AI processing
Last updated: July 2026
MailMCP uses generative AI models for a limited number of features. This section documents what we process, why, where, and how — in line with EU AI Act Art. 50 (transparency) and GDPR Art. 13/14 (information of data subjects).
AI features and purposes
- Public chatbot (Léa). Answers visitor questions about MailMCP features. Visible AI label.
- Support reply assistance. Drafts a suggested reply to support tickets, reviewed by a human before sending. PII (email, IBAN, IP, card, phone) is automatically stripped before the prompt is sent to the model.
- Outreach pitch generation. On-demand only — generates personalized outreach drafts for the user, from public data (YouTube channel description, declared website).
Providers and data residency
All AI inference is routed through OpenRouter with a strict EU-provider order:
azure → amazon-bedrock → google-vertex → mistral.
Fallback to non-EU providers is explicitly refused. Data collection by the provider for training is disabled (data_collection=deny). No prompt or response is used to train any model.
What is logged
For traceability (EU AI Act) and cost monitoring, we log metadata for every AI call:
- Timestamp, preset (purpose), model, provider, tokens, cost, latency, status.
- User ID (for authenticated calls) — never the prompt content or response content.
- Retention: 90 days, then automatic purge.
Transparency and human oversight
- AI-generated responses are explicitly labelled (chatbot, support drafts).
- No fully automated decision-making with legal effect — every customer-facing AI output is reviewed by a human.
- You can request the deletion of any AI metadata related to your user ID by contacting privacy@mailmcp.io.
Your rights when interacting with our AI
- Right to know. You are always informed when you are talking to an AI (EU AI Act Art. 50). Léa, our chatbot, displays an explicit "AI" badge on every message.
- Right to a human. At any moment, you can stop talking to Léa and reach a real person at contact@mailmcp.io.
- Right to opt out of AI processing. GDPR Art. 22 — you have the right not to be subject to a decision based solely on automated processing. We do not perform automated decisions affecting your access, billing, or account status.
- Right to lodge a complaint. If you believe our AI use violates GDPR or the EU AI Act, you may lodge a complaint with the CNIL (France) or your national supervisory authority.
Known limitations of generative AI
Generative AI models are statistical predictors of plausible text. They can produce confident-sounding but incorrect answers. We require our users to keep this in mind (EU AI Act Art. 4 — AI literacy).
- Hallucinations: the model can invent features, prices, URLs, or technical details.
- Knowledge cutoff: training data ends before the model release date.
- Not a legal, medical, or financial advisor: chatbot output is informational only.
- For billing, account state, or technical changes — always confirm via the dashboard or human support.
Regulatory classification
Under the EU AI Act, our AI features fall into the "limited risk" category (Art. 50) — transparency obligations only. We do not deploy: prohibited practices (Art. 5: social scoring, biometric categorisation, emotional inference at work, etc.), nor high-risk systems (Art. 6 Annex III: employment, credit scoring, law enforcement, etc.).
AI / privacy contact
For any question on AI processing, data deletion, or to exercise your rights: privacy@mailmcp.io. We respond within 30 days (GDPR Art. 12).
© 2026 MailMCP — STAY WEB (SASU). All rights reserved.