Skip to main content
Inbox Imp Logo

Privacy Policy

Inbox Imp

Last Updated: August 26, 2026

Introduction

Inbox Imp ("we", "our", or "the Service") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered email organization service.

What We Do

Inbox Imp helps you automatically organize your inbox using AI-powered classification. We read your emails, analyze them, and file or label them to help you prioritize and manage your inbox more efficiently.

Mailboxes We Connect To

Inbox Imp connects to Google Gmail (through the Gmail API, under the gmail.modify scope) and to Microsoft Outlook and Microsoft 365 mailboxes (through the Microsoft Graph API, under the Mail.ReadWrite, Mail.Send and User.Read scopes). Both are authorized by you through the provider's own consent screen, and everything in this policy applies to both unless a section says otherwise. If you never connect a Microsoft account, none of your data reaches Microsoft's Graph API through us.

Information We Collect

Mailbox Data (Gmail and Outlook)

  • Email Messages: Subject lines, sender information, message body content, metadata (dates, labels or categories, message and thread identifiers, and headers such as In-Reply-To and List-Unsubscribe that our safety protections read)
  • Labels and Folders: Existing labels or categories, and the ones we create
  • Attachments: When a message has attachments, we read them in order to classify the message; see "Attachments" below
  • Message IDs: Unique identifiers to track which emails we've processed
  • Sent Mail: If you turn on reply-style assistance, messages you have sent, used to draft replies that sound like you
  • Account Information: The email address of each connected mailbox

Account Data

  • Your Google or Microsoft account email address (used for authentication)
  • OAuth access tokens (encrypted at rest before storage; only the encrypted form is kept)
  • Classification preferences and custom criteria you set

Payment Information

Payments are processed by Stripe (web) or Apple (App Store in-app subscriptions), which tokenize payment details. We do not receive or store your card details. We store your subscription status, credit balance, and transaction history.

How We Use Your Information

Primary Uses

  • Email Classification: We analyze email content to determine appropriate labels and actions
  • Label Management: We apply labels to your Gmail messages based on AI classification
  • Service Improvement: We store classification decisions to learn and improve accuracy over time
  • User Interface: We display summaries and classifications in the web console

AI Processing

We send email subject lines, senders, and message bodies to our AI provider, OpenRouter, which routes each request to an underlying model provider. This is the complete list of places it happens:

  • Classification and highlights. Deciding what to do with a message, and extracting the "why you got this" summary and key sentences shown above an email.
  • Attachments. When a message has attachments, text extracted from them (and, for images, the image itself) is included in that classification request.
  • Search embeddings. The numerical representations of your mail that make semantic search work.
  • Search answers. When you ask a question in search, your question and excerpts of the matching messages.
  • Reply and forward drafting. When you ask for a draft, the message you are replying to or forwarding, and (if reply-style assistance is on) a few of your own past sent replies as examples. Composing a brand-new email involves no AI at all, and AI never chooses or fills in a recipient.
  • Policy and suggestions. Turning your plain-English rules into instructions, and proposing changes based on your corrections.
  • Sender research. Described separately below, because it reaches the public web.

Every request we send carries a no-retention instruction (data_collection: deny), which restricts routing to providers that do not retain your content or use it to train models. Your email is never used to train any model, ours or anyone else's.

OpenRouter does not guarantee which country a given request is processed in, so (unlike our storage, which is entirely in the United States) we do not claim a processing location for AI inference. If you supply your own OpenRouter API key, your requests run through your own OpenRouter account and your own agreement with them.

Sender Research (Perplexity)

The "Research this sender" feature answers who is behind an unfamiliar sender by searching the public web. It is routed through OpenRouter to Perplexity (perplexity/sonar), a web-grounded model. What we send is limited to the sender's address, display name, domain, and the subject line of the message you are asking about, never the message body. Because that model queries the live web, treat the subject line as leaving our infrastructure. The result, including its citations, is cached per account and domain.

Attachments

When a message has attachments, we read them so the message can be classified correctly. Text is extracted from documents and sent to OpenRouter with the rest of the message; image attachments are sent to the model as images. We keep a short AI-written description of each attachment (its filename, type, size, and a summary of its contents) alongside the classification decision. We do not store the attachment files themselves.

What We DO NOT Do

  • Share your emails with third parties for marketing purposes
  • Sell your data to anyone
  • Use your emails for advertising
  • Read emails outside the Inbox Imp features described in this policy
  • Access emails without your explicit authorization

Data Storage and Security

What We Store

  • Classification Results: Decisions about which label to apply and why (stored in our Supabase database)
  • Message Summaries: AI-generated summaries for your reference
  • Body Previews: Short excerpts of email content, along with subject and sender, kept to power in-app search
  • Highlights: A few verbatim key sentences copied from an email, plus brief AI commentary, used to show you why an email matters and what to do about it
  • Search Embeddings: Vector embeddings (numerical representations of email content) built from the subject, sender, summary, and body preview to enable semantic search
  • OAuth Tokens: Access tokens to maintain authorized access, encrypted at rest with AES-128 (Fernet) before they reach the database. Only the encrypted form is stored; the plaintext token is never written down.
  • Attachment Descriptions: For each attachment, its filename, type, size and a short AI-written summary of its contents, stored with the classification decision
  • Sender Research Results: The verdict and citations returned for a researched sender domain, cached per account
  • Custom Criteria: Your classification rules and preferences

What We DO NOT Store

  • Email message bodies beyond the first ~2,000 characters (up to roughly the first 2,000 characters of each message is retained as a body preview to power in-app search; this may be the entire body for short messages; the remainder is processed in memory only)
  • Attachment files, or the full text extracted from them (only the short description described above is kept)
  • Contact lists
  • Unprocessed email content

Security Measures

  • All data transmitted using HTTPS/TLS encryption
  • OAuth tokens encrypted at rest (AES-128/Fernet) with the key held in Google Secret Manager, separate from the database; only ciphertext is persisted
  • Any OpenRouter API key you provide is encrypted at rest; we keep only the last four characters as a plain hint
  • Supabase database with row-level security
  • Access logs maintained for security monitoring
  • Regular security updates and patches
  • No storage of passwords (OAuth-only authentication)

Data Retention

  • Classification Decisions: Kept until you delete your account or ask us to delete them. Revoking our access stops all further processing, but on its own it does not delete decisions we already hold: delete your account (Settings → Delete account) or email privacy@inboximp.com if you want them gone
  • Email Content: Up to roughly the first 2,000 characters of each message body is retained as a preview to power in-app search (this may be the entire body for short messages); the remainder is processed only temporarily in memory
  • OAuth Tokens: Stored until you revoke access or delete your account
  • Mailbox Data: Deleted within 30 days after you remove your account or request deletion
  • Billing Records: Subscription status, credit balance, and transaction history may be retained as required for accounting and legal purposes

Where Your Data Is Stored

All Inbox Imp data at rest is stored in the United States. Our application services run in Google Cloud's us-central1 region (Iowa) and our database, search index, and embeddings are held in us-east-2 (Ohio).

The one exception, stated plainly: AI inference is performed by OpenRouter, which does not guarantee a processing region. We therefore claim US-only storage, not US-only processing. See "AI Processing" above for the no-retention constraint that applies to every request we send.

Third-Party Services

We use the following third-party services:

Google Gmail API

Used to access your Gmail messages. Subject to Google's Privacy Policy.

Microsoft Graph API

Used to access Outlook and Microsoft 365 mailboxes when you connect one: reading messages, moving them between folders, applying categories, and sending mail you compose or forward. Subject to Microsoft's Privacy Statement.

OpenRouter API

AI service used to classify email content. We send email subject lines, message bodies, and attachment content to OpenRouter for analysis, as described under "AI Processing" above. Subject to OpenRouter's Privacy Policy.

Perplexity

Reached through OpenRouter for the "Research this sender" feature only, and sent only a sender's address, display name, domain and the message's subject line. Subject to Perplexity's Privacy Policy.

Supabase

Database service used to store classifications, message metadata, encrypted OAuth tokens, and search embeddings. Subject to Supabase Privacy Policy.

Google Cloud Platform

Used to host the Service and deliver Gmail notifications through Pub/Sub. Subject to GCP Privacy Notice.

Stripe

Payment processor for memberships and credit purchases. When you pay, Stripe processes your name, email address, payment method, and billing address. Subject to Stripe's Privacy Policy.

Apple Push Notification service (APNs)

Used only if you install the Inbox Imp iPhone app and turn on notifications. When a new email is kept for you, we send Apple the sender name, the subject line, and a short excerpt of that email (the assistant's one-line summary when one is available, otherwise a snippet of the message content) so it can be delivered to your device as a notification. No push data is sent otherwise. Subject to Apple's Privacy Policy.

PostHog (product analytics)

We count the steps of using the product, so we can tell whether it is working: you arrived (land), you connected a mailbox (connect), you signed in (signin_completed), your first setup started, finished or failed (onboarding_started, onboarding_completed, onboarding_failed, cleanup-complete), and the billing steps (trial_started, trial_expired, checkout_started, subscription_created, subscription_cancelled, payment_failed, paid). That list is the only vocabulary our code is capable of sending, in the browser or on our servers.

Some of these are sent by our servers rather than your browser, because they happen when no page is open: your setup can finish after you close the tab, and a payment notice from Stripe arrives with no browser involved. A server-sent event identifies you only by a one-way hash of your account id.

What goes with them: a random id stored in your browser (or a one-way hash of your account id, never the address itself), the page path, the hostname that referred you, any UTM tags in the link you clicked, which provider you connected, whether it was the web or the iPhone app, how long setup took, and integer counts. No message content, no subjects, no senders, no email addresses, and no IP address: our code drops any value containing an @ or longer than 64 characters rather than truncating it, and PostHog is configured to discard client IPs.

There is no tracking script on this site. We never load PostHog's JavaScript library, so there is no autocapture, no session recording, no heatmap, and nothing that can read the page around you; we send a small JSON message and nothing else. Data is stored in PostHog's EU region (Frankfurt). Subject to PostHog's Privacy Policy. Blocking it with any ad blocker costs you nothing in the product.

Your Rights and Choices

Access and Control

  • Revoke Access: For a Gmail account, visit Google Account Permissions and remove "Inbox Imp". For a Microsoft account, visit Microsoft app permissions (or ask your administrator, for a work or school account)
  • View Classifications: Access all classification decisions via the web console
  • Delete Data: Delete your account and all stored data yourself from Settings → Delete your account, or contact us and we will do it
  • Export Data: Download a copy of your stored data yourself from Settings → Download my data
  • Modify Preferences: Update classification criteria at any time

Data Deletion

To delete your data:

  1. To delete everything, email privacy@inboximp.com or support@inboximp.com and ask. This removes your stored data (messages, search index, tokens, policies, preferences, and related records) for your primary inbox and every linked inbox
  2. To remove a single added or linked inbox yourself, use the Accounts page in the application; this deletes that inbox's stored data
  3. If you use the Inbox Imp iOS app, Settings → Delete account does the same full deletion immediately, and best-effort revokes our access
  4. You can also cut off access at any time by revoking it at Google Account Permissions or Microsoft app permissions; note that revoking stops processing but does not by itself delete data we already hold, so ask for deletion too
  5. We will delete your mailbox data within 30 days; billing records may be retained as described under Data Retention

Children's Privacy

Our Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by:

  • Updating the "Last Updated" date at the top of this policy
  • Sending an email notification to your connected email address (for material changes)
  • Displaying a notice in the application

Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

Contact Us

The controller of the personal data described in this policy is Bitwise Learning Inc., 6801 NE 132nd Way, Vancouver, WA 98686-4995, United States. If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:

  • Email: support@inboximp.com
  • Privacy Requests: privacy@inboximp.com

Google API Services User Data Policy

Inbox Imp's use and transfer of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements.

Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), our legal basis for processing your personal data is:

  • Consent: You have given explicit consent by authorizing our app via Google or Microsoft OAuth
  • Contract: Processing is necessary to provide the email organization service
  • Legitimate Interest: To improve and maintain our services

California Privacy Rights (CCPA)

California residents have specific rights regarding their personal information:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to request deletion of personal information
  • Right to opt-out of the sale of personal information (we do not sell data)
  • Right to non-discrimination for exercising CCPA rights

To exercise these rights, contact us at privacy@inboximp.com.

Home Terms of Service Security Support Pricing

© 2026 Inbox Imp. All rights reserved.