Last updated: September 1, 2026
Intake is an AI-powered email intake service operated by costa.ai, based in Switzerland (“costa.ai”, “we”, “us”), available at intake-app.costa.ai (the “Service”). costa.ai is the controller of the personal data described in this policy. This policy explains what personal data we process when you use the Service, why, and the choices you have. It should be read together with our Terms of Service.
We use your data to provide and secure the Service: ingesting and storing your email, extracting tasks and other structured information, showing it to you in the app, notifying you about items that need attention, handling billing, providing support, and preventing abuse. We do not sell your personal data, and we do not use the content of your emails for advertising.
The Service sends portions of your mailbox content to third-party AI model providers to generate summaries and extract structured information. These providers process the content on our behalf to deliver the Service. We do not use your content to train models, and our agreements with AI providers restrict their use of your content to providing the service to us and exclude training on your data.
If you connect a Google account, Intake’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing features described in this policy, is not transferred to third parties except as necessary to provide those features (or as required by law), and is never used for advertising.
We share personal data only with service providers that process it on our behalf under contractual confidentiality and data-protection obligations. They fall into these categories:
A current list of these subprocessors, with names, roles, and processing locations, is provided with our Data Processing Agreement — contact us at the address below to receive it.
We may also disclose data if required by law, to protect the rights and safety of our users or the public, or as part of a corporate transaction (in which case this policy will continue to apply to the transferred data).
We retain your data for as long as your account is active. If you disconnect a mailbox, we stop syncing from it. If you delete your account, or ask us to, we delete your mailbox content and derived data within a reasonable period, except for records we must keep for legal, billing, or security purposes. Backups are deleted on their normal expiry cycle.
Data is encrypted in transit, mailbox credentials and tokens are stored encrypted, and access to production systems is restricted to authorized personnel. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the competent authorities as required by law.
Under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU/EEA GDPR, you have rights to access, correct, export, restrict, or delete your personal data, to object to certain processing, and to lodge a complaint with a supervisory authority (in Switzerland, the Federal Data Protection and Information Commissioner). You can exercise these rights by contacting us at the address below; we will respond within the timeframes required by applicable law.
We are based in Switzerland, and our service providers may process data in other countries, including the United States. Where data leaves Switzerland or the EU/EEA for a country without an adequacy decision, transfers are protected by appropriate safeguards such as standard contractual clauses.
The Service is intended for business use by adults and is not directed at children under 16. We do not knowingly collect personal data from children.
We may update this policy from time to time. If we make material changes, we will notify you by email or an in-app notice before they take effect. The “Last updated” date above reflects the latest revision.
Questions or requests about your data? Contact us at luca@costa.ai.