Data protection

GDPR and the AI email client

The moment a mail app summarises, sorts or drafts replies, it processes personal data. This page explains plainly what happens, which questions to put to your vendor, and where BoxBee stands.

What an AI mail client technically does with your data

A mail app without AI fetches messages from your provider and displays them. Processing happens on your device. As soon as an AI feature is added that changes: to summarise, classify or draft, the text of the message has to reach a model, and the model does not run on your machine.

That is true of every vendor in this field, BoxBee included. Anyone claiming otherwise either means a very small on-device model or is being imprecise. The honest answer is: content is transmitted, and the relevant questions are which content, to where, stored for how long and on what legal basis.

The four questions to ask any vendor

These four questions separate vendors faster than any feature list. If an answer evades or slides into marketing language, that is itself an answer.

  • Which data leaves my device, and at exactly which action? Only when summarising, or continuously in the background?
  • In which country are the servers that do the processing, and who operates them?
  • Is my content stored, and is it used to train models?
  • Is there a data processing agreement under Article 28 GDPR, and who are the sub-processors?

Why the processing location so often becomes the core question

The GDPR has its own rules for transferring personal data to third countries. In practice that means data protection officers, works councils and supervisory authorities look harder at US vendors and ask for more documentation. If the processing happens in Europe anyway, a large part of that discussion falls away.

That is why BoxBee is built this way: AI requests go to Mistral, a model developed in France, and are processed on servers in Europe. The vendor, TTA Technologies, is based in Luxembourg. That is not a promise of legal safety and it does not replace your own assessment, but it is a chain without a change of legal jurisdiction.

BoxBee is a client, not a mailbox provider

This distinction is important and often muddled. BoxBee does not host mailboxes and does not hand out addresses. Your mailbox stays with whoever provides it today, and BoxBee connects to it over IMAP and SMTP.

For your documentation that means: your mail provider stays in the record of processing activities unchanged, and BoxBee is added as a further processor for the AI features. If you cannot or will not move your mailbox, nothing has to be rebuilt.

What BoxBee explicitly does not claim

That clarity is deliberate. A privacy page that promises more than it can hold costs more trust at the first close look than it ever gained.

  • No ISO 27001 certification, no SOC 2 report, no seal that cannot be evidenced here.
  • No claim that deployment in your organisation is automatically permissible. Your own assessment decides that.
  • No encryption that does not exist. End to end encrypted are the BeeCrypted direct messages between BoxBee users, not ordinary mail to third parties.

What you can practically do

Take the BoxBee privacy policy, read the section on AI processing and hold it against the four questions above. If you work in a regulated sector, hand that section to your data protection officer before rolling out. And test for seven days with a real mailbox, because only then do you see which content actually passes through the AI features in daily work.

Last checked: July 2026

Try BoxBee for seven days

Connect an account, let the mailbox load, then decide. No migration, no new provider: BoxBee speaks IMAP and SMTP to the mailbox you already have.

Keep reading