1. Who We Are
InboxReply.ai ("we," "us," or "our") is an AI-powered email management service operated at inboxreply.ai. If you have questions about this policy, contact us at support@inboxreply.ai.
2. Information We Collect
Account Information
When you create an account, we collect your email address and a hashed password. We do not store your password in plain text.
Gmail Data (via Google OAuth)
With your explicit permission, InboxReply.ai accesses your Gmail account using the following Google API scopes:
- gmail.readonly โ to read email messages for AI analysis, triage, and summarization
- gmail.send โ to send AI-drafted replies on your behalf only when you explicitly approve and click Send
We only read emails for the date you select in the app. We do not continuously monitor, archive, or index your inbox.
Google Calendar Data (via Google OAuth)
With your explicit permission, InboxReply.ai accesses your Google Calendar using:
- calendar.readonly โ to read upcoming events so the AI can cross-reference your schedule when analyzing emails and deadlines
We only read events within the date range you select. We do not modify, create, or delete calendar events.
OAuth Tokens
OAuth access tokens and refresh tokens issued by Google are stored securely in our database (Supabase, encrypted at rest) and are used solely to make API calls on your behalf within the app. Each user's tokens are strictly isolated โ no user can access another user's tokens.
Usage Data
We store records of email analysis runs, drafted replies, and action statuses in your account to power the app's dashboard and history features. This data is associated with your user account and not shared.
3. How We Use Your Information
- To provide AI-powered email triage, summarization, and reply drafting
- To display your email analysis history and action tracker in the dashboard
- To send the morning briefing email you configure in the app
- To authenticate you and maintain your session
- To process subscription payments via Stripe
We do not use your email or calendar content to train AI models. All AI analysis is performed via Anthropic's Claude API, which processes your data solely to generate responses and does not retain it for training purposes.
4. How We Share Your Information
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.
We share data only with the following service providers, strictly to operate the app:
- Anthropic โ processes email content via the Claude API to generate summaries and draft replies. Subject to Anthropic's Privacy Policy.
- Supabase โ hosts our database and authentication. Data is stored in the United States. Subject to Supabase's Privacy Policy.
- Google โ we access Gmail and Calendar via the Google API on your behalf. Subject to Google's Privacy Policy.
- Stripe โ processes subscription payments. We do not store payment card information. Subject to Stripe's Privacy Policy.
- Resend โ delivers transactional emails (account confirmation, password reset). Subject to Resend's Privacy Policy.
5. Google API Data Use Disclosure
InboxReply.ai's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only request access to Gmail and Calendar data that is necessary to provide the features described in this policy
- We do not use Google user data to develop, improve, or train generalized AI or ML models
- We do not allow humans to read your Gmail or Calendar data unless you explicitly share it with us for support purposes
- We do not transfer Google user data to third parties except as necessary to provide the service (listed above)
6. Data Retention
We retain your account data and email analysis history for as long as your account is active. OAuth tokens are refreshed automatically and replaced when you reconnect.
If you delete your account, all associated data โ including OAuth tokens, email analysis records, and drafted replies โ is permanently deleted within 30 days.
7. Your Rights and Controls
- Disconnect Gmail/Calendar: Use the "Disconnect" button in the app sidebar at any time. This immediately revokes our access and deletes your stored OAuth tokens. You can choose at the same time to permanently delete your previously analyzed email history for that provider, or keep it and disconnect only.
- Delete your account: Use the "Delete Account" option in the app sidebar (Danger Zone) to permanently delete your account and all associated data immediately. You can also email support@inboxreply.ai for assistance.
- Revoke Google access: Visit Google Account Permissions to revoke InboxReply.ai's access directly from your Google account at any time.
- Data export: Contact us to request a copy of your stored data.
8. Security
We use industry-standard security practices including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Encrypted at-rest storage via Supabase
- Per-user data isolation โ no user can access another user's data
- OAuth tokens stored securely and never exposed to the browser
9. Children's Privacy
InboxReply.ai is not directed at children under 13. We do not knowingly collect personal information from children under 13.
10. Changes to This Policy
We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy questions, data requests, or concerns, contact us at:
support@inboxreply.ai
InboxReply.ai