Privacy Policy
Lalvani AI Hub · Last updated 20 August 2026
Lalvani AI Hub (“we”, “us”, “our”) operates Automation Hub (the
“Service”), a business automation platform that includes an optional AI Assistant which
produces a personalised daily briefing from your connected email and calendar. This policy explains what
personal data we process, why, and your rights. It applies to people who use the Service through an
account provided to them.
We are a sole-operator business based in the United Kingdom. For any privacy question, or to exercise your
rights, contact lalvanishaan5@gmail.com.
1. Information we collect
Account information
When your account is created (by invitation from your organisation’s administrator), we store your
name, email address, role, and the organisation (tenant) you belong to. Your password is stored only as a
salted, one-way BCrypt hash — we never store or have access to your actual password.
Email and calendar data (AI Assistant only — optional)
The AI Assistant is off by default. If you choose to connect a Microsoft 365 or Google (Gmail / Calendar)
account, we access the following strictly to build your briefing:
-
Recent inbox and sent-mail metadata only — sender, subject, date, and a short preview
snippet. We do not read, download, or store the full body of your emails.
- Recent calendar events — title, time, and attendees.
We request read-only permissions only (Google gmail.readonly and calendar.readonly;
Microsoft Mail.Read and Calendars.Read).
Connection tokens
When you connect an email account, the provider issues OAuth access and refresh tokens. These are stored
encrypted at rest and are used only to fetch the data described above. You can disconnect
at any time, which deletes them.
Generated briefings
The briefing we generate for you (a summary and suggested actions) is stored under your account so you can
view past briefings. The underlying raw email and calendar data used to build it is not
stored — it is processed in memory and then discarded.
Knowledge graph of derived facts (World Model)
The Service maintains a knowledge graph for each individual user — structured notes about
people, organisations, teams, projects, decisions, and commitments relevant to your work. Your knowledge
graph is private to your own account: it is not shared with your organisation, and other
users — including your organisation’s administrators — cannot read, edit, or search it. Entries can be
created manually by you and, when the AI Assistant is enabled, can be
suggested automatically: after a briefing runs we extract candidate facts from the same
email and calendar summaries described above (never from full message bodies) and store each suggestion
together with its provenance — the short source snippet that supports it.
-
This is derived data, not raw email storage. Raw message bodies are still never
read, downloaded, or retained.
-
Automatically extracted suggestions are stored as pending proposals and do not
enter your knowledge graph until you review and confirm them.
-
The Service also writes the notes on an entry automatically, but only where doing
so cannot overwrite your own writing. If an entry’s notes are empty, or the entry was created
by the Service and you have never edited it, generated notes are saved to it
without asking you first. If you wrote or edited the entry yourself — or if
the Service cannot tell, because the entry predates our recording of who wrote it — the
generated notes are instead offered to you as a pending proposal and your existing
text is left untouched unless you accept it. You can edit or delete any entry, and its notes, at any
time.
-
Generated notes are checked before they are stored. We instruct our AI provider never
to record special category data — information revealing health, racial or ethnic origin,
religious or philosophical beliefs, political opinions, trade-union membership, sex life or sexual
orientation, or any genetic or biometric data — and we then screen what it returns for such
language. Anything that trips that check is discarded: it is neither saved to the
entry nor offered to you as a proposal, and the entry is left exactly as it was. The check is
deliberately cautious, so ordinary notes are sometimes discarded as well; you can always write the
entry yourself.
-
To personalise a briefing, the Service may also match an email sender or calendar attendee against
an existing knowledge-graph entry to retrieve context. The limited matching fields sent for briefing
generation are described in section 4.
-
When you use the Ask feature to put a natural-language question to your knowledge
graph, your question is sent — together with your own graph entries (their
titles, types, and a short truncated preview of each entry’s notes) — to our AI provider
so it can return an answer that cites the entries it used. Only your own entries are
sent; no other user’s graph is included. This is described in section 4.
-
Knowledge-graph entries may reference people who do not use the Service (for example, a
correspondent mentioned in an email). You can delete any individual entry in your own
knowledge graph directly from its page in the World Model, and your entire knowledge graph is
deleted with your account. Deleting an entry keeps a record of its
name alone, so the same entry is not suggested to you again; that record is
encrypted, is listed on the World Model setup page where you can remove it, and is described under
“Deletion records” in section 5. Any referenced person can also ask us to
remove the entries that reference them — including any such deletion record
— by contacting
lalvanishaan5@gmail.com.
People and organisations you tell us about (roster — optional)
You can optionally declare the people and organisations you work with — your own
organisation, colleagues, clients and their contacts, projects, and products — on the World Model
setup page. For each entry you may record a name, the kind of thing it is, an optional note, and
alternative spellings and email addresses that refer to the same person or organisation.
-
Unlike the derived facts described above, this information is typed in by you rather
than extracted from your mail. It is entirely optional and the Service works without it.
-
It may include personal data about other people — colleagues and client
contacts — who are not users of the Service. Please only record what you need.
-
We use it to recognise those people when they appear in your mail and calendar, so the Service reuses
the entry you already created instead of creating a near-duplicate under a different spelling. Entry
names and types are included in the material sent to our AI provider during extraction, as described
in section 4.
-
Roster entries live in your own knowledge graph. They are private to your account, you can delete any
of them at any time, and they are deleted with your account.
Security and operational logs
For security we keep audit logs of significant account events (such as sign-in), which include your IP
address and browser user-agent, plus counts of AI tokens used. We keep these only as long as needed for
security and troubleshooting.
2. How we use your information
We use your information solely to:
- provide and operate the Service and your account;
- generate your personal daily briefing (AI Assistant), when you enable it;
-
maintain your own knowledge graph, including graph suggestions extracted from your briefing
inputs (AI Assistant) that you review before they enter your graph;
- answer your natural-language questions about your knowledge graph (the Ask feature), when you use it;
- keep the Service secure, diagnose problems, and provide support;
- comply with our legal obligations.
We do not use your information for advertising, and we do not sell it.
3. Google API Services — Limited Use
Automation Hub’s use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google
user data obtained through the Gmail and Google Calendar APIs is used only to provide the
user-facing AI Assistant features you have enabled — generating your daily briefing, proposing
knowledge-graph entries for you to review, and answering your questions about
your own knowledge graph (Ask); is not transferred to
others except as needed to provide those features, for security, or to comply with law; is
not used for advertising; and is not used to train generalised or
broadly-applicable AI / ML models.
Any human access to Google user data is prohibited except with your explicit consent, for security
purposes, to comply with applicable law, or where the data has been aggregated and anonymised.
4. Third parties that process data for us
To provide the AI Assistant and related account services, we share the minimum necessary with the following sub-processors:
- Anthropic (Claude API) — to generate your briefing, and to extract the
knowledge-graph suggestions described above, we send the email and calendar summaries
described above (sender / subject / snippet and event details), not full message bodies. When a sender
or attendee matches an existing knowledge-graph entry, we may also send a bounded selection of matching
World Model context: at most 30 entries by default (and never more than 100), consisting only of each
entry’s title, type, and a generated relationship-count summary. To stop the same
person or project being recorded twice under slightly different names, the knowledge-graph extraction
step — that step only, not briefing generation — additionally sends a
bounded list of the names and types of entries already in your World Model — at
most 200 by default and never more than 500 — together with the entries you declared yourself on
the Roster page and the alternative names you gave them. These are sent whether or not they appear in
that day’s email or calendar, so the name of someone you have recorded may be sent on a day they
did not contact you. We do not send graph body text, properties, source evidence, or individual
relationships to Anthropic for either briefing generation or extraction.
A separate enrichment step fills in entries whose notes are empty or very short. For a
small number of entries per run — at most 5 by default and never more than 25 — that step
sends more than the steps above do: the entry’s title, type and existing notes;
the titles, types and relationship directions of the entries it is linked to (at most 30
by default, never more than 100); and the stored source evidence snippets for that entry
(at most 10 by default, never more than 50, and configurable to none). Those snippets are short verbatim
extracts from the emails or calendar entries a fact was originally derived from. The entries chosen are
whichever have gone longest without being looked at, so an entry may be sent on a day it was not
mentioned anywhere. Anthropic processes these inputs in the United States and, under its API terms, does not
use API inputs to train its models. Separately, when you use the Ask feature to query
your knowledge graph, we send your question together with a bounded set of your graph entries —
their titles, types, the dates each entry was recorded and last had activity, and a
truncated preview of each entry’s notes (not the full
entry, and no properties or source evidence) — so Anthropic can produce an answer that cites the
entries used.
- ElevenLabs (only if voice briefings are enabled) — receives the text
of your generated briefing to synthesise audio; it does not receive your raw email or calendar data.
- Email delivery (SMTP) provider — to deliver your briefing and account emails.
- Hosting / infrastructure provider — to run the Service.
Each processes data only on our instructions. We do not sell personal data to anyone.
5. Data retention
- Raw email / calendar data: not retained (processed transiently).
- Generated briefings: retained under your account until you or we delete them.
-
Knowledge-graph entries and pending proposals (including their source snippets): retained under your
account until you delete them, a referenced person asks us to remove them, or your account is deleted.
-
Deletion records: when you delete a knowledge-graph entry, we keep a record of that entry’s
name and the date you deleted it, so the Service does not suggest the same entry
again on a later pass. The name is encrypted at rest like any other entry name. No other part of the
deleted entry — its notes, relationships, or source evidence — is kept. You can see these
records and remove any of them from the World Model setup page, and they are
deleted with your account.
- Connection tokens: retained until you disconnect the provider or delete your account.
- Account data: retained until your account is deleted.
- Security logs: retained only as long as necessary for security.
6. How we protect your data
Connection tokens are encrypted at rest using ASP.NET Core Data Protection; knowledge-graph content,
including node names, is likewise encrypted at rest using ASP.NET Core Data Protection (its identity is
preserved through a keyed one-way index so it stays searchable without exposing the names); passwords are
stored as BCrypt hashes; all traffic is served over encrypted TLS connections; and access to email /
calendar data is limited to generating the AI Assistant briefing you enabled.
Some operational metadata about your knowledge graph is stored unencrypted so the Service can query,
maintain, and draw it safely. This includes entry and relationship types, internal record and owner
identifiers, links between entries, timestamps, whether an entry was written by you or derived
automatically, proposal status and confidence, and keyed one-way values used for search and
deduplication. It does not include entry names, notes, relationship properties, proposal content, or
source evidence, which are encrypted. To be clear about the limit of this: someone with direct access to
the database could infer how many entries you keep, their categories, the kinds and timing of their
relationships, how they cluster together, and whether they were written by you or derived automatically,
even though every name, note, and source reference within them is encrypted.
7. Your rights
Because we operate in the United Kingdom, UK GDPR gives you the right to access, correct, delete, restrict,
or object to our processing of your personal data, and to data portability. Where processing relies on your
consent (connecting an email account), you can withdraw that consent at any time. To exercise any right,
contact lalvanishaan5@gmail.com.
8. Revoking access and deleting your data
- Disconnect a provider in the AI Assistant settings — this deletes the stored
tokens immediately.
- Revoke access from the provider’s side at
Google Account
permissions or your Microsoft account’s app permissions.
- Delete your account from the Account page — this removes your account and the
associated assistant data (profile, connections, and briefings). You can also ask us to delete your
data by email.
9. International transfers
Some processors (for example, Anthropic) are located in the United States. Where personal data is
transferred outside the UK / EEA, we rely on appropriate safeguards such as the processor’s standard
contractual clauses.
10. Children
The Service is intended for business use and is not directed to anyone under 18. We do not knowingly
collect data from children.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the
“Last updated” date above and, where appropriate, notifying you.
12. Complaints
If you have concerns about how we handle your data, please contact us first. You also have the right to
lodge a complaint with the UK Information Commissioner’s Office (ICO) at
ico.org.uk.
See also our Terms of Service.