← Inbox AI
Privacy Policy
Last updated: March 4, 2026
1. Introduction
MailSort, LLC, doing business as Inbox AI ("we", "our", or "us") is committed to protecting your privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use
our email management service.
2. Information We Collect
2.1 Information You Provide
- Google account information (name, email address, profile picture)
- Account settings and preferences
- Custom classification rules you create
- Feedback and support communications
2.2 Information We Collect Automatically
- Email metadata (sender, subject, date, labels)
- Email content for classification purposes
- Usage data and analytics
- Device and browser information
- IP addresses and log data
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our email classification service
- Process and analyze your emails using AI to categorize and prioritize them
- Apply labels to emails and organize your inbox
- Archive non-actionable emails on your behalf
- Create email drafts on your behalf (e.g., forwarding a receipt or drafting a reply) for your review before sending
- Analyze your writing style from previously sent emails to generate drafts that match your tone
- Respond to your support requests
- Monitor and analyze usage patterns
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. AI Processing and Email Analysis
We use OpenAI's GPT models to classify your emails. When processing emails:
- Email content snippet is sent to OpenAI for classification
- We only send necessary information (sender, subject, snippet)
- OpenAI does not use your data to train their models, per our agreement
- Processed data is not retained by OpenAI beyond the API call
- Classification results are stored in our secure database
5. Data Storage and Security
We implement industry-standard security measures to protect your data:
- OAuth refresh tokens are encrypted using Google Cloud KMS
- Data is stored in Google Cloud with appropriate access controls
- All communications use HTTPS encryption
- Access to data is limited to authorized personnel only
- Regular security audits and updates
6. Data Sharing and Disclosure
We do not sell your personal information. We may share your information with:
- Service Providers: OpenAI for email classification, Google Cloud for infrastructure
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
7. Your Rights and Choices
You have the right to:
- Access your personal information
- Correct inaccurate data
- Request deletion of your data
- Revoke Gmail access permissions
- Export your data
- Opt-out of non-essential communications
- Delete your account at any time
8. Email Service Provider Integration
Inbox AI integrates with email service providers to deliver its core functionality. Currently, we support
Gmail via the Google API. We may add support for additional email providers in the future. This section
describes how we access and use data from connected email accounts.
8.1 Gmail Integration
Inbox AI's use and transfer of information received from Gmail APIs adheres to the
Google API Services User Data Policy
,
including the Limited Use requirements.
8.2 OAuth Permissions We Request
When you connect your Gmail account, we request the following permissions. We request only the minimum
permissions necessary to provide our service.
-
openid, userinfo.email, userinfo.profile — Used to authenticate your account and
identify you within the service. We read your name, email address, and profile picture.
-
gmail.labels (
.../auth/gmail.labels) — Used to create and manage category
labels in your Gmail account (e.g., "InboxAI/Action", "InboxAI/FYI") so that classified emails are
visually organized.
-
gmail.modify (
.../auth/gmail.modify) — Used to: read incoming emails for
AI classification; apply category labels to messages; archive non-actionable emails from your inbox
(when Inbox Zero mode is enabled); and create email drafts on your behalf for your review. We do not
send emails on your behalf — drafts are saved to your Drafts folder for you to review and send.
8.3 How We Use Gmail Data
We access your Gmail data solely to provide the Inbox AI service. Specifically:
- Email content and metadata (sender, subject, body snippet) is sent to OpenAI for classification purposes
- Your previously sent emails (up to 30) may be analyzed to detect your writing style when generating draft replies — this analysis happens at draft creation time and is not stored
- Classification results and email metadata are stored in our secure database to power your activity feed and usage statistics
- We do not use Gmail data for advertising, profiling, or any purpose unrelated to providing email management features
- We do not allow humans to read your email content except to investigate a specific support request you have raised, with your consent
9. Data Retention
We retain your information for as long as your account is active or as needed to provide services.
When you delete your account, we will delete your personal information within 30 days, except where
we are required to retain it for legal purposes.
10. Children's Privacy
Our service is not intended for users under 18 years of age. We do not knowingly collect personal
information from children under 18.
11. International Data Transfers
Your information may be transferred to and maintained on servers located outside of your state,
province, country, or other governmental jurisdiction. We use Google Cloud Platform's US-based
infrastructure.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting
the new Privacy Policy on this page and updating the "Last updated" date. Material changes will be
communicated via email.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at: