A copy of you reads your mail and can act in your voice. Here’s exactly how that works, what you decide, and how your data is handled — in plain terms.
It reads your mail and writes drafts in your voice. It cannot send a single message on its own. Nothing goes out in your name until you turn sending on yourself — one lane at a time — and you can switch it back off in a tap.
If it can’t see the whole picture — a message it couldn’t read, an ask it can’t pin down — it flags it and waits for you. It won’t send something wrong in your name to paper over a gap.
You see every draft before it goes out — nothing is sent blind. Building: once you grant a lane, a full record of everything it does, each action undoable.
Building: it watches how people respond to what it sent — the moment a reply reads as off (a confused answer, a wrong turn), it raises a flag to you right away, before it becomes a problem.
Pause the whole thing in one tap. Revoke its access from your Google account whenever you want — you don’t have to ask us.
What it learns about you trains only your copy — never pooled into a model shared with other users. Anthropic, the AI behind it, doesn’t train on your data either.
We charge for the product. We don’t sell your data and we don’t run ads.
The system processes your mail; people don’t read through it. Access is least-privilege and limited to a small team for debugging. Building: zero standing access, with every access logged.
Google will ask for read and send permission up front — that’s how Gmail works — but nothing sends without your approval, from day one. Autonomy is earned in steps as you watch it work; turn it down anytime — it never gets ahead of you.
Encrypted in transit (TLS) and at rest. Sign-in runs on Supabase; your mail lives in our own database and an encrypted vault (ciphertext only, per-account keys rolling out). Your Google tokens are stored encrypted; we never see your password.
A small, named set of providers, each under a data agreement: Google (what you connect), Anthropic (the AI), Supabase (sign-in), Railway (hosting and database), Cloudflare (encrypted vault — ciphertext only). No one else. Building: self-serve export and full deletion, a formal key-rotation schedule, and Google’s security assessment (CASA), then SOC 2.
Learning can only ever change the order — never hide something. A real, direct ask to you keeps its place no matter what any score says. So “you’ve been letting this one sit” can lower where something ranks, but it can never make it disappear. It fades things; it never buries them.
It learns who counts from what you actually do — who you write back to, how much, how recently — and quietly adjusts. Someone you keep ignoring fades; someone you always jump on rises. It never asks you to rate anyone.
A miss — us burying something you cared about — corrects hardest (that’s the 1.0). One ignored day isn’t avoidance, so it only counts after two. And if you’ve never written back to someone, they score zero and nothing lifts it — a bot stays a bot.
It learns how you write from your sent mail — and most of all from your edits: when you rewrite a draft, that’s you saying “not like that, like this.” Your recent writing counts more than old, so your voice can change and it follows.
As you send its drafts as-is versus rewrite them, it learns which kinds of message it’s ready to handle on its own — and only offers to take one over once it’s earned it. It already records your edits; the “has it earned this” step isn’t turning yet.
It will watch how people respond to what it sent — a confused or “wrong person” reply is the signal it got something wrong — flag you right away, and learn not to repeat it. Not built yet, and it’s a requirement before it ever sends anything on its own.
It will learn the natural cadence of each relationship — how often you two actually talk — so it knows when one is quietly slipping and worth a nudge. The current cadence signal is unreliable, so this is switched off until it’s rebuilt.
Over time it will learn from outcomes — did they reply, did the thread move — to get sharper about what to surface and when. The plumbing exists; it isn’t wired in yet.
None of this is a black box you can’t reach. What it learns trains only your copy — never mixed with anyone else’s, never sold — and you can see what it concluded (“I think Karen matters because you always reply fast”) and tell it when it’s wrong. Building: the screen that shows you what it’s learned and lets you correct it.
Plain English. No legalese.
The three things that matter: we don’t sell your data. We don’t train AI on it. Nothing sends without your approval. The short version of everything else is on the tab; this is the precise one, for the record.
When you connect an account, you’re giving it the email and calendar data you authorize — your messages, contacts, threads, and events. It takes what it needs to build and run your copy, and nothing beyond that.
Only to run your copy: to learn who and what matter to you, draft in your voice, surface what needs you, and — once you allow it — act for you. Never for advertising. Never to train a model that anyone else’s copy touches.
Only the handful of providers that make the product run, listed under How it works — each under a data agreement, and each only with the data they need. We don’t sell it. Full stop.
Your mail is indexed by our own search engine and stored encrypted — the vault holds ciphertext only. It is not handed to a third-party search or embedding service to be indexed — the whole pipeline that reads your mail is ours end to end. Each message is encrypted before it is stored; per-account keys are live for new mail and rolling out to the rest.
To draft in your voice or read meaning out of a thread, the relevant text is sent to the AI model that does the writing — today that is Anthropic, through our account, under a data agreement that forbids training on it. That is the only egress, and we’d rather name it than let you assume it away.
If you’d rather that never touch our account at all, you can connect your own model credentials — your own provider key or your own cloud region — and every call for your data runs inside your agreement, not ours. If those credentials ever stop working, your copy stops working; it will never quietly fall back to our account. Building: the setup screen for this — today we’ll wire it up for you.
You can rule an address, a whole domain, or a subject-line keyword — privileged, confidential, whatever you choose — permanently out of bounds. Excluded mail is never stored, never indexed, never drafted from, and adding a rule also deletes anything matching it that is already here. It reads everything you allow, and nothing you don’t. Building: the screen for managing those rules yourself.
Every action your copy takes on your data is recorded — what it read, when, and each time your text went to a model. Building: the screen that shows you that record; the record itself is being kept now.
Google requires us to spell this out: the use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. In plain terms — your Gmail and Calendar data powers only the features you see here. It is never sold, never used for advertising, never used to train AI models beyond your own copy’s personalization, and no human reads it except with your explicit consent, for security, or where the law requires.
We keep your data while your account is active. You can see it, export it, or delete it — email us and we’ll take care of it while we finish the self-serve tools — and you can cut off any connected account straight from Google. Where GDPR or CCPA apply to you, you have their full rights; we don’t carve anything out.
Deletion here means something stronger than a promise to press delete. Your stored mail is encrypted under a key that exists only for your account. When you delete, we destroy that key and then delete the files. Anything encrypted under it — including any copy that might still sit in a backup — becomes unreadable to us, permanently, because the key that opened it no longer exists anywhere. You get a written record of the moment it was destroyed. Within 30 days, every record we derived from your mail is deleted as well — the account ends whole.
Rennik, Inc. (Delaware) — the controller of your data where that term applies. privacy@ilurennik.com
Last updated August 18, 2026.
Plain English. No legalese.
Ilu Rennik is built by Rennik, Inc., a Delaware corporation — these terms are between you and us, governed by Delaware law. Ilu Rennik builds you a personal copy that helps with — and, once you allow it, acts on — your relationship and communication work. It works on your behalf, under your direction. That’s the deal.
You decide how much it’s allowed to do. Until you grant it, it doesn’t send or act on its own. Anything it does with your permission is yours — treat it as if you did it yourself. You can pull that permission anytime.
Don’t use it for anything illegal or deceptive, or that steps on someone else’s rights or breaks the rules of the accounts you connect. The accounts you connect, and the messages sent in your name, are your responsibility.
It’s early: the service is provided as-is for now, and features will change. We’ll give you fair notice before we change these terms in a way that matters. Our liability is limited to the extent the law allows.
Leave anytime: disconnect your accounts and delete — deletion destroys your encryption key, so gone means gone. We can suspend accounts that break these rules; if we ever discontinue the service, you’ll get notice and your export first.
Last updated August 18, 2026.