Skip to content
Inbox Manager

Privacy Policy

Effective date: [EFFECTIVE_DATE] · Last updated: [LAST_UPDATED]

This Privacy Policy explains how [COMPANY_LEGAL_NAME] (“we”, “us”) collects, uses, and protects information in connection with the Inbox Manager application (the “Service”). The Service is provided to organizations and their invited team members; it is not offered to the general public.

1. Information we access from Google

When you connect a Google (Gmail) account, you grant the Service the following OAuth scopes, and we access the corresponding data solely to provide the features described:

  • Gmail — read (https://www.googleapis.com/auth/gmail.readonly): we read messages, threads, labels, and your send-as settings to display, search, and organize your mail within the Service.
  • Gmail — send (https://www.googleapis.com/auth/gmail.send): we send messages you compose or reply to, on your behalf, from within the Service.

We do not request or use any other Google data. We do not permanently delete your Gmail data through the Service.

2. Other information we collect

  • Account information: your email address and workspace membership/role.
  • Message content and metadata synced from your connected mailboxes, stored encrypted to power the Service's features.
  • Audit logs: a record of security-relevant actions (sign-in, message views, sends) for compliance.
  • Standard technical data (IP address, user agent) for security and abuse prevention.

3. How we use information

We use the information only to provide and secure the user-facing features of the Service — displaying and organizing your mail, sending on your behalf, access control, and audit logging. We do not use it for advertising, sell it, or share it with data brokers.

4. Limited Use of Google user data

Inbox Manager's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, consistent with those requirements:

  • We limit our use of Google user data to providing or improving user-facing features that are prominent in the Service.
  • We do not transfer Google user data except as necessary to provide or improve those features (with your consent), for security, to comply with law, or as part of a merger/acquisition with your explicit consent.
  • We do not allow humans to read your Google user data unless you affirmatively agree, it is necessary for security or to comply with law, or the data has been aggregated and anonymized for internal operations.
  • We do not use Google user data for advertising, and do not transfer it to advertising platforms, data brokers, or resellers.

Source: Google API Services User Data Policy (last updated by Google 2024-02-15).

5. Storage, security, and retention

Message content and OAuth tokens are stored encrypted. Database connections use full TLS certificate verification. Access is scoped per workspace and logged.

Retention. Message content is retained while a mailbox is connected — the connected mailbox is the record, so there is no age-based cap on messages. When a mailbox is disconnected, its message content is permanently purged 90 days after disconnection. When a workspace (account) is deleted, all of its data — messages, drafts, folders, inboxes, clients, and its encryption keys — is permanently purged 30 days after deletion. These purges are irreversible. A limited administrative audit trail (who did what, when — without message content) is retained separately to meet security and legal obligations for [AUDIT_RETENTION_PERIOD]. You may disconnect a mailbox or request deletion at any time (Section 8).

6. Subprocessors

We use the following service providers to operate the Service: Google (Gmail API), Supabase (database and authentication), and Resend (transactional email). Confirm and complete this list before publishing: [SUBPROCESSOR_LIST_CONFIRMED].

7. HIPAA

The Service is designed to handle protected health information (PHI) under HIPAA. PHI is processed subject to a Business Associate Agreement with your organization: [BAA_STATUS_AND_CONTACT].

8. Your rights and choices

You can revoke the Service's access to your Google account at any time at myaccount.google.com/permissions, or by disconnecting the mailbox in the app. To request access to or deletion of your data, contact us below.

9. Contact

[COMPANY_LEGAL_NAME], [MAILING_ADDRESS]. Privacy contact: [PRIVACY_CONTACT_EMAIL].

10. Changes

We may update this policy; material changes will be posted here with a new “Last updated” date.

Privacy Policy — Inbox Manager