Privacy Policy
Effective Date: August 25, 2026 • Last Updated: August 25, 2026
InboxMate's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalized AI/ML models.
1. Overview
InboxMate ("we", "us", "our", or the "Application") is an AI-powered email productivity assistant designed to help you summarize emails, draft contextual replies, and organize your inbox efficiently. We respect your privacy and are committed to protecting the confidentiality and integrity of your personal information.
This Privacy Policy outlines how InboxMate collects, processes, uses, and protects your information when you access or use our web application at InboxMate.
2. Information We Collect
We only collect and process data that is strictly required to provide the core productivity features of the service:
Google Account Profile
When you authenticate via Google OAuth 2.0, we receive basic profile info (email address, display name, and avatar URL) to establish your authenticated session.
Gmail Content (On-Demand)
When requested by you, our application reads email metadata (subject, sender, date, labels) and email bodies strictly to display them in your dashboard and generate requested summaries/replies.
OAuth Tokens
We receive temporary OAuth access and refresh tokens from Google. These tokens are stored securely in server-side encrypted session storage and are never exposed to client-side code.
3. How We Use Information
We use the data collected strictly for user-initiated productivity operations, specifically to:
- Display your Gmail inbox, threads, labels, and message details in the dashboard interface.
- Generate concise, 2-3 sentence summaries of selected emails using Google Gemini AI.
- Generate contextual, customizable draft replies matching your chosen tone (e.g., Professional, Casual, Direct).
- Classify emails by priority and category (e.g., Action Required, Newsletter, Transactional) on demand.
- Execute email actions that you explicitly initiate (such as sending replies, composing new emails, archiving, starring, or deleting).
4. Google API User Data & Limited Use Disclosure
InboxMate accesses Google user data via authorized Google OAuth 2.0 scopes (specifically gmail.readonly, gmail.send, and gmail.modify).
Our Direct Commitments:
- No Model Training: Google Workspace APIs and Gmail user data are NEVER used to train, retrain, or improve generalized artificial intelligence or machine learning models.
- No Data Brokering: We do not sell, rent, lease, or monetize your personal or email data to third parties, data brokers, or advertisers under any circumstances.
- No Human Reading: No human at InboxMate reads your private emails unless you have explicitly provided affirmative consent for specific technical troubleshooting, or when required by applicable law.
- Limited Scope: Data access is strictly limited to the functions required to deliver the email management and AI assistance features explicitly requested by you.
5. AI Processing & Google Gemini
To provide summarization and drafting features, email content that you select is sent securely via encrypted API calls (HTTPS/TLS) to the official Google Gemini API (Google AI / Vertex AI).
- Data transmitted to the Gemini API is processed transiently in memory for the sole purpose of generating the requested summary, reply, or classification.
- No email text is retained or archived in third-party public AI datasets.
- You maintain complete control over which emails you summarize or reply to.
6. Data Storage & Security
We implement robust technical and operational measures to safeguard your information:
- No Permanent Email Database: We do not store or mirror your inbox messages in a persistent cloud database. Emails are fetched live on-demand via the official Gmail API.
- Encrypted Transport: All data transmissions between your browser, our backend server, Google APIs, and Gemini APIs occur over encrypted HTTPS connections with TLS 1.3.
- Secure Session Management: User sessions and OAuth credentials are stored in secure, server-side session stores with
HttpOnly,SameSite, andSecureflags enabled. - Security Headers: Our application enforces Strict Transport Security (HSTS), Content Security Policy (CSP), and Cross-Origin Resource protections via Helmet.js.
7. Third-Party Sharing
We do not share your personal information with third parties, except in the following limited technical capacities required to operate the service:
- Google LLC: For authentication (Google Identity), email access (Gmail API), and generative AI processing (Gemini API).
- Hosting Providers: Infrastructure providers (Vercel for frontend hosting and Render for backend service execution) which transmit data strictly under encrypted transit protocols.
- Legal Compliance: If required by law, subpoena, or lawful court order.
8. Your Rights & Revoking Access
You have full control over your data and access permissions at all times:
- Revoke Google Permissions: You can disconnect InboxMate and immediately revoke its access to your Google account at any time by visiting Google Account Permissions.
- Sign Out & Terminate Session: Clicking the Sign Out button in the dashboard immediately destroys your active session and deletes all cached OAuth tokens from memory.
- Data Portability & Deletion: Because we do not store copies of your emails on our servers, revoking access or signing out leaves no residual email archive on our infrastructure.
9. Data Retention & Deletion
Authentication sessions and ephemeral tokens expire automatically after 24 hours of inactivity or immediately upon user logout. When a session expires, all associated tokens are permanently purged from the server session store.
11. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable legal obligations. Any updates will be posted on this page with an updated "Last Updated" timestamp.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please reach out to us: