Skip to content

Legal

Privacy Policy

Last updated: June 8, 2026

This Privacy Policy explains how 4logist AIcollects, uses, stores, shares, and protects personal data when you use our service, including data we access from your Gmail or Microsoft 365 mailbox with your permission.

1. Who we are

4logist AI is operated by Solario projektai, UAB, a company registered in Lithuania (registration code 304156786; VAT LT100010226014), with its registered office at Subačiaus g. 17-10, Vilnius, LT-01300, Lithuania (“4logist AI”, “we”, “us”). We are the data controller for your account and usage data. When you connect a mailbox and instruct us to process its emails on your behalf — including the personal data of your correspondents — we act as your data processor under Article 28 of the GDPR, on your documented instructions; a data processing agreement is available on request.

For any privacy question or to exercise your rights, contact our privacy team at privacy@4logist.ai. Our data protection contact can be reached at the same address.

2. Scope and who this applies to

This policy applies to two groups of people:

  • Operators (our users): the freight-forwarding staff who create an account, connect a mailbox, and use the dashboard.
  • Email correspondents:third parties who send freight-quote requests to a connected mailbox. Their personal data may appear in the emails we process on the operator's behalf. Where we process such data without collecting it directly, we do so under Article 14 of the GDPR; the operator is generally the controller for the content of their own mailbox and we act on their instructions.

3. Personal data we collect

  • Account & identity: your name, email address, and Google or Microsoft account identifier (from Google Sign-In / userinfo.email / openid).
  • Mailbox content: the subject, body text, headers, metadata, labels, and thread/conversation data of emails relevant to freight quoting in the mailbox you connect.
  • OAuth tokens: the access and refresh tokens that let us connect to your mailbox on your behalf (stored encrypted).
  • Workspace & usage data: workspace settings, team membership, pricing configuration, processed-run logs, and statistics.
  • Notification data: if you enable Telegram notifications, the quote summaries we send to your configured chat.
  • Technical data: IP address, device/browser information, and cookies (see our Cookie Policy).

4. Where we get your data

We collect most data directly from you when you sign up, connect a mailbox, and use the service. We also receive personal data indirectly — namely the personal data of email correspondents contained in the messages in your connected mailbox, which we process on your behalf to draft replies.

5. How and why we use your data (legal bases)

PurposeGDPR legal basis
Creating your account and authenticating youPerformance of a contract (Art. 6(1)(b))
Connecting your mailbox, reading quote emails, generating draft replies, applying labels, and sending/replying within a threadPerformance of a contract (Art. 6(1)(b))
Caching email bodies and thread data to show your conversation history in the dashboardPerformance of a contract (Art. 6(1)(b))
Processing the personal data of email correspondents inside the emails we handleLegitimate interests (Art. 6(1)(f)) — to provide the quoting feature the operator requested; we have carried out a Legitimate Interests Assessment
Securing the service, preventing abuse, and complying with lawLegitimate interests / legal obligation (Art. 6(1)(f) / (c))
Setting non-essential (e.g. analytics) cookiesYour consent (Art. 6(1)(a))

We never sell your personal data. We do not share it with data brokers, and we do not use it for advertising or to build advertising profiles.

6. How we access and use Google user data

When you connect a Gmail mailbox, we request the following Google OAuth scopes. We request the minimum access needed to provide the quoting feature:

ScopeTypeWhy we need it
https://www.googleapis.com/auth/gmail.modifyRestrictedRead incoming freight-quote emails in the connected mailbox, apply processing labels, and create or send the draft reply in the same thread.
https://www.googleapis.com/auth/userinfo.emailSensitiveIdentify which Google account was connected and link it to the correct workspace.
openid / Google Sign-InBasicLet operators sign in to the dashboard with their Google account.

The full lifecycle of Google user data in 4logist AI is:

  • Access. Using gmail.modify, we access the content of relevant emails — subjects, bodies, headers, metadata, labels, and thread data — plus your account email via userinfo.email and Google Sign-In.
  • Use. Google data is used solely to power the freight-quote feature you asked for: triaging inbound mail, extracting logistics parameters, generating a draft reply, applying processing labels, and creating or sending the reply in the same thread. It is not used for any other purpose.
  • Store. Email bodies and thread data are cached in our database (Supabase Postgres, hosted in the European Union, with per-workspace row-level isolation) so we can show your conversation history in the dashboard. OAuth refresh tokens are stored encrypted.
  • Share. To draft a reply, the relevant email content is transferred to our AI subprocessor, OpenAI, L.L.C. (United States). We otherwise share Google data only as needed to provide the feature, to protect security, to comply with law, or in connection with a merger or acquisition with your prior consent. See Section 7.
  • Retain. Cached Google data is kept only as long as necessary to provide the feature and is not retained beyond what is required. OpenAI does not train on data submitted through its API and retains it for at most 30 days for abuse monitoring (or zero days where a Zero Data Retention arrangement applies). See Section 10.
  • Delete.You can disconnect a mailbox at any time, which revokes our access and erases that mailbox's cached messages, or request full deletion of your data. See Section 12.
  • On your behalf. The agent acts on your behalf to read threads, apply labels, create drafts, and send or reply to emails.

Google API Services — Limited Use disclosure

4logist AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, 4logist AI uses Gmail data only to provide its user-facing freight-quote drafting feature; does not transfer this data except to provide or improve that user-facing feature (with the user's consent), for security, to comply with applicable law, or as part of a merger or acquisition with the user's prior consent; does not allow humans to read the data except with the user's explicit consent, where necessary for security, or to comply with applicable law; and does not use, sell, or transfer the data for serving advertisements or to create, train, or improve any generalized machine-learning or artificial-intelligence model.

In particular, 4logist AI does not use Google Workspace APIs data to develop, improve, or train generalized artificial-intelligence or machine-learning models, and does not sell Google user data, transfer it to data brokers, or use it for advertising. Humans do not read your Google data except where you give explicit consent (for example, your own operators reviewing drafts), where necessary for security, or where required by law.

Our use of information received from Google APIs is also governed by the Google API Services User Data Policy; in the event of any conflict regarding Google user data, that policy prevails.

7. Service providers and subprocessors

We use the following third-party providers to deliver the service. Each acts as our processor and is bound by appropriate data-protection terms.

ProviderPurposeLocationData involved
OpenAI, L.L.C.AI processing of email content (parsing freight parameters, drafting replies)United StatesEmail subject and body content of processed quote requests
Supabase, Inc.Managed Postgres database, authentication, and storageEuropean Union (region-pinned project)Account data, workspace data, processed email metadata and cached email bodies, OAuth refresh tokens
Railway Corp.Application hosting / computeUnited States / EU (deployment region)Data in transit during request processing; transient logs
Google LLCGmail API and Google Sign-InUnited States / globalMailbox content accessed under the granted scopes; account email
Microsoft CorporationMicrosoft 365 / Outlook mailbox integration (optional alternative to Gmail)United States / EUMailbox content accessed under granted Microsoft Graph scopes
Telegram FZ-LLCOperator notifications (optional)United Arab Emirates / globalNotification text containing quote summaries (no raw credentials)

8. International data transfers

Our primary database (Supabase) is hosted in the European Union. Some providers are located outside the European Economic Area — in particular, email content is transferred to OpenAI, L.L.C.in the United States to generate draft replies. Where personal data leaves the EEA, we rely on the European Commission's Standard Contractual Clauses(incorporated into our processors' data processing agreements) and applicable supplementary measures. You can request a copy of the relevant safeguards by emailing privacy@4logist.ai.

9. How we store and protect your data

We apply organisational and technical measures appropriate to the risk, including: encryption in transit (TLS); encrypted storage of OAuth tokens; per-workspace row-level isolation in the database; least-privilege access controls; and least-privilege OAuth scopes. No method of transmission or storage is completely secure, but we work to protect your data and to undergo periodic third-party security assessment (CASA) as required for Google-restricted-scope apps.

10. How long we keep your data

  • Cached email content & thread data: kept only as long as necessary to provide the dashboard and quoting feature; erased when you disconnect the mailbox or delete your account, and not retained beyond what is necessary.
  • OAuth tokens: kept while the mailbox is connected; deleted when you disconnect it or delete your account.
  • Account & workspace data: kept for the life of your account and deleted (or anonymised) after closure, subject to any legal retention obligations.
  • Processing logs & quote history: run metadata, the parsed parameters, and draft text we store so you can review your quoting history are kept for the life of your workspace and deleted when it is deleted. They are not used to train generalized AI models.
  • Data sent to OpenAI's API:not used to train OpenAI's models and retained by OpenAI for at most 30 days (or zero where a Zero Data Retention arrangement applies), after which it is deleted unless retention is legally required.

11. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data rectified;
  • have your data erased (“right to be forgotten”);
  • restrict or object to processing, including processing based on legitimate interests;
  • data portability;
  • withdraw consent at any time (e.g. for cookies), without affecting the lawfulness of processing before withdrawal.

To exercise any right, email privacy@4logist.aiwith “Data Subject Request” in the subject line. We will verify your identity and respond within the time limit set by law (generally one month); for access requests we provide a copy of your data in a commonly used, machine-readable format. Exercising your rights is free unless a request is manifestly unfounded or excessive.

12. Deleting your data and revoking access

You can remove your data and revoke our access to your mailbox in several ways:

  • Disconnect a mailboxin your dashboard settings. This revokes the OAuth token we hold for that mailbox, stops monitoring it, and erases that mailbox's cached messages from our database.
  • Delete your account / workspace by emailing privacy@4logist.ai. We will erase your account, workspace, cached email content, and tokens, and confirm completion.
  • Revoke at Google. You can independently revoke 4logist AI's access from your Google Account at myaccount.google.com/permissions (or, for Microsoft, in your Microsoft account settings).

13. Complaints

If you believe we have mishandled your data, please contact us first so we can help. You also have the right to lodge a complaint with your local supervisory authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija).

14. Is providing data required?

Providing account data and connecting a mailbox is necessary to use the service — without it we cannot read your quote emails or draft replies. Providing optional information (such as Telegram notifications) is voluntary.

15. Automated processing and AI

4logist AI uses AI models to triage incoming emails, extract logistics parameters, and draft a suggested reply, with pricing grounded in your historical routes. These outputs are suggestions: an operator reviews and decides on every reply before it is sent. Because a human makes the final decision, we do not make decisions producing legal or similarly significant effects based solely on automated processing within the meaning of Article 22 GDPR. You can object to our use of AI processing by contacting privacy@4logist.ai. AI outputs may contain errors and should be checked before use.

16. Cookies

We use strictly necessary cookies to run the service and, with your consent, other categories such as analytics. For details and to manage your choices, see our Cookie Policy.

17. Children

4logist AI is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

18. Changes to this policy

We may update this policy from time to time. If we intend to use Google user data in a new way or for a new purpose, we will update this policy and obtain your consent before doing so. Material changes will be communicated through the service or by email, and the “Last updated” date above will change.

19. Contact

Questions about this policy or your data? Email privacy@4logist.ai or write to Solario projektai, UAB, Subačiaus g. 17-10, Vilnius, LT-01300, Lithuania.

Looking for something else? Read our Privacy Policy, Terms of Service, or Cookie Policy.