Trust

What it can do, and what you control.

A copy of you reads your mail and can act in your voice. Here’s exactly how that works, what you decide, and how your data is handled — in plain terms.

The honest worry with a copy of you is simple: will it do something you’d be mortified by? Here’s exactly what it can and can’t do — today, not someday.

Right now, it can’t send anything

It reads and drafts — that’s the whole of it today

It reads your mail and writes drafts in your voice. It cannot send a single message on its own. Nothing goes out in your name until you turn sending on yourself — one lane at a time — and you can switch it back off in a tap.

When it’s not sure, it stops

It would rather hold than guess

If it can’t see the whole picture — a message it couldn’t read, an ask it can’t pin down — it flags it and waits for you. It won’t send something wrong in your name to paper over a gap.

If it slips, you can catch it

You see it before it sends

You see every draft before it goes out — nothing is sent blind. Building: once you grant a lane, a full record of everything it does, each action undoable.

If something goes wrong, you hear it first

Building: it watches how people respond to what it sent — the moment a reply reads as off (a confused answer, a wrong turn), it raises a flag to you right away, before it becomes a problem.

Pause or pull the plug, instantly

Pause the whole thing in one tap. Revoke its access from your Google account whenever you want — you don’t have to ask us.

Your data stays yours

It only ever trains your copy

What it learns about you trains only your copy — never pooled into a model shared with other users. Anthropic, the AI behind it, doesn’t train on your data either.

You pay for it, so you’re not the product

We charge for the product. We don’t sell your data and we don’t run ads.

People don’t browse your mail

The system processes your mail; people don’t read through it. Access is least-privilege and limited to a small team for debugging. Building: zero standing access, with every access logged.

You hold the dial

It starts at zero and earns the rest

It starts read-only and earns each step up as you watch it work. Turn it up when it’s earned your trust; turn it down anytime — it never gets ahead of you.

The technical bits

Encryption

Encrypted in transit (TLS) and at rest (via our database provider, Supabase, on AWS). Your Google tokens are stored encrypted; we never see your password.

Who touches your data

A small, named set of providers, each under a data agreement: Google (what you connect), Anthropic (the AI), Supabase / AWS (database), Railway (hosting). No one else. Building: self-serve export and full deletion, a formal key-rotation schedule, and Google’s security assessment (CASA), then SOC 2.

Most of what makes this useful, it learns — from what you do, not a form you fill out. Here’s exactly how, loop by loop, math and all. Two run today; the rest are how it’s built to grow. It only ever learns your copy — never pooled with other people, never sold — and you can see what it concluded and correct it.

The one rule over everything

Learning can only ever change the order — never hide something. A real, direct ask to you keeps its place no matter what any score says. So “you’ve been letting this one sit” can lower where something ranks, but it can never make it disappear. It fades things; it never buries them.

1 · Who matters to you running

It learns who counts from what you actually do — who you write back to, how much, how recently — and quietly adjusts. Someone you keep ignoring fades; someone you always jump on rises. It never asks you to rate anyone.

score(person) = 0.60·reciprocity + 0.20·volume + 0.20·recency + 0.25·(learned) reciprocity how much you write back (levels off ~20 sent) recency 0.5 ^ (days since last / 60) learned, updated each pass: raw = 0.5·(you acted) + 1.0·(we buried it) − 0.12·(days ignored, after 2) new = halfway from old toward raw — a prior, not a reflex

A miss — us burying something you cared about — corrects hardest (that’s the 1.0). One ignored day isn’t avoidance, so it only counts after two. And if you’ve never written back to someone, they score zero and nothing lifts it — a bot stays a bot.

2 · Your voice running

It learns how you write from your sent mail — and most of all from your edits: when you rewrite a draft, that’s you saying “not like that, like this.” Your recent writing counts more than old, so your voice can change and it follows.

each of your writing samples: score = signal + 0.9·recency signal 1.0 if it's a rewrite/tone edit you made, 0.4 if a plain sent email recency 0.5 ^ (days old / 180) the top 4 examples shape each draft

3 · What it’s trusted to handle building

As you send its drafts as-is versus rewrite them, it learns which kinds of message it’s ready to handle on its own — and only offers to take one over once it’s earned it. It already records your edits; the “has it earned this” step isn’t turning yet.

4 · Catching its own mistakes building

It will watch how people respond to what it sent — a confused or “wrong person” reply is the signal it got something wrong — flag you right away, and learn not to repeat it. Not built yet, and it’s a requirement before it ever sends anything on its own.

5 · Your rhythm with people building

It will learn the natural cadence of each relationship — how often you two actually talk — so it knows when one is quietly slipping and worth a nudge. The current cadence signal is unreliable, so this is switched off until it’s rebuilt.

6 · What actually worked building

Over time it will learn from outcomes — did they reply, did the thread move — to get sharper about what to surface and when. The plumbing exists; it isn’t wired in yet.

Yours, and correctable

None of this is a black box you can’t reach. What it learns trains only your copy — never mixed with anyone else’s, never sold — and you can see what it concluded (“I think Karen matters because you always reply fast”) and tell it when it’s wrong. Building: the screen that shows you what it’s learned and lets you correct it.

The short version is on the tab. This is the precise one, for the record.

What it can see

When you connect an account, you’re giving it the email and calendar data you authorize — your messages, contacts, threads, and events. It takes what it needs to build and run your copy, and nothing beyond that.

What we do with it

Only to run your copy: to learn who and what matter to you, draft in your voice, surface what needs you, and — once you allow it — act for you. Never for advertising. Never to train a model that anyone else’s copy touches.

Who else touches it

Only the handful of providers that make the product run, listed under How it works — each under a data agreement, and each only with the data they need. We don’t sell it. Full stop.

Google data, specifically

Google requires us to spell this out: our use of information from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. In plain terms — we use it only to run your copy, never for advertising, and we never hand it off except where you direct it or the law requires.

Getting your data out, or gone

We keep your data while your account is active. You can see it, export it, or delete it — email us and we’ll take care of it while we finish the self-serve tools — and you can cut off any connected account straight from Google. Where GDPR or CCPA apply to you, you have their full rights; we don’t carve anything out.

Contact

privacy@ilurennik.com

What this is

Ilu Rennik builds you a personal copy that helps with — and, once you allow it, acts on — your relationship and communication work. It works on your behalf, under your direction. That’s the deal.

You’re in charge, and on the hook

You decide how much it’s allowed to do. Until you grant it, it doesn’t send or act on its own. Anything it does with your permission is yours — treat it as if you did it yourself. You can pull that permission anytime.

Don’t use it for anything shady

Don’t use it for anything illegal or deceptive, or that steps on someone else’s rights or breaks the rules of the accounts you connect. The accounts you connect, and the messages sent in your name, are your responsibility.

The part the lawyers need

It’s early: the service is provided as-is for now, and features will change. We’ll give you fair notice before we change these terms in a way that matters. Our liability is limited to the extent the law allows.

Contact

legal@ilurennik.com