Privacy Policy

Built So Your Inbox Stays Private, Protected, And Under Your Control

Privacy is not a side note for Inboxaly. It is part of the product design itself. This page explains, in plain language, how data is handled, what is not stored, how access works, and what happens when you leave.

No human reads your emails No email body storage Data deleted within 24 hours of cancellation
No human access to email content

Email bodies are processed by AI only and are not read by Inboxaly staff.

Privacy
Encrypted in transit and at rest

AES-256 and TLS 1.3 are used to protect data throughout the workflow.

Security
Data removed after cancellation

Templates, rules, logs, and connected service data are deleted within 24 hours.

Control

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

24 hrs

Deletion window after cancellation

0

Advertising tracking cookies used

Last Updated: [Date]

Clear Privacy Principles, Structured For Easy Review

This page follows the same philosophy as the product itself: keep things transparent, practical, and easy to understand.

The Short Version

The fastest possible summary of how Inboxaly handles privacy and data.

  • We never read your emails. Only our AI processes them, and no human at Inboxaly accesses your email content.
  • We never store email bodies on our servers. Emails are processed in real time to determine action and execute it.
  • We store metadata such as sender, subject, labels, and actions taken to power your dashboard and activity log.
  • We use AES-256 encryption at rest and TLS 1.3 in transit.
  • We connect through OAuth 2.0 and do not see or store your email password.
  • We are SOC 2 Type II compliant and undergo regular third-party security audits.
  • We are GDPR compliant, and you can request data export or deletion at any time.
  • We never sell your data to anyone for any reason.
  • When you cancel, your data is deleted within 24 hours.
  • We use essential cookies only and do not use advertising tracking cookies.

How Data Is Handled

What Inboxaly processes, what it stores, and what it deliberately avoids storing.

What we do not store

Inboxaly is designed not to store email bodies on its servers. Email content is processed in real time so the system can decide what action to take and then complete that action.

What we do store

Inboxaly stores metadata including sender, subject, timestamp, labels, and actions taken. This supports your dashboard, activity log, and system transparency.

Practical Meaning

The product is built to keep the operational benefits of logging and visibility without turning full email body storage into part of the platform model.

Security Protections

The controls described for encryption and security review.

Encryption at rest

Inboxaly uses AES-256 encryption for stored data.

Encryption in transit

Inboxaly uses TLS 1.3 to protect data moving between systems.

Independent review

The platform states that it is SOC 2 Type II compliant and undergoes regular third-party security audits.

Security philosophy

Privacy and security are presented as part of the core design, not optional add-ons.

Access & Authentication

How account connection works and why your password is not part of the model.

Inboxaly connects through OAuth 2.0, which means account access is authorized securely through the email provider’s authentication flow. Inboxaly does not see or store your email password.

This design reduces credential exposure while making connection and revocation cleaner and more controllable for users.

Compliance & Data Rights

Standards and user rights explicitly stated in the policy summary.

GDPR compliance

Inboxaly states that it is GDPR compliant.

User rights

Users can request data export or deletion at any time.

Data selling

Inboxaly states clearly that user data is never sold to anyone for any reason.

Human access boundary

The policy states that no human at Inboxaly accesses user email content.

Deletion & Cancellation

What happens when you stop using the service.

When you cancel, Inboxaly states that all product-side data is deleted within 24 hours. This includes templates, rules, logs, and connected dashboard-related data.

Your original emails remain in your own inbox untouched.

Important

Deletion applies to Inboxaly-managed platform data. Your underlying email account and its email history remain under your own control.

Cookies

Essential Cookies Only. No Advertising Tracking

The privacy summary states that Inboxaly uses only essential cookies and does not use tracking cookies for advertising. That means the site is intended to support required functionality without turning cookie behavior into an ad-targeting system.

  • Essential cookies only
  • No advertising tracking cookies
  • Privacy-first approach to basic site functionality
Purpose

Support core product and site functionality.

Not used for

Advertising-based user tracking.

Privacy position

Keep cookie usage narrow, necessary, and non-exploitative.

Questions about privacy?

Talk To Us Before You Connect Your Inbox

If you want more clarity on security, storage, access, or compliance before using Inboxaly, we would rather answer those questions directly than leave anything unclear.