Cadence ← Back to home
CONTRACTUAL DOCUMENT

Privacy policy

LAST UPDATED: 20 JULY 2026 · VERSION 1.0

The essentials in four points. Your emails are read only by automated processing, to sort, summarise and prepare your replies. They are never used to train an artificial intelligence model. Identifying data is anonymised locally before any call to a language model. Your data is hosted in the European Union and you can delete everything at any time.

1. Who is the data controller?

The Cadence service (“Cadence” or “the Service”) is published by Diego Ferreira Fernandez, sole trader (autónomo, Spain), Ronda del General Mitre 112, 2º-2ª, 08021 Barcelona, Spain, acting as data controller within the meaning of Regulation (EU) 2016/679 (“GDPR”) and French act no. 78-17 of 6 January 1978 as amended (“Informatique et Libertés”).

For any question about your data: 10egoferr@gmail.com.

2. What data do we process?

  • Account data: email address, name and profile picture provided by Google during OAuth 2.0 sign-in.
  • Mailbox content: the emails of the Gmail account you voluntarily connect (sender, subject, body, dates, labels), limited to what is necessary for the features described in article 3.
  • Derived data: triage categories, summaries, reply drafts and follow-up suggestions generated by the Service from your emails.
  • Billing data: subscription status and transaction identifiers provided by our payment provider Stripe. Cadence never sees or stores your card number.
  • Technical data: connection and error logs strictly necessary for the security and proper operation of the Service.

3. Why do we read your emails? (purposes)

Your mailbox content is processed exclusively to provide the services you subscribed to:

  • Semantic triage: automatically classifying each incoming email (booking, logistics, administration, other) to prioritise your reading;
  • Summarising: producing a short summary of each conversation;
  • Preparing replies and follow-ups: writing drafts that only you validate and send.

No other purpose is pursued. Your emails are not used for advertising, are not sold, rented or shared with third parties for commercial purposes, and are not subject to any profiling unrelated to the features above. No human reads your emails, except at your explicit support request and with your prior agreement.

PURPOSELEGAL BASIS (ART. 6 GDPR)
Triage, summaries, drafts, follow-upsPerformance of the contract (art. 6.1.b)
Billing and subscription managementPerformance of the contract and legal obligations (art. 6.1.b and 6.1.c)
Security, abuse prevention, technical logsLegitimate interest (art. 6.1.f)
Service information emails (waiting list, beta)Consent (art. 6.1.a), withdrawable at any time

4. Guarantee that AI models are not trained on your data

Contractual commitment. The data of Cadence users — emails, summaries, drafts, metadata — is never used, by Cadence or its processors, to train, fine-tune or improve any artificial intelligence model, whether public or private. This commitment forms an integral part of our contractual terms.

In practice: calls to language models are made exclusively through professional APIs whose terms contractually exclude the use of submitted data for model training. We enable no sharing or retention option for model improvement purposes, and we audit those terms whenever our providers change.

5. Anonymisation before any call to a language model

Before an email excerpt is sent to a language model, it goes through an anonymisation pipeline running on our own servers: directly identifying data (email addresses, phone numbers, IBANs, postal addresses, identifiers) is detected and replaced with neutral tokens. The language model therefore only receives pseudonymised text, limited to what is strictly necessary for the task (triage, summary or drafting). The mapping between tokens and real data never leaves our infrastructure.

6. Where is your data hosted?

Service data (synchronised emails, derived data, account data) is stored in the European Union, in data centres located within EU territory and subject to the GDPR. Keeping data at rest in Europe is a deliberate architectural choice, so as to apply the strictest security and privacy standards.

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Internal access is restricted, logged and limited to what is strictly necessary.

7. Processors and transfers outside the EU

Cadence relies on a limited number of processors, each bound by a data processing agreement (DPA) compliant with article 28 GDPR:

PROCESSORROLEDATA LOCATIONSAFEGUARDS
Google Cloud (Firestore)Service databaseEuropean Union regionDPA, standard contractual clauses (SCC), EU-U.S. Data Privacy Framework certification
NetlifyWebsite and application function hostingEU / United States (execution)DPA, SCC
OpenAI (API)Language model (triage, summary, drafting) — on anonymised data onlyUnited StatesAPI DPA, SCC, contractual no-training, no retention
StripePayment and billingEU / United StatesDPA, SCC, PCI-DSS certification

Where processing involves a transfer outside the European Union, it is governed by the mechanisms provided for in chapter V of the GDPR (European Commission standard contractual clauses, supplemented by technical measures: encryption, prior anonymisation described in article 5). An up-to-date list of processors is available on request at the address given in article 1.

8. How long do we keep your data?

  • Mailbox content and derived data: for the lifetime of your account. Deleted within a maximum of 30 days after account deletion or revocation of Gmail access.
  • Account data: lifetime of the account, then deletion within 30 days.
  • Billing data: 10 years (legal accounting obligation).
  • Technical logs: 12 months maximum.
  • Waiting list / pre-sale: until the Service launches or until you unsubscribe.

9. Your rights

In accordance with articles 15 to 22 of the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability of your data, as well as the right to give post-mortem directives. You may exercise them at the address given in article 1; we respond within one month.

You may also, at any time and without contacting us:

  • revoke Cadence's access to your Google account from myaccount.google.com/permissions — synchronisation stops immediately;
  • export all of your data from the Service;
  • delete your account and all associated data.

If you consider that your rights are not being respected, you may lodge a complaint with the French CNIL (cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07) or with the supervisory authority of your country of residence.

10. Google user data (Limited Use)

Cadence's use of information received from Google APIs complies with the Google API Services User Data Policy, including its “Limited Use” requirements: Gmail data is only used to provide the user-facing features of the Service, is never transferred to third parties beyond the processing described in article 7, is never used for advertising purposes, and is never read by humans outside the cases exhaustively permitted by that policy.

11. Changes

Any substantial change to this policy will be notified to you by email at least 30 days before it takes effect. The version in force is dated at the top of the document.

Legal notice Terms Privacy Cookies FREN © 2026 CADENCE