Legal
AI Data Privacy & Model Ethics Statement
Detailed breakdown of AI processing via AWS Bedrock, our absolute Zero Model-Training commitment, and ephemeral data handling policies.
Summary for UI display (AI Composer Toolbar): InboxDays AI operates via AWS Bedrock. Your email content, prompts, and generated drafts are processed in ephemeral server memory and never used to train public or commercial AI models.
1. AI infrastructure & model partners
InboxDays provides intelligent drafting, inline autocompletion, and thread summarization through secure API integration with Amazon Bedrock. Depending on your active account tier, features may utilize:
- Amazon Nova Micro: Low-latency inline autocompletion and structural editing.
- Anthropic Claude 3.5 Sonnet: Advanced context drafting, tone adjustments, and thread reasoning.
- Amazon Titan Text Embeddings V2: Semantic vector generation for natural language search.
Material provider changes are also reflected in the Subprocessor Directory.
2. The Zero Model-Training Guarantee
Your data belongs to you. InboxDays maintains strict legal and technical contractual agreements with our AI infrastructure providers (Amazon Web Services and Anthropic):
- NO public model training: Your emails, prompt inputs, context snippets, and generated completions are NEVER used to train, retrain, evaluate, or fine-tune public, commercial, or foundational AI models.
- NO third-party sharing: Your content is never shared with external advertisers, data brokers, or unauthorized third parties.
- NO persistent storage: Prompts and context vectors passed to AWS Bedrock are not saved to persistent storage on AI provider servers.
3. Ephemeral processing lifecycle
When you trigger an AI action (e.g., Draft Reply or Summarize Thread), your request follows a strictly ephemeral data lifecycle:
- Client request initiated (in-app action)
- TLS 1.3 encrypted transit → AWS Bedrock isolated runtime
- In-memory inference execution (no disk write)
- Streaming tokens returned to client → memory flushed immediately
- In-transit protection: All API calls are encrypted using TLS 1.3.
- In-memory inference: Context text is processed strictly within volatile system memory (RAM) during execution.
- Immediate memory reclamation: As soon as the response stream completes, the context payload is immediately purged from execution memory.
Limited operational logs (request IDs, latency, error codes, approximate token counts) may be retained by InboxDays for reliability, billing, and abuse prevention — without storing full email bodies in those logs where avoidable.
4. Vault & zero-knowledge isolation
AI processing features do not operate automatically on Vaulted emails. Content stored inside the zero-knowledge Vault is encrypted client-side. To use AI features on a Vaulted email, you must explicitly decrypt the message locally and opt-in to pass the plaintext snippet to the AI service for that specific interaction. See the Zero-Knowledge Cryptographic & Key Loss Disclaimer.
5. Human monitoring disclosures
Neither InboxDays engineers nor AWS/Anthropic personnel engage in human review or manual monitoring of prompts, drafts, or email content submitted through our AI processing pipelines. Automated filtering occurs solely in-memory to detect system abuse and enforce platform security policies.
6. User control & opt-out options
AI capabilities inside InboxDays are optional:
- Workspace Administrators can disable AI drafting capabilities organization-wide via Settings organization controls when available.
- Individual users can disable inline AI autocompletion in personal composer settings when available.
Until those settings surfaces ship, contact support@inboxdays.com to request AI disablement for your account or organization.