Who owns emails sent to a company, including customer messages?
A company owns its mailbox, but copyright in an inbound email usually belongs to the sender or the sender's employer. The company can generally license what its own employees wrote, while customer and partner messages need contract review, de-identification or exclusion before any AI data license, as SourceX scopes with the company.
Who owns an email a company received?
Possession and authorship are different things. A company owns the mailbox, the servers and the physical copy of every message it received, but the copyright in the words of an inbound email usually sits with whoever wrote it, or with that writer's employer. Owning the archive does not automatically mean owning the right to license every message in it.
That distinction decides what a company can put into an AI data license. Messages its own employees wrote in the course of their jobs are generally the company's to license. Messages from customers, vendors, candidates and contractors are a mixed picture that needs sorting before anything is scoped. This is general information, not legal, tax or financial advice.
What does copyright law say about authorship?
Copyright vests first in the author. Under 17 U.S.C. 201, a work made for hire belongs to the employer, and an owner can transfer or license individual rights separately from the rest. The Copyright Office's Circular 30 on works made for hire explains that a work prepared by an employee within the scope of employment is a work made for hire, while work from an outside contractor counts only in listed categories and only with a signed written agreement.
Two practical consequences follow for an inbox:
- An email a customer's employee wrote to your account manager is, in the ordinary case, authored for the customer's employer, not for you.
- An email from a freelancer or agency may belong to that individual or firm unless a written assignment says otherwise.
Whether a recipient may use a received message for particular purposes, and what an implied permission covers, is a legal question that turns on facts and jurisdiction. Treat it as something for counsel to answer, not something a partner or an owner should assume.
Which messages in a company mailbox are safest to license?
Sort the archive by who wrote each message and what obligations travel with it.
| Message type | Who likely holds the copyright | What to check |
|---|---|---|
| Written by the company's own employees in their jobs | The company, as employer | Employment terms and any personal-use carve-outs |
| Written by customer or client staff | The customer or its employer | Master services agreement, confidentiality clauses, privacy policy promises |
| Written by freelancers, agencies or contractors | The individual or firm, unless assigned in writing | Contractor agreements and assignment language |
| Exchanged under an NDA with a vendor or deal counterparty | The writer's side, plus a contractual confidentiality duty | NDA scope, survival period, residual-information terms |
| Attachments created by third parties (reports, contracts, decks) | The third party | Source of each attachment and any license terms printed on it |
| Automated notices and system alerts | Depends on how the notice was generated; often low-value for buyers | Whether they add anything beyond metadata |
| Personal messages in a work mailbox | The individual writers | Exclusion rules agreed before work begins |
Ownership is only one layer. Even when a company clearly owns the text, privacy rules and contractual confidentiality may still limit use. The question of whether message content counts as sensitive personal information is covered in emails and Slack messages under the CPRA.
How do data licenses handle other people's messages?
A well-scoped license does not try to claim rights the company does not hold. It narrows the delivery to what the company can stand behind. SourceX agrees de-identification and redaction requirements with the company before any work begins, and data is delivered only after an executed agreement and the company's authorization.
A typical scoping sequence for a mailbox looks like this:
- Group the mailbox by sender domain and by internal versus external correspondence.
- List the contracts and NDAs that bind the company to specific counterparties, and mark any counterparty whose messages must stay out.
- Decide which classes of external correspondence to exclude entirely, such as legal counsel, regulators, HR matters and anything under privilege.
- Agree what is removed from the messages that stay in: names, signatures, phone numbers, account identifiers and attachments.
- Have the company's own counsel review the remaining scope before the owner signs.
The company keeps ownership throughout; data is licensed, not sold, and nothing is binding until the company agrees price and terms and signs. If a company is unsure about sensitivity in general, the objection answer on data that feels too sensitive to license gives the owner's side of this discussion.
What does this mean for a referral partner?
Partners make introductions and give basic fit information. They never export, upload or describe confidential records, and they should not offer an opinion on who owns any particular email. Your job is to raise the right question early so the owner brings counsel in.
A useful way to open the topic is the three-source test. Ask the owner which part of the archive was written inside the company, which part arrived from customers or partners, and which part sits under a written confidentiality promise. If the first bucket is large and the other two can be set aside, the company is much easier to scope.
Registered professionals such as CPAs, lawyers and brokers should check their own rules on referral fees and disclosure before registering. For a broader screen that covers rights, history and reach, use the company fit checker, then read how the introduction process works.
When should the company pause?
Stop and take advice first when any of these apply:
- The mailbox is mostly correspondence with consumers rather than businesses.
- A large share of the traffic is with one customer who has strong confidentiality terms.
- The messages include legal advice, health information or financial account details.
- Former employees or contractors wrote much of the content and nobody has their agreements.
The related question of how the finance sector treats business customer data is covered in whether GLBA covers business customers.
Next step
Ask one owner which part of the archive their own people wrote. If it is substantial and the company has 50+ full-time employees at peak (contractors excluded), register as a partner and make the introduction. Confirm any ownership question with the company's own counsel before acting.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can a company share emails it received from customers?
Not automatically. The company holds the messages, but copyright in the text normally belongs to the writer or the writer's employer, and contracts or privacy promises may add limits. A license usually removes or de-identifies customer messages, or excludes certain counterparties, and the company's counsel reviews the scope first.
Are emails written by my employees mine to license?
Generally the company is the owner of work its employees prepare within the scope of their jobs, under the work-made-for-hire rule. Exceptions include personal messages, content from contractors without a written assignment, and anything restricted by privacy or confidentiality terms. Counsel should confirm the position for your own archive.
Does an NDA change who owns an email?
An NDA does not usually transfer copyright, but it can restrict what the recipient may do with the content. Messages exchanged under an NDA often need to be excluded from a data license unless the NDA allows the use. Check the scope and survival terms with counsel.
Does deleting names make a customer email safe to license?
Not always. Removing names helps, but signatures, account numbers, quoted text and context can still identify a person or a company, and copyright and confidentiality are unaffected by de-identification. That is why scope, exclusions and contract review sit alongside redaction rules.
Do referral partners need to verify email ownership?
No. A partner introduces the company and shares basic fit information only. Rights review, redaction rules and contracting are handled between the company and SourceX, with the company's own counsel involved. Partners should never ask for or handle confidential records.
Related pages
Free resources
- Working capital calculator — Net working capital, current ratio and quick ratio.
- Due diligence checklist generator — A tailored document request list by deal type.
- Cash flow calculator — A 12-month cash forecast with shortfalls highlighted.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment