Legal
Privacy Policy
How InboxDays collects, uses, stores, and shares personal data — and how you can exercise your rights.
This Privacy Policy explains our practices for the InboxDays websites and application (collectively, the “Service”). It is designed to meet expectations under the GDPR, UK GDPR, and CCPA/CPRA, and to satisfy Google API Services User Data Policy (Limited Use) requirements for OAuth integrations.
1. Who we are
InboxDays operates the Service. For privacy requests, contact privacy@inboxdays.com. Enterprise customers may also rely on our Data Processing Addendum.
2. Categories of data we process
Account metadata
- Identity and contact details (name, email address, authentication identifiers).
- Billing and subscription metadata (plan tier, invoices, payment status via our Merchant of Record when paid plans are enabled — we do not store full card numbers). Until a Merchant of Record agreement is live, we do not process card payments through InboxDays.
- Account preferences, signatures, connected mail-account labels, and UI preferences.
Application data
- Mail sync artifacts needed to operate the client (message metadata, folder/label structure, and message content retrieved from your providers as authorized).
- Search indexes / vectors derived from content you authorize us to process for search and triage features.
- Encrypted Vault / secure-link payloads (ciphertext). For zero-knowledge Vault features we do not possess decryption keys — see the Zero-Knowledge Disclaimer.
- WORM Vault archives (full MIME copies you explicitly retain under Object Lock retention policies), stored separately from day-to-day mailbox sync.
- AI prompts, selected thread context, and drafts when you invoke AI assist — processed per the AI Data Privacy & Model Ethics Statement.
- Audit and security metadata (login events, admin actions, tamper-evident logs where enabled for enterprise).
Technical data
- Device/browser information, IP address, approximate location derived from IP, and diagnostic logs.
- Essential auth/session storage described in the Cookie & Tracking Disclosure.
3. Why we process data (purposes & lawful bases)
- Contractual necessity — to create accounts, authenticate you, sync and display mail, provide settings, billing, and support.
- Legitimate interests — to secure the Service, prevent abuse, improve reliability, and understand aggregate product usage (balanced against your rights).
- Consent — where required (e.g. non-essential analytics cookies, or certain marketing communications).
- Legal obligation — to comply with law, respond to lawful requests, and keep required financial records.
4. Where data is stored
Primary infrastructure is hosted on Amazon Web Services in regions we configure for the Service (commonly EU regions such as eu-west-2 for current deployments). Subprocessors are listed in the Subprocessor Directory. Cross-border transfers, where applicable, rely on appropriate safeguards (including SCCs as described in the DPA).
5. Retention
- Account metadata is retained while your account is active and for a limited period afterward as needed for security, billing, and legal compliance.
- Application mail data follows product sync behavior plus any TTL / delete rules or rolling auto-archive settings you configure — expired TTL windows result in deletion as disclosed in the Terms; auto-archive removes messages from Inbox at the provider without creating a separate InboxDays backup.
- WORM Vault copies remain locked for the retention duration you selected and cannot be shortened while Object Lock compliance mode applies.
- AI inference payloads are processed ephemerally as described in the AI Policy and not retained for model training.
- Audit logs may be retained for longer windows for security and enterprise compliance.
6. Sharing
We share personal data with subprocessors that help us run the Service (hosting, auth, payments, AI inference, OCR), with your connected mail providers as needed to sync and send mail, and when required by law. We do not sell personal information. We do not use Google user data for advertising.
7. Google API Services — Limited Use
InboxDays' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means Gmail and related Google user data obtained via OAuth is used only to provide or improve user-facing features visible in InboxDays (reading, searching, composing, organizing, and related productivity features you request), is not sold, and is not used for serving advertisements. Human access is limited to security, compliance, and support cases with appropriate controls.
8. Your rights (GDPR / UK GDPR / CCPA)
Depending on your location, you may have rights to:
- Access / know what personal data we hold (DSAR)
- Rectification / correction
- Erasure / deletion
- Restriction or objection to certain processing
- Portability / export
- Withdraw consent where processing is consent-based
- Opt out of “sale” or “sharing” as defined under CCPA (we do not sell personal information)
How to exercise a DSAR
- Email privacy@inboxdays.com from your account email with subject line “DSAR” and specify whether you request export, deletion, or another right.
- We may need to verify your identity before fulfilling the request.
- We aim to respond within one month (GDPR/UK GDPR) or applicable CCPA timelines. Complex requests may require an extension, which we will explain.
- Account self-serve deletion and billing cancel paths (when enabled) are available under Settings; see also Cancellation & Refunds.
9. Children
The Service is not directed to children under 16 (or higher age where required). We do not knowingly collect such data.
10. Security
See our Security & Vulnerability Policy. No method of transmission or storage is 100% secure; please use strong authentication and protect Vault keys.
11. Changes
We will update this Policy by posting a new version with a revised date. Material changes will be highlighted as required.
12. Contact & complaints
Privacy: privacy@inboxdays.com. You may also lodge a complaint with your local supervisory authority (EEA/UK) if you believe processing infringes applicable law.