Skip to content
← Guides

Is an AI email client safe for client data?

Part of AI email clients

On this page

It can be, but AI is not what makes it safe or unsafe. What decides it is how much the tool does on its own, whether you can see and correct what it did, and whether the vendor will tell you in writing where your data goes and who else touches it. Judge a product on those.

  • The duty stays with you. No vendor takes it off you, and their contract almost certainly caps what they owe you if it goes wrong.
  • The questions worth asking are about data handling, not about AI: training, storage, retention, access, the other companies in the chain, and which country it all sits in.
  • Some inboxes should not be connected to any AI tool on standard terms. Tax return information is the clearest case, and it is usually carved out in the vendor’s own contract.

Does the duty transfer to the vendor?

No. Buying a tool moves the work, not the responsibility, and the rest of this page hangs off that. Writing for US practitioners in April 2026, The Tax Adviser put it in a line: “The CPA firm can outsource a task or function, but its responsibility cannot be outsourced.”

In the United States, three things stack on a small accounting or tax practice. The AICPA’s Confidential Client Information Rule (ET §1.700.001) sits behind the profession’s confidentiality obligations, and putting client information into a third-party tool is a disclosure rather than an internal filing decision.

If you prepare federal returns it is also criminal law. Under 26 U.S.C. §7216, a preparer who knowingly or recklessly discloses return information, or uses it for anything other than preparing the return, “shall be guilty of a misdemeanor, and, upon conviction thereof, shall be fined not more than $1,000 … or imprisoned not more than 1 year, or both.”

And the FTC Safeguards Rule (16 CFR Part 314) requires a “comprehensive information security program that is written in one or more readily accessible parts.” Tax preparers are squarely inside it, because the rule’s own examples state that “an accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution.” Nor does being small get you out of the written program: firms holding information on fewer than five thousand consumers are exempt from four specific requirements, and that is not one of them.

If you practice elsewhere that is not your rule book, but the problem is the same, so look up your own institute’s confidentiality rule and what your data protection law says about processors.

Then the part vendors rarely volunteer. Every software contract caps what the vendor owes you if they lose your clients’ data, and Point’s own terms cap it at the greater of twelve months of fees or US $100, with carve-outs for fraud, willful misconduct and gross negligence. That is an ordinary cap rather than a mean one, which is why it is worth reading: whatever a security page says, the contract has already decided that the consequences of a breach are mostly yours.

None of this forbids good software. Plenty of firms use cloud tools daily and meet these duties. It means the vendor has to earn a place inside your obligation, and one that is vague about control or data handling has not earned it, however clever it is.

What are the real risks?

Four, and the last two are the ones that get left out.

The first is where your data goes. Connecting your email to any tool means that tool can read your mail. What matters is what happens next: whether it is stored, how long, who can see it, and whether it trains models. Some vendors are clear about this and some are not, and the difference matters more than any feature.

The second is a breach at the vendor. Anything you connect to becomes part of your security surface. A serious vendor guards your credentials and your mail closely; a careless one is a liability no matter how good the product looks.

The third gets underweighted because it is specific to AI email rather than to software generally: the tool acts on your behalf, and it can get it wrong. These systems are probabilistic and will be wrong some of the time, and a wrong action that reaches a client is a confidentiality problem of its own: the reply that quotes one client’s numbers to another. The mitigation is not a promise of accuracy, which nobody can honestly give. It is how much you let it do unsupervised, and how much of that you can see and reverse.

The fourth is left out of the calculation entirely: email is already the way most attacks arrive, whether or not you buy anything. In Verizon’s 2024 Data Breach Investigations Report, drawn from incidents worldwide, “the human element was a component of 68% of breaches,” and the report puts “the median time for users to fall for phishing emails” at less than 60 seconds. An AI client adds a twist, because mail can be written to manipulate whatever reads it rather than the person. So the honest question is not only whether a tool adds exposure, but what it does about the exposure your inbox already carries.

Is this the same as pasting client data into a chatbot?

Most of the fear here comes from one picture: someone copying a client’s numbers into a public chatbot, where the input may be retained and used to train a model. That fear is well founded. A general-purpose AI tool is not built to hold confidential work.

An AI email client is a different arrangement, but be clear about what has actually changed, because it is the contract rather than the absence of a third party. The AI in an AI email client is usually not the vendor’s own model; your mail, or excerpts of it, goes to a model provider under the vendor’s commercial terms. That is materially better than a consumer chatbot. It is not the same as your mail never leaving the building, and it makes the questions the same ones, asked of a proper vendor and answerable in writing.

What should you ask before you connect an account?

There is a separate list for working out whether a product’s triage is real rather than a relabeled filter, and stop triaging email by hand has it. This is the other list, the data one. Send it as an email, because the answer you want is one you can keep.

  • Do you train on my mail, and whose models are they? “We do not train on your data” can mean several things. Ask whether it covers the vendor’s own models, the third-party models underneath, and whether improving the service is carved out. A precise answer is a better sign than a sweeping one.
  • Which other companies process my mail? Hosting, AI providers, mail delivery, support tooling. A vendor with a published subprocessor list has already answered; one who has to go and find out has not thought about it.
  • Where is it stored, in which country, for how long, and who at your company can read it? The last is the one people forget. Support access, abuse investigation and troubleshooting are normal reasons for a human to see your mail, so ask for the list of reasons rather than a claim that it never happens.
  • What is encrypted, and where is it not? “Bank-level encryption” is marketing. “In transit and at rest where supported” is an answer, and the follow-up is which parts are not supported.
  • How much can it do without asking, and what can it not take back? The second half matters more. Most tools let you set how far it goes; far fewer say plainly which actions are one-way.
  • Are the businesses I run kept apart? And ask what that boundary is not: separating two businesses you operate is a different thing from separating two clients inside one of them.
  • What happens to my data if I stop paying? Deletion or return, on what timescale, and what stays in backups until overwritten. Ask in week one, while you still have their attention.
  • Will you sign something for regulated data? If your mailbox carries data your own rules ring-fence, the standard terms probably exclude it. Ask it early, before you get attached to the product.

Treat a vague answer as an answer. And keep one thing in proportion: even a clear no on training is a policy commitment, not a physical property of the system. It is a real promise, worth weighing against how the vendor stores and separates data, and whether it goes in the contract rather than on a web page.

Does an AI email client make you safer, or riskier?

Both are possible, and the deciding factor is the vendor’s design, not the presence of AI.

Handled badly (a tool that trains on your mail, stores it carelessly, or acts without oversight) an AI email client raises your exposure, and no feature makes up for that. Handled well, it can genuinely lower your risk. A client that holds suspicious mail back before it reaches you is working against the most common attack path there is. One that keeps a plain log of everything done on your behalf, and lets you reverse most of it, gives you an audit trail your old inbox never had, the kind of record a written security program is supposed to produce. And by making sure the message that needed you does not get buried, it reduces the quiet, everyday risk of the missed email: the deadline or the request that slipped, which for a small firm is its own kind of harm.

Safety here is not a badge a product wears. It is whether the product hands you control, shows its work, and is straight with you about your data.

Who should not connect their inbox?

Some firms should not buy this category yet, or not on standard terms, and it is better to know now.

If your mailbox routinely carries data your own rules ring-fence. Most vendors keep regulated data out of the standard service unless they have expressly agreed to handle it, and that holds for tools built for professionals as much as for anything else. Read the terms for the carve-out, and if it covers what lands in your inbox, ask what the vendor will sign before you connect rather than after.

If you cannot get the answers in writing. A vendor who will not put storage, retention, training and subprocessors in a document is asking you to carry a duty on their behalf without terms.

If your engagement letters do not cover it. Where your obligations require client consent to disclose their information to a third party, the consent comes first.

If you want software that does not need checking. These systems are probabilistic and will be wrong sometimes, and no serious vendor’s terms say otherwise. If the plan is to hand over the inbox and stop looking, the category cannot give you that safely.

Where does Point fit?

Point is an AI email client, so every question above can be put to it. The answers as they stand:

  • How much it does on its own is a dial you set, one kind of action at a time, from staying out of it, through preparing and waiting for your approval, to handling it. Out of the box everything sits on review. Raise a kind of work to the top and Point does it alone rather than checking in, which is the point of raising it: it will run a scheduling back-and-forth end to end if you let it.
  • Everything it does is written down in plain language, and most of it can be reversed in a click. What cannot be reversed is a message that has already left, and Point’s terms say so rather than glossing it.
  • Each business you run is sealed off from every other, which is a boundary between businesses you operate, not between the clients inside one of them. Your clients’ mail sits together in your practice’s account, exactly as it does today.
  • Hostile mail is held at the door, unread and unprocessed, in a quarantine you release from. And a thread that has to stay between two people can be locked end to end, so not even Point can read it: a channel rather than a blanket, because a locked message gets no summary, no ranking and no task pulled out of it.

On the data questions, the terms say Point will not use your content to train generalised third-party models unless you authorize it, and that it may process your content to provide, secure, support and improve the service for you. The other companies involved are named rather than described, in subprocessors: AWS for hosting, Anthropic and OpenAI for the AI processing, Google for text embeddings and mobile push, Resend for transactional mail, Stripe for billing, Cloudflare for this website, with the AI providers under business terms carrying no-training controls where those exist.

Data sits in the United States and wherever those providers operate, which for a UK or EU firm is an international transfer the privacy policy sets out a mechanism for. Encryption is in transit and at rest where supported, and the terms decline to promise absolute security, as every honest vendor’s contract does. The regulated-data carve-out in the section above is Point’s own, so read that first.

Common questions

Is using an AI email client like pasting client data into ChatGPT?

No, though the underlying question is the same. A public chatbot is a general-purpose tool that may retain and train on what you paste. An AI email client is a service you connect under a specific agreement, built for confidential mail. That is a better arrangement, not an exemption from the same checks: training, storage, access, and whether the vendor will answer in writing.

Will it train AI on my clients’ data?

That depends on the product, and it is the most important question to ask. A useful answer is specific about whose models and about what counts as improving the service, so treat an absent one as a red flag. Point’s position is in its terms: it will not use your content to train generalised third-party models unless you authorize it, and it may process your content to provide and improve the service for you.

Which other companies can see my mail?

More than one, in any AI email product, and a vendor should be able to name them. The work is usually spread across a hosting provider, one or more AI model providers, and smaller services for things like mail delivery and billing. Ask for the list rather than a reassurance. Point publishes its subprocessors, including the AI providers.

Can I really undo everything it does?

No, and be wary of any product that says otherwise. A good client logs every action and lets you reverse most of them, so a thread it filed or a draft it prepared comes straight back. But no software recalls a sent message from someone else’s server. That is why the autonomy setting on replies deserves more thought than the one on filing.

Does using an AI email client breach client confidentiality?

Not by itself, but the duty stays with you. Handing client data to an outside supplier counts as disclosing it, so the job is to choose a vendor whose data practices fit your obligations and, where those obligations require it (as under US federal law for tax return information), to obtain the client’s consent. Many firms build that consent into their engagement terms.

If you prepare US federal tax returns, quite possibly both. The FTC Safeguards Rule requires a comprehensive, written information security program and treats tax preparers as financial institutions, and 26 U.S.C. §7216 makes it a misdemeanour to disclose or use return information beyond preparing the return without consent. The specifics are for your own judgment and adviser, but most firms document their safeguards and build consent into their engagement terms.

The short version

  • Safety is not about whether a tool uses AI. It is about control, transparency, and a straight written answer on where your data goes, who else touches it, and whether it trains anything.
  • The duty stays with you, and so does most of the cost of a breach, because the vendor’s contract caps their liability. In the US that duty is ethical and, for tax preparers, legal.
  • Done well an AI email client can lower your risk; done badly it raises it. The questions above are how you tell before you connect rather than after.
  • If your mailbox carries regulated data, check the vendor’s terms for the carve-out first. It is usually there, and usually unread.

For the bigger picture, start with what an AI email client is and how it differs from an AI email assistant. If you run a firm, see AI email for accountants, and how to switch for what the first week involves. Read Point’s privacy policy, terms and subprocessors for the specifics, or everything Point does. The calm version of all this is the idea behind Point.

The duty weighs heaviest where the correspondence is itself the record, which is the case made on the page for law practices, and it shapes the account written for accountants and tax firms too.

Join the private beta

We're onboarding a few teams at a time. Leave your email, confirm it once, and we'll send an invitation the moment a place opens.