Nurova Global Ltd ("Nurova", "we", "us") builds automation systems for business clients, including EIRA, an email triage and drafting assistant. This policy explains what data EIRA accesses, why, how it is stored, and how a client can end that access at any time.
1. What we access, and why
When a client connects a Gmail mailbox to EIRA, we request exactly two Google permissions (scopes) — never broader access:
- Read mailbox content (
gmail.readonly) — to read incoming messages so EIRA can categorize them and understand context for drafting replies. - Manage drafts (
gmail.compose) — to create draft replies inside the connected mailbox, and, only where a client has separately opted in, to send a reply after a human has approved it on the dashboard.
We deliberately do not request full mailbox-modify or account-management access. EIRA cannot delete a client's email, cannot change their account settings, and cannot access any other Google service (Drive, Calendar, Contacts, etc.).
2. What data is processed and stored
For each message in a connected mailbox, EIRA processes:
- Sender and recipient addresses, subject line, and message body text
- Image and PDF attachments, where present, to understand their content (e.g. an invoice or screenshot referenced in the email)
- Standard email authentication headers (SPF/DKIM/DMARC results) already generated by the mail system, used only to flag messages that may be spoofed
This data is used to produce: a category/priority label, a short internal summary, and — where relevant — a draft reply. These results are stored in a private, access-controlled database operated for the client's use, and are never made public or accessible to anyone outside the client's own authorized users and Nurova Global Ltd.
3. How AI is used
Message content is sent to Anthropic's Claude API to generate the category label and draft reply text. Anthropic processes this data solely to return a result to EIRA for that one request; Nurova Global Ltd does not use client email content to train any AI model, and does not permit any subprocessor to do so.
4. Human approval, always
EIRA's default behavior is to leave every reply as a draft for a person to review, edit, and send themselves. Where a client has explicitly enabled direct sending, a reply is still only ever sent after a specific human action (clicking "Approve & Send" on the dashboard) — EIRA never sends a message automatically upon classifying it.
5. Who else sees this data
Data is processed by a small number of service providers acting on our behalf, each under their own security and privacy terms:
- Google — the mailbox itself remains the client's own Google account at all times.
- Anthropic (Claude API) — processes message content to produce classifications and draft text, as described above.
- Supabase — hosts the private database storing classification results, draft text, and account metadata.
- Google Cloud — hosts the EIRA application itself.
We do not sell client data, and we do not share it with any third party for advertising or marketing purposes.
6. How long data is kept
Data is retained for as long as a client's EIRA connection is active, so that classification, drafting, and history features continue to work correctly. Upon a client's request, or when a service relationship ends, connected mailbox access is revoked and stored data is deleted within a reasonable period.
7. Ending access
A client may disconnect EIRA at any time in either of two ways:
- Removing EIRA's access directly from their Google Account permissions page — this immediately and completely revokes EIRA's ability to read or draft in that mailbox.
- Contacting us directly (below) to request the connection be removed and associated data deleted from our systems.
For clients using a forwarding-based setup (mail from another provider auto-forwarded into a dedicated Gmail mailbox), disabling that forwarding at the source stops any new mail reaching EIRA at all, independent of the above.
8. Google API Services User Data Policy
EIRA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
9. Contact
Nurova Global Ltd, Sri Lanka.
Questions about this policy or a data request: zia@nurovaglobal.com
This policy may be updated from time to time as EIRA's features change; the "last updated" date above will reflect the most recent revision.