail in the next section.
  • Operational records — a log of actions the assistant took, when scheduled routines ran, and whether they succeeded, so that we can support you and keep the service working.
  • A mobile number, only if you switch on WhatsApp updates, and only after you have confirmed it by messaging us from that number.
  • WhatsApp messages, if you have switched WhatsApp updates on. That means both the updates we send you and the messages you send back: WhatsApp is a two-way conversation with your assistant, so anything you write there is treated like anything you write in the app. It is kept with the rest of your conversations, you can read the whole exchange in the app, and its content is sent to our AI provider to generate the reply, exactly as described below.

We do not buy personal data about you from anyone else. What we keep in your browser is described under Cookies below.

Cookies, and what else the app keeps in your browser

We set three cookies and no others:

  • A sign-in cookie, so that you stay signed in. It is set when you sign in and removed when you sign out; if you never sign out, it expires about thirteen months after you last used the app on that device. It identifies your account to our servers and does nothing else.
  • Two short-lived cookies while you connect a Google or Microsoft account. They last ten minutes and exist so that the connection Google or Microsoft sends back is the one you started in your own browser, and not one somebody else started for you. They are cleared the moment the connection completes.

The app also keeps three things in your browser that are not cookies. The answers you type into the setup wizard are kept in that browser tab until the wizard finishes, so that a refresh does not lose them; the app’s icon and logo are kept so that the installed app can draw itself; and which approval cards that tab has already shown you is kept until the tab closes, so that the reminder about a card waiting in another conversation does not repeat one you are looking at. None of them holds anything about you beyond what you typed.

None of this tracks you, on our site or anyone else’s. We use no analytics, no advertising cookies and no third-party scripts of any kind. Because everything above is needed to provide the service you asked for, the law does not require your consent for it, which is why there is no cookie banner. If we ever add anything that is not strictly necessary, we will describe it on this page first and give you a simple way to say no.

How Fairlead uses Google user data

If you connect a Google account, we ask for exactly four permissions and no others:

  • gmail.modify — read your messages, create drafts, and send. We read messages so the assistant can produce the inbox summaries and routines you set up (for example the morning update or end-of-day review), and so it can answer your questions about your mail. This includes opening an attachment on a message when answering you requires it. We create reply drafts in your own Gmail drafts folder for you to review. We send a message only when you explicitly ask the assistant to send it, or approve it doing so. We also apply and read Gmail labels, and can move a message to the bin at your request. We never permanently delete a message you have sent or received. The one exception is a draft: when you ask us to discard one, Gmail removes it outright rather than binning it, so there is nothing to restore.
  • calendar.events — read and create events on your primary calendar, so the assistant can tell you what is coming up and book an appointment when you ask.
  • spreadsheets — read and update Google Sheets, so the assistant can work with the spreadsheets you run your business on: reading a job list or price list, adding rows, and creating a new sheet when you ask for one.
  • drive.readonly — used only to find a spreadsheet by its name. Google shows this as “see and download all your Google Drive files”, which is broader than what we do with it, so it is worth being exact. We use it for one thing: searching for spreadsheets by name, so that you can say “open the job sheet” instead of hunting out a link. Every search we make is restricted to Google Sheets files, and asks only for their name, their link and when they last changed. We never download a file with this permission — reading what is inside a spreadsheet is done with the spreadsheets permission above, on a specific sheet you asked about. In the default setting, nothing in Fairlead can search or list your Drive at all; searching becomes possible only if you turn on the wider setting described below.

We ask for these together in a single consent screen, and we request the narrowest permissions that let those features work. We do not ask for permission to change or delete anything in your Drive, and we do not see files belonging to anyone else. We do not change your Gmail settings or filters; we read one setting only, the list of addresses you are allowed to send from, so that a reply goes out from the right one.

Two of these permissions are broader than the use we make of them, because Google does not offer a narrower version. calendar.events covers every calendar in your account, not just your main one — Fairlead confines itself to your primary calendar. spreadsheets covers every spreadsheet you can open — Fairlead confines itself to the ones you have linked. Those are limits we impose, described in the next section, not limits the permission imposes.

We only open the spreadsheets you choose

Google does not offer a per-file version of the spreadsheet permission, so the permission you grant is broader than what we actually use. We deliberately narrow it ourselves, and by default the assistant can only open spreadsheets you have explicitly linked on the Permissions page in Fairlead, and nothing else. Every spreadsheet the assistant touches has to be in that list, you can see the whole list at any time, and unlinking a spreadsheet removes the assistant’s access to it immediately. The same applies to Excel workbooks in OneDrive. Your assistant can also ask to add a spreadsheet to that list while you are talking to it — it can only do so with a file you have named, and only after you confirm.

That default is ours, not something the permission forces, so you can widen it: on the same page there is a switch that lets the assistant open a spreadsheet you name without linking it first, which is what the Drive permission above is for. It is off unless you turn it on, and you can turn it off again at any time.

It is worth being straight about what that switch changes. With it off — the default, and where every workspace starts — the assistant cannot reach your Drive or OneDrive at all; it can open the spreadsheets on your linked list and nothing else. With it on, it can search for a spreadsheet you have named instead of you linking it first.

What does not change is what it can reach. Every search is restricted to spreadsheets, on both routes into your files — whatever else you keep there is filtered out before we see it, and the assistant is never told those files exist. It asks only for a file’s name, its link and when it last changed, and it cannot download a file: reading what is inside a spreadsheet is done with the spreadsheet permission, on the one sheet you asked about. It cannot create, rename, move or delete anything in your Drive. And it stays within your own files — the ones you own and any a colleague has shared directly with you — never your organisation’s wider shared drives or SharePoint.

Where that data goes

Message, event and spreadsheet content — from your email, calendar and sheets, and from anything you send the assistant on WhatsApp — is retrieved by our servers, and is sent to our AI provider, OpenAI, purely so that the assistant can generate its reply. OpenAI does not use data submitted through its API to train its models. Content that appears in your assistant conversations is stored in our database (hosted by Supabase, in the European Union) so that you can see your own history, and each business’s data is separated from every other business’s at the database level and by running each workspace’s assistant in its own isolated container.

Your Google access and refresh tokens are encrypted (AES-256-GCM) before being stored, are held only on our server, and are never given to the assistant container or to any third party.

We never sell, rent or transfer Google user data to advertising platforms, data brokers or resellers; use it for advertising, retargeting or personalised marketing; or use it to assess creditworthiness or for lending decisions.

Code the assistant runs

To answer some questions the assistant writes a short piece of code and runs it — to total a column, compare two lists, or work through a spreadsheet a step at a time. That code runs on our servers in a separate locked-down container which has no access to the internet and holds none of your credentials. It cannot reach your Google or Microsoft account itself: it has to ask our gateway for each piece of data, and the gateway checks every one of those requests against the permissions described on this page — your own files only, no creating or deleting files, and the same confirmation before anything is sent or changed. Which spreadsheets it may open is governed by the setting above: the linked list when that setting is off, and any spreadsheet of yours it can find when you have turned it on. The same container is what reads the text out of a photographed or scanned document. Code and files are discarded when the request finishes.

AI model training

We do not retain, use or transfer data obtained through Google Workspace APIs, or through Microsoft Graph, to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models, including foundation models. Neither does our AI provider on our behalf.

Fairlead does maintain shared libraries of working practices — for each trade, and for small businesses generally — so that a new customer starts with something useful rather than a blank page. These are instruction notes about how a job is done — they are not copies of your correspondence, they never include email, calendar or spreadsheet content, identifying details are automatically stripped out before anyone reviews them, and nothing enters a shared library without our explicit review and approval.

Human access to your data

No one at Fairlead reads your email, calendar or spreadsheet data, your conversations with your assistant, or files you attach except in these cases: where you have given us your explicit consent to look at specific messages or files (for example when you raise a support request about a particular message); where it is necessary to investigate a security incident, abuse, or a fault you have reported; or where the law requires it. We do not browse customer mailboxes or conversations.

Limited Use

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

Fairlead’s use and transfer of information received from Google APIs to any other app will also adhere to the Google API Services User Data Policy, including the Limited Use requirements.

If you connect a Microsoft mailbox instead

The same principles apply, and the same page in the app controls it. When you connect a Microsoft account — a personal Outlook account or a work Microsoft 365 account — we ask for these permissions and no others:

  • Mail.Read, Mail.ReadWrite and Mail.Send — read your messages and their attachments, prepare drafts, and send a message when you ask the assistant to or approve it doing so.
  • Calendars.ReadWrite — read what is in your calendar and add or change an appointment when you ask.
  • Files.ReadWrite — work with Excel workbooks in your own OneDrive, and only the ones you have linked, unless you switch on the wider setting described above. This is deliberately the narrow permission: we do not request Files.ReadWrite.All, so we cannot reach other people’s files or your organisation’s wider SharePoint.
  • User.Read, openid, profile and email — read your name and the address of the mailbox you connected, so the app can show you which account is connected.
  • offline_access — keep the connection working without asking you to sign in again every hour.

Microsoft tokens are encrypted and stored in the same way as Google tokens, and are never given to the assistant container. Everything above about where data goes, AI model training, human access and retention applies to Microsoft data in exactly the same terms.

If you connect a mailbox over IMAP

For other mailboxes, the password you provide is encrypted and used only to reach your mail server. IMAP covers email only, with no calendar or spreadsheet access. To save you looking up server settings, we check the domain part of your email address — the example.com in you@example.com, never the whole address and never your password — against Mozilla’s public directory of mail-provider settings, and we look up that domain’s public DNS records to find its mail servers. If you would rather we did neither, you can enter your server settings by hand instead.

Who else processes your data

We use a small number of providers to run the service:

  • OpenAI — generates the assistant’s responses. Receives message, calendar and spreadsheet content as part of the request. Does not train on it.
  • Supabase — our database and sign-in system, hosted in the European Union.
  • Vercel — hosts the web application.
  • Hostinger — hosts the servers that run the assistant, read documents and hold the connections to your email and calendar.
  • Meta (WhatsApp Business) — only if you have switched on WhatsApp updates. Meta carries the conversation in both directions: the updates and replies we send you, and the messages you send to us. Meta handles those messages under its own terms as the operator of WhatsApp.
  • Mozilla — only when you set up an IMAP mailbox, and only the domain of your email address, as described above.
  • Our email provider — carries the account emails we send you (confirming your address, resetting a password) and any support request you send us, which contains whatever you wrote in it.
  • Anthropic — used only for the shared-libraries work described under AI model training, and only on the anonymised working notes described there. It never receives your email, calendar or spreadsheet content, and it is not involved in generating your assistant’s replies.

Reading the text out of a document or a photograph is done on our own servers and does not involve any of these providers other than the host they run on.

Some of these providers are located outside the United Kingdom and the European Economic Area. Where that is the case, transfers are made under appropriate safeguards, such as the UK International Data Transfer Addendum or standard contractual clauses.

How long we keep it, and how to get rid of it

  • Disconnecting an account — go to Permissions in the app and disconnect. We immediately delete the stored credentials and, for Google accounts, we also tell Google to revoke Fairlead’s access, so we can no longer reach your mailbox at all.
  • Unlinking a spreadsheet — on the same page. The spreadsheet itself is untouched and stays exactly where it is; only the assistant’s access to it ends. If you have switched on the wider setting described above, turn that off too, otherwise unlinking only removes the spreadsheet from the list.
  • Revoking from Google directly — you can remove Fairlead’s access at any time at myaccount.google.com/permissions.
  • Revoking from Microsoft directly — the equivalent page is myapps.microsoft.com for a work account, or account.live.com/consent/Manage for a personal one.
  • Deleting conversations — you can delete any conversation from the history page in the app, which permanently deletes its messages from our database, including any email content quoted in them and the text of any document read in them. Your assistant also keeps a working copy of the conversation inside its own container; that copy is removed when the workspace is deleted.
  • Deleting old conversations automatically — this is off unless you switch it on, and only the person who set up your workspace can switch it on or off, under Account in the app. While it is on, we check every day and permanently delete any conversation in your workspace that nobody has used for 60 days, in the same way as deleting it yourself: its messages, including any email content quoted in them and the text of any document read in them, and its approval requests. We never delete a pinned conversation, your WhatsApp conversation, a conversation one of your routines reports in, or a conversation with an approval still waiting or a reply still being written. As with deleting a conversation yourself, the working copy inside your assistant’s container is not removed by this; it is removed when the workspace is deleted. Switching it off stops any further deletion, but a conversation that has already been deleted cannot be recovered.
  • Deleting everything — email support@fairlead.uk and we will delete your workspace, its conversations, its connections and its assistant container within 30 days, other than records we are required to keep for legal or accounting reasons.
  • Operational logs are kept while your workspace is open, so that we can investigate faults and security incidents, and are deleted with the workspace.

Keeping it safe

The credentials for your connected accounts — your Google and Microsoft tokens, your IMAP password — are encrypted at rest with AES-256-GCM and are never placed in a customer’s assistant container, nor in the container that runs code or reads documents. Every workspace’s data is isolated at the database level using row-level security, and each workspace’s assistant runs in its own container. Connections between your browser, our servers and our providers are encrypted in transit. Access to production systems is limited to those who need it.

Your rights

Under UK data protection law you can ask us for a copy of your personal data, ask us to correct or delete it, object to or restrict how we use it, and ask for it in a portable form. Email support@fairlead.uk and we will respond within one month. If you are not satisfied with our response, you can complain to the Information Commissioner’s Office at ico.org.uk.

Children

Fairlead is a business tool and is not intended for, or directed at, anyone under 18.

Changes to this policy

If we change how we use your data we will update this page and change the date at the top. If the change is significant — for example if we ask for a new permission on your email, calendar or files — we will tell you in the app before it takes effect.

Fairlead
Email setupPrivacyTermsContact