Privacy Policy

Exactly what we
do with data.

Lulal AI is an AI productivity assistant that provides an AI sidebar (chat, grammar fixing, translation, PDF/image tools) and AI-powered email features (summarize, reply suggestions, classification) on Gmail and Outlook. This policy describes exactly what data the extension processes, based on its actual behavior.

📅 Effective date: July 15, 2026
Applies to the Lulal AI Chrome Extension
01
Data We Collect and Process
Account and authentication data
  • Email address and password — sent to our backend only when you sign in or register. Your password is never stored by the extension.
  • Registration details — username, first name, last name (if you register).
  • Authentication tokens — a JWT access token and refresh token issued by our backend are stored locally in your browser (chrome.storage.local) to keep you signed in. Your account email address and sign-in provider (classic / Google / Microsoft) are also stored locally.
  • OAuth sign-in — if you sign in with Google or Microsoft, authentication happens on our backend's OAuth flow; the extension only receives and stores the resulting token and your email address. The extension does not access your Google or Microsoft account beyond this sign-in.
Email content (only when you use an email feature)

When you actively use Summarize, Generate Replies, Custom Reply, chat "include email", or when automatic classification runs on an open email, the extension reads the currently open email from the page (subject, sender name/address, message dates, and message bodies) and sends it to our backend for AI processing. Email content is read only from the visible email you have open in Gmail or Outlook; the extension does not access your mailbox via any email provider API.

Files you attach

If you attach files to a custom reply, chat message, or custom template (PDF, DOCX, XLSX, EML, MSG), the file content is uploaded to our backend for AI processing.

Text you submit

Text you enter for grammar fixing or translation, chat messages, custom instructions, prompt templates, and custom template definitions are sent to our backend to produce the result.

Settings and preferences
  • Stored locally in your browser: interface language, sidebar width and toggle-button position, tone/language preferences, and your authentication tokens.
  • Stored on our server (linked to your account): default tone, default language, reply count, your saved prompts and custom templates, and chat sessions (including their messages and any email content you chose to include).
Subscription data

The extension retrieves your subscription status (plan name, expiry date) from our backend for display. It does not collect or process any payment information.

PDF and image tools
PDF merge/split, image-to-PDF, and image resize run entirely locally in your browser. Files used with these tools are never uploaded.
02
Where Data Is Sent and Stored

All network communication goes exclusively to our backend server.

The extension makes no requests to any other server. It contains no analytics, tracking, or advertising code, and loads no third-party scripts from the network. Server-side, our backend forwards the content you submit to our AI model provider, OpenAI, solely to generate the result you requested.

Locally, data is stored only in chrome.storage.local on your device (tokens, email address, UI preferences).

03
How We Use Data

Data is used solely to provide the extension's features: authenticating you, generating AI summaries/replies/classifications/translations/grammar corrections, running chat sessions and templates, and remembering your preferences. AI processing of your submitted content happens server-side.

We do not sell your data and do not use it for advertising. To generate AI results, our backend sends the content you submit (email text, chat messages, text to fix/translate, attached file content) to our AI model provider, OpenAI, strictly as a data processor to fulfill your request. Beyond these service providers and our hosting provider, your data is not shared with anyone.

04
Data Retention and Deletion
  • Local data — removed when you log out (tokens and email are cleared) or uninstall the extension.
  • Email summarization, reply generation, classification, grammar fixing, and translation — processed transiently: the submitted content is not stored on our servers after the response is returned (we retain only anonymous token-usage counts for quota purposes).
  • Chat sessions (including any email content you chose to include) — stored on our servers so you can revisit them, until you delete them. Deleting a chat session from the extension permanently removes it and its messages from our database.
  • Account data, settings, prompts, and templates — retained while your account is active; prompts and templates can be deleted from within the extension at any time.
Account deletion
To request deletion of your account and all associated server-side data, contact us at contact@lulal.ai.
05
Contact
Privacy questions or data requests?
For any privacy questions or data requests, reach out to us by email.
06
Changes to This Policy

We may update this policy as the extension evolves. The effective date above reflects the latest revision.