ASUP reads the message you are writing, in the moment you are writing it, so it can flag risk and suggest better wording before you hit send. That only works if you can see exactly what we look at, what leaves your device, and what we never do with it. This policy sets that out in plain terms.
Section 01Who we are
The ASUP extension and services are provided by ASUP Communications Inc., a Delaware corporation, together with its Israeli affiliate that carries out research and development ("ASUP", "we", "us").
For the purposes of the EU and UK General Data Protection Regulation and Israel's Privacy Protection Law, ASUP Communications Inc. is the controller of the personal data described in this policy, except where we act as a processor on behalf of an organisation that has deployed ASUP for its staff (see Section 15).
| Registered office | Delaware, United States |
| R&D office | Jerusalem, Israel |
| Privacy contact | admin@asupme.com |
Section 02What ASUP does, and when it runs
ASUP is a communication assistant and oversight layer. It installs into the interfaces you already use — Gmail, Outlook on the web, Microsoft Outlook desktop (as an add-in), and WhatsApp Web — and works in two ways:
- While you write. When you have a compose window open, ASUP analyses the draft text and highlights wording that may create risk, confusion, or a compliance problem, and offers alternatives.
- Before you send. When you click send, ASUP can hold the message for a moment and show you what it found, so you can revise, confirm, or cancel.
ASUP runs on a message when there is an open compose window on a supported platform, or when you explicitly ask it to check something. It does not walk through your mailbox, index your history, or read conversations you have not opened for composing.
Analysis takes place on ASUP servers and, for language understanding, at the AI providers listed in Section 8. ASUP does not currently perform its analysis entirely on your device. In-tenant and on-device deployment options are on our roadmap and are not part of the service today.
Section 03Information we collect
a. Message content
The text of the message you are composing, or that you ask ASUP to check, including the subject line, recipients' display names or handles where visible, and the thread context shown in the compose view where that context is needed to understand your draft.
b. Attachments
Where you attach a file to a message being checked, and attachment analysis is enabled for your account, we process the contents of that file to identify sensitive material or extract the information you asked for.
c. Detected sensitive identifiers
Before your draft leaves your browser, ASUP attempts to detect personal identifiers — such as identity numbers, payment card numbers, phone numbers and email addresses — and replace them with neutral placeholders. The original values are held in your browser only, so that the analysis can be mapped back onto your text locally. This masking is a best-effort protection, not a guarantee. Pattern detection cannot catch every identifier in every language and format, and you should not treat it as a substitute for your own judgement about what you write.
d. Account information
Your name, email address, organisation, role where you provide it, authentication identifiers, and your settings and preferences.
e. Analysis records
A record of checks performed — timestamps, platform, risk categories detected, whether you accepted or dismissed a suggestion, and processing duration — used for your own history, for billing where applicable, and to improve accuracy.
f. Technical and diagnostic data
Extension version, browser type and version, operating system, IP address, and error traces.
g. Communications with us
Support requests, feedback, and correspondence.
Section 04What we do not collect or do
- We do not read, download or index your mailbox, your archived mail, or your chat history.
- We do not collect your passwords, authentication cookies or session tokens for Google, Microsoft, Meta or any other platform.
- We do not monitor your browsing outside the supported platforms listed in Section 6. The extension has no access to other sites.
- We do not sell, rent, trade or broker personal information, and we have never done so.
- We do not use your data for advertising, ad targeting or ad measurement.
- We do not use your data to assess creditworthiness or for lending purposes.
- We do not use your message content to train, fine-tune or improve AI models — ours or those of any third party.
Section 05Chrome Web Store Limited Use disclosure
Our use of information received from Google APIs and through the ASUP Chrome extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:
- We use the data only to provide and improve the user-facing features that are prominently described in the extension's store listing — real-time analysis of the message you are composing, risk flagging, and wording suggestions.
- We do not transfer the data to third parties except as necessary to provide those features (the service providers in Section 8), to comply with applicable law, or as part of a merger or acquisition subject to the notice in Section 12.
- We do not use or transfer the data for serving advertisements, including retargeting or interest-based advertising.
- We do not use or transfer the data to determine creditworthiness or for lending purposes.
- We do not allow humans to read the data, unless: we have your affirmative consent for a specific message; it is necessary for security purposes such as investigating abuse; it is necessary to comply with applicable law; or the data has been aggregated and de-identified so that it is no longer linked to an individual user.
- We do not use the data to train generalised or foundation AI models.
Section 06Permissions we request, and why
| Permission | Why it is needed |
|---|---|
| Access to mail.google.com | To read the draft in the Gmail compose window, highlight findings inside it, and hold the send action until you have seen them. |
| Access to outlook.office.com and outlook.live.com | The same functions in Outlook on the web. |
| Access to web.whatsapp.com | The same functions in the WhatsApp Web message box. |
| storage | To keep your settings, your session, and locally held masking values in your browser. |
| scripting | To place the ASUP interface inside the compose window on those pages. |
| alarms | To refresh your session and clear expired local data on a schedule. |
The extension has no access to any other website. It does not request tab history, downloads, bookmarks, geolocation, camera or microphone.
Section 07How we use information, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Analysing your draft and returning findings | Performance of a contract with you, or your consent |
| Maintaining your account and settings | Performance of a contract |
| Security, abuse prevention, and service integrity | Legitimate interests |
| Diagnosing faults and improving accuracy using aggregated or de-identified data | Legitimate interests |
| Billing and financial records | Contract and legal obligation |
| Responding to legal requests | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interest in operating a secure and accurate service does not override your rights, and we use aggregated or de-identified data wherever it is sufficient for the purpose.
Section 08Service providers who process data for us
We use a small number of providers, each under a written agreement that limits them to processing on our instructions:
| Provider | Role | Location |
|---|---|---|
| Anthropic | AI language analysis of message content | United States |
| Google (Gemini API) | AI language analysis of message content | United States / EU |
| Supabase | Database and authentication | European Union |
| Render | Application hosting | United States / EU |
On AI providers and model training. We access these models through their commercial APIs, under terms that prohibit them from using our inputs or outputs to train their models. Providers may retain content for a limited period for abuse and safety monitoring in accordance with their own published terms; we do not authorise any other use. We do not send your content to consumer AI products or free-tier services.
The current list of sub-processors is available on request, and organisational customers receive advance notice of changes under their agreement with us.
Section 09Where data is stored
Account data, settings and analysis records are stored in a Postgres database hosted in the European Union. Message content is processed in transit and is not written to our database as a matter of course; where a record is retained — for example, where you save a check to your history, or where an organisational customer has enabled an audit log — that is stated in your settings or in your organisation's agreement.
Section 10How long we keep information
| Category | Retention |
|---|---|
| Message content sent for analysis | Held only for the duration of processing and deleted immediately afterwards, unless you have saved it or your organisation has enabled retention |
| Attachments | Same as message content |
| Analysis records (metadata, no content) | 12 months |
| Account data | For as long as your account is active, then deleted within 30 days of closure |
| Diagnostic and error logs | 30 days |
| Billing and tax records | As required by law, typically seven years |
Section 11Security
- All traffic between the extension, our servers and our providers is encrypted in transit using TLS 1.2 or higher.
- Stored data is encrypted at rest.
- Personal identifiers detected in your draft are replaced with placeholders in your browser before transmission, as described in Section 3(c).
- Access to production systems is restricted to named personnel, requires multi-factor authentication, and is logged.
- We follow secure development practices including code review, dependency scanning and least-privilege service accounts.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant supervisory authority within the timeframes required by law.
Section 12When we share information
We share personal data only:
- with the service providers in Section 8, on our instructions;
- with your organisation, where ASUP has been deployed to you as part of an organisational account, and only as described in Section 15;
- with professional advisers under a duty of confidentiality;
- where required by law, court order or a binding request from a public authority, after we have assessed whether the request is valid and, where legally permitted, notified you;
- in connection with a merger, acquisition or sale of assets, in which case we will give notice before your data becomes subject to a different privacy policy.
Section 13International transfers
We operate from the United States and Israel and use providers in the United States and the European Union, so your data may be transferred across borders. Where data is transferred out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, including the European Commission's adequacy decision covering Israel. Copies of the relevant transfer mechanisms are available on request.
Section 14Your rights
Depending on where you live, you have some or all of the following rights: to access the personal data we hold about you; to correct it; to delete it; to restrict or object to its processing; to receive it in a portable format; to withdraw consent at any time without affecting processing already carried out; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
ASUP's analysis is advisory. It flags and suggests; it does not make decisions about you, and you remain free to send your message unchanged.
To exercise any right, write to privacy@asupme.com. We respond within 30 days. If you are in the EEA or UK you may complain to your local supervisory authority; if you are in Israel you may contact the Privacy Protection Authority.
If you are a California resident: we do not sell or share personal information as those terms are defined under the CCPA, and we do not discriminate against you for exercising your rights.
Section 15Where your organisation deployed ASUP
If you received ASUP through your employer, school or another organisation, that organisation decides how ASUP is configured and is the controller of the data processed through it. We act as its processor under a written data processing agreement. In that case:
- your organisation's own privacy notice governs how it uses the results;
- your organisation may be able to see aggregate usage, policy settings, and — where it has enabled an audit log — records of flagged messages;
- requests to access or delete your data should be directed to your organisation first, and we will support it in responding.
We do not use organisational customers' content for any purpose other than delivering the service to that organisation, and our agreements prohibit us from using it to train models.
Section 16Children
ASUP is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Section 17The asupme.com website
Our website uses only the cookies necessary to serve the site and, where you have consented, basic analytics to count visits. It does not use advertising cookies or third-party trackers for marketing. If you contact us through the site, we use your details to respond and to keep a record of the correspondence.
Section 18Changes to this policy
We update this policy when the service changes. The effective date at the top always reflects the current version. For material changes — a new category of data, a new purpose, or a new class of recipient — we will notify you in the extension or by email before the change takes effect.
Section 19Contact us
Privacy questions and rights requests: admin@asupme.com
General: daniel@asupme.com
Post: ASUP Communications Inc., 838 Walker Road, Suite 21-2, Dover, DE 19904, US
A Hebrew translation of this policy is available at asupme.com/docs/he/privacy. It is provided for convenience; this English version governs.