Trust
Where your email goes
Kerna reads a message only when you press a button, redacts personal data before anything reaches the model, processes what remains in memory, and writes none of that content down. Your account, your plan and your settings are stored, because the service cannot run otherwise; your email is not. This page is the long version, with the source for every claim in our Privacy Policy. It exists so your security review can be a read rather than a meeting.
Every claim on this page is sourced from our Privacy Policy or Terms. Last checked against them on .
The short version
The ten questions your security review will ask
If you only read one section, read this one. Each answer points at the clause it comes from.
- Is our email content stored anywhere?
- No. When you trigger an action the relevant text is sent over an encrypted connection, held in volatile memory only for as long as the request takes, and discarded once the result reaches your sidebar. No email content is written to any database, log file or persistent storage. The retention table in our Privacy Policy records email content as zero.
- Does Kerna read the inbox in the background?
- No. Kerna operates exclusively on user-initiated actions. It does not passively scan, index, monitor or archive your inbox, calendar, contacts or any other mailbox data. Every interaction with your data requires an explicit action by the person using it.
- What exactly does the AI provider receive?
- The text of the message or draft you are acting on, plus your instruction, with personal data redacted first. The redaction happens inside Kerna’s own processing, so the redacted personal data never reaches the provider at all, and it runs on every request rather than being an option you enable. Your account identifiers, email address and billing data are never sent.
- Is our data used to train AI models?
- No, and not by OpenAI either. Your data is never used to train, fine-tune, retrain or improve any model, ours or anyone else’s. Our agreement with OpenAI includes Zero Data Retention terms: content Kerna transmits for inference is excluded from OpenAI’s abuse-monitoring logs and is not retained once the request has been served.
- Where does the service run?
- Kerna’s own infrastructure is in the EU: the application runs on Google Cloud Run in Belgium (europe-west1), with Firestore in Poland (europe-central2), and Kerna sp. z o.o. is a Polish company, so the controller is inside the EU as well. Inference is a separate question and the honest answer is separate too: our agreement is with OpenAI Ireland Limited, and that agreement permits transfers outside the EEA under Standard Contractual Clauses, so we do not claim the model call itself stays in the EU. Section 11 of the Privacy Policy sets out the sub-processor position and the safeguards covering it.
- Can a Kerna employee read our messages?
- No, and there is nothing stored for anyone to read. Personnel access to user data obtained through the platform APIs is prohibited except with your affirmative agreement for specific messages, where necessary to investigate abuse, or to comply with law. Because message content is never written to disk, there is no archive of your correspondence to be accessed, leaked or subpoenaed. That removes one class of risk; it does not remove the risk that exists while a request is being processed, which is what the encryption and access controls below are for.
- Can a team leader see what their team is emailing?
- No. Team leaders see usage — tokens spent and actions run per member, and on Enterprise a log of when those actions took place. None of it includes message content, subject lines or recipients, because Kerna does not store them anywhere.
- Has any of this been independently reviewed?
- Partly, and it is worth being precise about which part. The Gmail add-on has completed Google’s OAuth verification and holds a CASA Tier 2 Letter of Validation — an assessment carried out by an independent third party, which is what Google requires of apps that access Gmail data. On the Microsoft side the Outlook add-in holds Publisher Attestation, which is our own self-assessment published by Microsoft for customers to read; Microsoft does not independently verify it, and it is not Microsoft 365 Certification. The two are not equivalent and we do not present them as equivalent.
- Will you sign a Data Processing Agreement?
- Yes. We can provide a data processing agreement covering the email content processed through Kerna, together with our sub-processor list and the safeguards we rely on for international transfers — Standard Contractual Clauses are incorporated into our agreements with each sub-processor where a transfer requires them. Write to support@kerna.io and tell us which entity the agreement should name.
- How do we delete everything?
- There is no email content to delete, because none was kept. For the rest, Kerna provides a data deletion endpoint that removes your profile, statistics and analytics data from all collections, and account data is deleted within 30 days of account deletion. One exception, and it is a legal one rather than a choice: billing records are kept for seven years for tax compliance, as the retention table below sets out. support@kerna.io will run the deletion on request.
The request path
What happens when someone presses a button
Four stages. Personal data is stripped out at the second one, before anything is transmitted, and what remains exists only for as long as the request takes.
- 01
Nothing happens until you act
The add-in sits in the ribbon or sidebar doing nothing. There is no scheduled job, no sync, no index. A message is touched only when someone presses Summarize, Reply, Translate, Compose, Extract or Rewrite.
- 02
Personal data is redacted first
Before anything leaves Kerna, personal data is redacted from the message content. This runs inside our own processing on every request — not as an option you enable — so the redacted data never reaches the inference provider at all.
- 03
The rest travels encrypted
What remains is sent to our inference provider over an encrypted connection, protected with TLS 1.2 or higher, and only the minimum text context the feature needs is sent.
- 04
It is processed in memory, then discarded
The content is held in volatile memory only for the time the request takes — never queued, cached, logged or written to a database. Once the result reaches your task pane the source content is gone, and the result is not stored either.
Never collected
What is never written down
Kerna reads these to do the job you asked for. None of them is stored, logged, cached or written to any persistent storage afterwards — which is a different and stronger statement than deleting them on a schedule.
- Email message bodies, subjects, or headers
- Sender or recipient email addresses from processed emails
- Attachment content or metadata
- AI-generated summaries, replies, translations, or drafts
- Calendar event content, contact details, or spreadsheet data accessed during user-initiated actions
- Account passwords or OAuth refresh tokens beyond what is required for active session management
Retention
What is kept, and for how long
The full table from Section 12 of the Privacy Policy, unedited.
| Data category | Retention period |
|---|---|
| Email content (processed) | Zero. Discarded immediately after processing. |
| Account data (email, name) | Retained while your account is active. Deleted within 30 days of account deletion. |
| Subscription and billing data | Retained while your subscription is active. Billing records retained for 7 years for tax compliance. |
| Usage metrics (token counts) | Retained while your account is active. Reset each billing cycle. |
| Preferences (language, tone) | Retained while your account is active. Deleted with account. |
| Analytics data (GA4) | Retained for 14 months per Google Analytics default configuration. |
| Early access / contact submissions | Retained until product launch or inquiry resolution. Deleted upon request. |
Sub-processors
Who else touches anything
Five, each receiving only what its function needs. Stripe never sees an email; OpenAI never sees billing data.
OpenAI
AI inferenceThe text of the email or draft you are acting on, plus your instruction, only when you trigger an action. Encrypted in transit, processed transiently, not stored, not used for training. Account identifiers, email address and billing data are never sent.
Stripe
Payment processingEmail address for customer identification. All payment details are handled directly by Stripe; Kerna never sees a card number.
Google Firebase
Authentication, database, hostingAccount data, subscription status, usage metrics and preferences. No message content.
Google Analytics
Website analyticsAnonymous, aggregated website usage data, subject to consent. Website only — the add-in is not analytics-instrumented against your mailbox.
Sentry
Error tracking and performance monitoringHashed user identifiers, error stack traces and operational metadata. No email content, recipients or subject lines.
Mailbox access
Exactly what Kerna can reach
Every scope the add-ins request, matching Section 8 of the Privacy Policy as it stood on the review date at the foot of this page, with what each one is used for.
Google Workspace
Eleven scopes, the set the add-on manifest requests. Google asks for the optional ones separately, so you decide which to grant. The identifiers below are Google’s own OAuth scope strings, each one prefixed https://www.googleapis.com/auth/ — the same strings the Marketplace listing is generated from, so the two lists can be checked against each other.
- userinfo.email
- Confirm your identity and read the address you signed in with.
- gmail.addons.execute
- Run the Kerna panel inside Gmail. On its own it gives no access to mail.
- gmail.addons.current.message.action
- Act on the message you have open, when you trigger a function from the panel.
- gmail.addons.current.message.readonly
- Read the message you have open, when you trigger a function from the panel.
- gmail.readonly
- Read the rest of the thread and its attachments for Summarize, Translate, Extract and Rewrite.
- gmail.compose
- Create a draft in your compose window. Google’s own wording for this permission is wider than what Kerna does with it — see the note under the table.
- calendar.events
- Create an event from a date and time found in a message, only when you confirm it.
- calendar
- Check your calendar for a conflict at the time an extracted event would fall.
- tasks
- Create a task from an action item when you ask for one.
- contacts
- Look up or add a contact when you request a contact action.
- drive.file
- Write the Google Sheet or Google Doc an extraction exports to. It reaches only files Kerna itself creates, never the rest of your Drive.
Microsoft 365
Ten scopes. On Outlook no permission to send mail is requested at all — unlike Gmail, where writing a draft needs the scope described under the table.
- Mail.Read
- Read the current message when you trigger an action.
- Mail.ReadWrite
- Insert generated drafts into your compose window.
- Calendars.ReadWrite
- Check availability and create events from dates you extract, on explicit confirmation.
- Tasks.ReadWrite
- Create tasks from action items when you ask for them.
- Contacts.ReadWrite
- Look up or add contacts when you request a contact action.
- People.Read
- Read your relevant people list to support contact actions.
- MailboxSettings.ReadWrite
- Read your time zone, language and working hours so extracted dates and conflict checks are right for your region. Write is used only to apply a setting you change yourself inside Kerna.
- Mail.Read.Shared
- Read the message you are working on in a shared or delegated mailbox your organisation has already granted you.
- Mail.ReadWrite.Shared
- Create or update a draft, and file a message you have triaged, in a shared or delegated mailbox you already have permission to use.
- User.Read
- Confirm your identity and read your name and email at sign-in.
Kerna cannot reach a mailbox your organisation has not already granted you access to, and it does not send mail. Be aware of one wording difference you will see for yourself: Google’s own label for the Gmail scope an add-on needs in order to write a draft is “Manage drafts and send emails”, so that phrase appears on our Marketplace listing. Kerna uses that scope to create the draft and never to send. On Outlook no send permission is requested at all.
Assurance
What has been assessed, and by whom
CASA Tier 2 Letter of Validation
The independent security assessment Google requires of applications that access Gmail data. Held alongside completed Google OAuth verification.
Microsoft Publisher Attestation
A self-assessment we completed and Microsoft publishes for customers to read. Microsoft does not independently verify the answers, and it is not Microsoft 365 Certification — so it belongs on this page as a disclosure, not as an audit.
Google API Limited Use and Microsoft APIs Terms of Use
Data from both platforms is used only to deliver the user-facing features, is never sold or transferred, is never used for advertising, and only the minimum scopes needed are requested.
Encryption and access control
TLS 1.2 or higher in transit, AES-256 at rest in Firestore, secrets in Firebase Secret Manager rather than source, role-based access to production, and document-level Firestore rules. A breach affecting personal data is notified within 72 hours under GDPR Article 33.
AI content is labelled
Drafts Kerna produces carry a machine-readable marker identifying them as AI-generated, in line with the transparency direction of the EU AI Act. An optional visible note can be switched on.
GDPR rights
Access, rectification, erasure, restriction, portability and objection, exercised through privacy@kerna.io. The legal bases are set out in the Privacy Policy.
Rollout
What IT needs to know before rollout
- Outlook requires a mailbox hosted by Microsoft: Microsoft 365, Exchange Online or Outlook.com. Microsoft does not load add-ins on accounts connected over POP or IMAP, and mailboxes on an on-premises Exchange server are not supported.
- On the client side Kerna runs in Outlook on the web, the new Outlook for Windows and Mac, and classic desktop Outlook.
- A Microsoft 365 administrator can deploy the add-in to the whole organisation from the Microsoft 365 admin center; a Google Workspace administrator can install the Gmail add-on for the entire domain from the Google Workspace Marketplace.
- Each person still signs in individually to link their Kerna plan. Authentication is Google OAuth or Microsoft sign-in — Kerna never creates, manages or stores a password.
Send us the questionnaire
Send us your security questionnaire or your IT team’s questions. We will answer them against the same sources this page cites, and add anything that turns out to be missing here.
