Privacy policy
Last updated: 3 September 2026 · Effective: 3 September 2026
Inboxly is operated by Inboxly, LLC, 7995 Blue Diamond Rd #102-119, Las Vegas, NV 89113, United States ("Inboxly", "we", "us", "our"). This policy explains what Inboxly accesses in your mailbox, what it stores, what it will never do, and how to remove everything. It is written to be specific rather than broad, because a policy about somebody's email should be checkable against what the software actually does.
This policy applies to the Inboxly website at myinboxly.com, the Inboxly applications for iOS and Android, and any related services (together, the "Service"). It does not apply to your email provider, whose own privacy policy continues to govern your mailbox, nor to any third-party website you reach through a link in an email.
The short version
- Your email is never sold, rented, or shared for advertising.
- No model is trained on your email, by us or by anyone else.
- We do not store the contents of your messages — only headers and derived data.
- Cleaning moves mail to Trash. Inboxly never deletes anything permanently.
- Inboxly cannot send email. It does not request permission to.
- Revoke access at any time and all processing stops immediately.
The rest of this document is the detail behind those six lines. Where the summary and the detail appear to disagree, the detail governs.
1. Definitions
- Personal data / personal information — information that identifies, relates to, or could reasonably be linked with you.
- Mailbox metadata — information about a message that is not its body: sender, recipients, subject, date, size, labels, and headers.
- Derived data — conclusions Inboxly calculates from metadata, such as a category, a recommendation, or a per-sender statistic.
- Google user data — data obtained from Google APIs about you or your mailbox.
- Process — any operation performed on data, including collecting, storing, analysing, disclosing and deleting.
2. What we collect
2.1 Account data. Your email address and an account identifier. If you sign in with Google we also receive your name and profile picture. If you contact support, we keep that correspondence.
2.2 Mailbox metadata. For each message in a connected mailbox: the message and thread identifiers, the sender's address and display name, recipients in the To and Cc fields, the subject line, the short snippet generated by your provider, the date, the approximate size, your provider's own labels (including whether a message is unread), and the presence and content of bulk-mail and unsubscribe headers.
2.3 Derived data. The categories, confidence scores and recommendations Inboxly calculates, the reason recorded for each, and per-sender statistics such as how many messages a sender has sent you, how many you opened, and whether you have ever replied.
2.4 Action records. What you approved, when it was executed, its outcome, and enough information to reverse it.
2.5 Payment data. Processed by Stripe, Apple or Google. We receive confirmation that a payment succeeded, a subscription status, an expiry date and an opaque identifier. We never see or store your card number or bank details.
2.6 Technical data. IP address, device and browser type and version, operating system, language, timestamps of requests, and error diagnostics. Used to operate, secure and debug the Service.
2.7 What we do not collect. We do not store the body of your messages. We do not store your attachments. We do not have your email password: access is granted through OAuth by your provider and can be withdrawn by you at any time. We do not collect precise geolocation, contacts from your device, biometrics, or any special category data as defined by UK or EU law, except insofar as such information may incidentally appear inside an email we process on your behalf and do not retain.
3. Where the data comes from
- From you — when you create an account, contact support, or approve an action.
- From your mail provider — when you authorise Inboxly, and thereafter as new mail arrives.
- Automatically — technical data generated when you use the Service.
- From payment providers — subscription status, so we know what you are entitled to.
We do not buy personal data, and we do not enrich your data from data brokers.
4. Google user data, specifically
Inboxly requests these Google permissions and uses them only as described:
gmail.readonly— to read message headers, and where necessary message content, in order to categorize your inbox and produce your report: how many messages are unread, which senders account for the most volume, which mail is bulk, and which senders you never open.gmail.modify— to carry out only the cleaning actions you have explicitly approved: archiving, applying labels, and moving messages to Trash.openid,email,profile— to identify your account and show you which mailbox is connected.
Inboxly does not request permission to send email. Replies and forwards open in your own mail application, which means Inboxly cannot send mail as you even if it were compromised. Inboxly does not request access to Google Drive, Calendar, Contacts, or any other Google service.
5. Google API Limited Use
Inboxly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Inboxly:
- does not transfer or sell Google user data to third parties for serving advertisements, for credit assessment, for lending, or for any similar purpose;
- does not use Google user data to develop, improve, or train generalised or non-personalised artificial intelligence or machine-learning models;
- uses Google user data only to provide and improve the user-facing features described in this policy, and for no other purpose;
- does not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition following notice to you; and
- permits humans to read Google user data only where you have given explicit consent for a specific support request, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised.
6. How we use what we collect
- To categorize your mail and produce your report — the core function of the Service.
- To execute actions you approve — archiving, labelling, unsubscribing, moving to Trash, and reversing those actions.
- To keep your view current — receiving change notifications from your provider so the Service reflects your mailbox.
- To operate and secure the Service — authentication, abuse prevention, rate limiting, fraud prevention and debugging.
- To bill you — and to determine what your subscription entitles you to.
- To support you — answering questions you raise.
- To comply with law — tax, accounting, and lawful requests.
- To improve the Service in aggregate — using statistics that do not identify you or any sender, and never by training a model on your mail.
We do not use your data for advertising, we do not profile you for anyone else's benefit, and we do not make decisions producing legal or similarly significant effects about you by automated means.
7. How your mail is categorized, and the limits of that
7.1 Most of it uses no AI at all. Categorization is calculated from information already present in the message: the sending domain, whether the message carries bulk-mail or unsubscribe headers, how often that sender writes to you, and how often you open or reply to them.
7.2 Where more is needed. Inboxly uses Google's Gemini models through Vertex AI inside our own Google Cloud project, under terms that prohibit using your data to train models. Your mail is not sent to OpenAI, Anthropic, or any other AI provider. In the ordinary case only a subject line and a short snippet are processed, not a full message.
7.3 It will sometimes be wrong. Categorization is automated and imperfect. That is why Inboxly shows you what it proposes before anything happens, moves mail to Trash rather than deleting it, records a reason you can check, and offers an undo. You remain in control of every action.
7.4 No automated decisions with legal effect. Nothing Inboxly calculates is used to make decisions about your credit, employment, insurance, or legal rights, and we will not supply it to anyone who does.
8. Legal bases for processing (UK and EEA)
- Performance of a contract — accessing and organising your mailbox, executing approved actions, and billing you.
- Legitimate interests — securing the Service, preventing abuse and fraud, debugging, and improving the Service in aggregate. We have balanced these against your rights and consider them not to override your interests; you may object at any time.
- Consent — the OAuth permission you grant your provider, which you may withdraw at any time without affecting the lawfulness of prior processing.
- Legal obligation — retaining financial records and responding to lawful requests.
9. Who else is involved
We use the following processors. No other third party receives data derived from your mailbox:
- Google Cloud Platform (United States) — hosting, database, task queues, and Vertex AI, all within our own project.
- Google LLC — as the provider of the Gmail API you have authorised.
- Stripe, Inc. — payments made on the web.
- Apple Inc. and Google LLC — payments made inside the mobile apps, under their own terms and privacy policies.
Each processor is bound by contract to process data only on our instructions and to maintain appropriate security. If we add a processor that handles mailbox data, we will update this list before it begins processing.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California law. We have not done so in the preceding twelve months.
We may disclose data where legally compelled by valid legal process; where necessary to establish, exercise or defend legal claims; or to protect the rights, safety or property of any person. Where the law allows, we will tell you first.
10. Business transfers
If Inboxly is involved in a merger, acquisition, financing or sale of assets, your data may be transferred as part of that transaction. We will give notice before your data becomes subject to a different privacy policy, and any acquirer will remain bound by commitments no less protective than these, including the Google Limited Use requirements.
11. Images and tracking in your mail
Remote images in your mail are loaded through our servers rather than by your device. A sender who embeds a tracking pixel therefore cannot learn that you opened their email, when you opened it, what device you used, or from what IP address. We do not report your activity back to senders, and we do not use tracking pixels of our own inside the Service.
12. International transfers
Data is processed and stored in the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, your data is transferred outside your region under the UK International Data Transfer Addendum, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, together with any supplementary measures required. You may request a copy of the relevant safeguards by writing to us.
13. How long we keep it
- Mailbox metadata and derived data — for as long as the mailbox is connected. Disconnecting deletes it.
- Message contents — not retained. Fetched for display, then discarded.
- Action records — 90 days, so an action can be explained and reversed.
- Account records — for as long as your account exists.
- Billing records — up to 7 years, where tax and accounting law requires.
- Support correspondence — 2 years.
- Security and diagnostic logs — 30 days, except where an investigation requires longer.
After you delete your account or revoke access, data is deleted within 30 days, except where law requires retention. Backups are overwritten on a rolling basis and any residual copy is deleted within 90 days.
14. Security
14.1 Measures. Data is encrypted in transit using TLS and at rest using our cloud provider's managed encryption. OAuth tokens are encrypted with a separately managed key. Access to production systems requires multi-factor authentication, is restricted to personnel who need it, and is logged. Our tooling is built to record identifiers rather than message contents, so that debugging does not become a means of reading mail.
14.2 Minimisation as a control. The strongest security property of the Service is what it does not hold: not storing message bodies means a breach cannot disclose them.
14.3 No guarantee. No system is perfectly secure and we do not claim otherwise.
14.4 If something happens. If a breach affects your personal data we will notify you and the relevant supervisory authority as the law requires, without undue delay and, where the UK or EU GDPR applies, within 72 hours of becoming aware of it.
14.5 Reporting a vulnerability. Write to security@myinboxly.com. We will not pursue legal action against good-faith research that respects user privacy and does not degrade the Service.
15. Your rights, wherever you live
At any time, without needing to ask us, you can:
- disconnect a mailbox in Inboxly, which deletes the stored data for that mailbox;
- delete your Inboxly account, which removes everything associated with it; and
- revoke Inboxly's access from your Google account at myaccount.google.com/permissions, which stops all processing immediately.
16. United Kingdom and EEA rights
You have the right of access; to rectification; to erasure; to restriction of processing; to object to processing carried out on the basis of legitimate interests; to data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office — though we would appreciate the chance to resolve it first.
We do not currently appoint a Data Protection Officer, as we are not required to. Requests should be sent to the contact address in section 21.
17. California rights (CCPA/CPRA)
In the preceding twelve months we have collected these categories of personal information:
- Identifiers — email address, account identifier, IP address. Collected from you and automatically. Used to operate the Service. Disclosed to our hosting and payment processors.
- Commercial information — subscription status and purchase records. Collected from payment processors. Used for billing and entitlement.
- Internet or network activity — technical and diagnostic data. Collected automatically. Used to secure and debug.
- Sensitive personal information — the contents of your email, insofar as it is processed to categorize it. Collected from your mail provider with your authorisation. Used only to provide the Service.
You have the right to know, to delete, to correct, to opt out of sale or sharing — we do neither — and to limit the use of sensitive personal information. Because we use sensitive personal information only to perform the service you requested and for no secondary purpose, the right to limit does not require a separate mechanism, but you may still exercise it and we will honour it by disconnecting the mailbox.
We will not discriminate against you for exercising any right. You may use an authorised agent, and we may ask that agent for proof of authorisation. We do not knowingly sell or share the personal information of anyone under 16.
18. Other US state rights
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have broadly equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling with legal effects. We do not conduct any of those three activities. Where your state provides a right to appeal a refused request, you may appeal by replying to our decision, and we will respond within the period your state's law requires. Nevada residents may direct a request not to sell covered information to the address in section 21, though we do not sell it.
19. How to exercise a right
Email privacy@myinboxly.com from the address associated with your account, stating what you want. We will acknowledge within 10 days and respond substantively within 45 days, extendable once by a further 45 days where the request is complex, or within any shorter period your law requires. We may need to verify your identity, and we will only ask for information necessary to do so. There is no charge unless a request is manifestly unfounded or excessive.
20. Cookies and similar technologies
We use only cookies strictly necessary to operate the Service: keeping you signed in, and protecting the OAuth flow against cross-site request forgery. We do not use advertising cookies, cross-site tracking, or third-party analytics that profile you. Because we set no non-essential cookies, no consent banner is required. Your browser's Global Privacy Control signal is honoured as an opt-out of sale and sharing, though we do neither.
21. Children
Inboxly is not directed to and not intended for anyone under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with data, contact us and we will delete it promptly.
22. Third-party links
Emails often contain links, and unsubscribe pages are operated by senders rather than by us. We are not responsible for the privacy practices of any third-party site, and this policy does not apply to them.
23. Changes to this policy
We may update this policy. If a change materially affects you, we will notify you in the Service or by email before it takes effect, and where the law requires it we will seek your consent. The date at the top always reflects the current version, and material changes are summarised at the point of notice.
24. Contact
Inboxly, LLC
7995 Blue Diamond Rd #102-119, Las Vegas, NV 89113, United States
Privacy and data requests: privacy@myinboxly.com
Security reports: security@myinboxly.com
Everything else: support@myinboxly.com