← Back to blog
Connecting your mailbox to a third-party service means giving it access to extremely personal data: private correspondence, invoices, bank details, business access... The question "what is done with my data?" is legitimate. Here are our concrete, verifiable commitments on email confidentiality.

Hosting: everything in France / EU

All our application servers and databases are at OVHcloud (Roubaix, France). No customer data is hosted outside the EU. This eliminates issues related to the US CLOUD Act and ensures GDPR-by-design.

The only exceptions are strictly necessary subprocessors (see section 4): Anthropic (AI analysis, USA), Stripe (payments, USA), all framed by the European Commission's Standard Contractual Clauses (SCCs) and certified Data Privacy Framework (DPF).

IMAP credential encryption

When you connect a mailbox via standard IMAP, your login + password transit to Fiabli (in TLS 1.2 minimum) then are stored encrypted at rest in AES-256-GCM. The master encryption key is stored on the server in a .master.key file outside the database — a SQL dump isn't enough to decrypt the credentials.

Concretely: if someone steals our database tomorrow, they get unreadable encrypted strings, not your real IMAP passwords.

For Gmail / Microsoft 365 accounts, we use OAuth 2.0 and only store refresh_tokens (themselves encrypted), not passwords. We request minimum permissions: read new mail + move between folders. No send permission, no reading of sent, no calendar or contacts access.

What does Fiabli see, what doesn't Fiabli see?

What Fiabli analyzes:

  • Email headers (From, To, Subject, Date, SPF, DKIM, DMARC)
  • Email text body
  • Contained URLs
  • Attachment names

What Fiabli NEVER reads:

  • Binary content of attachments (PDF invoices, photos, etc.)
  • Your sent emails
  • Your calendar, contacts, drives
  • Emails already read before connection (only new incoming)

No Fiabli employee individually consults your emails. The only admin accesses happen in the context of a technical support explicitly requested by you, and only on metadata (verdict, date, sender), never on full content.

Anthropic subprocessing: 30 days max, no training

AI analysis goes through Anthropic (Claude models, hosted in USA). When an email is analyzed, its content (subject, sender, text body, URLs) is sent to the Anthropic API.

Anthropic's contractual commitments to us (and you):

  • No use for training models. Guaranteed by contract in the Anthropic commercial API.
  • Maximum 30 days retention for anti-abuse purposes, then permanent deletion.
  • USA transfers framed by SCCs + DPF EU-USA certification.

For customers who absolutely don't want non-EU AI analysis, we're working on a Mistral Large 2 option hosted in France for 2026 H2.

Your GDPR rights: exercise in 1 click

Per GDPR articles 15 to 22, you have the right to:

  • Access all your data → "Export my data" button in Settings
  • Rectify inaccurate data
  • Erase your account → "Delete my account" button. Effective deletion within 30 days, except invoices kept 10 years (legal accounting obligation).
  • Receive your data in a readable format (JSON / CSV export)
  • Object to any processing based on legitimate interest
  • Complain to your data protection authority if you feel your rights aren't respected

Our team responds to GDPR requests within a maximum delay of one month. Email: contact@fiabli.io with "GDPR Request" as subject.

Our commitment

Privacy isn't a marketing argument for us. It's the condition of the service's existence: a phishing detector that gets hacked would be an absolute disaster. So we take measures beyond what GDPR requires: AES-256-GCM encryption, master key outside DB, minimum subprocessors, total transparency on flows.

Our complete privacy policy details every point above. For any question, write to us — we respond within 48h.

Ready to protect your mailbox?

Activate Fiabli in 2 minutes. First verdict in under 2 seconds. Free plan forever.

Create a free account

Related articles