Effective August 28, 2026
Inboxer Privacy Policy
This Privacy Policy explains how Inboxer ("Inboxer," "we," "us," or "our") collects, uses, discloses, stores, and protects personal information when you use the Inboxer website, applications, dashboard, unified email workspace, connected email services, hosted mailboxes, custom-domain tools, and related services (collectively, the "Services").
1. Scope and roles
This Privacy Policy applies to personal information processed by Inboxer through the Services.
When a business or organization provides access to an Inboxer workspace, that organization generally controls its workspace, members, connected accounts, and email data. Inboxer processes that data to provide the Services on the organization's behalf.
Inboxer separately determines how account, billing, website, security, and service-administration information is processed. If you use Inboxer through an organization, you may need to contact that organization to exercise rights concerning information it controls.
2. Information we collect
Information you provide
- Your name, email address, profile information, and authentication details.
- Workspace names, team membership, roles, invitations, and account preferences.
- Business-domain names, mailbox addresses, and DNS configuration information.
- Billing contact information, subscription details, transaction records, and payment status. Payment-card information may be processed directly by our payment provider rather than stored by Inboxer.
- Communications, support requests, and other information you submit to us.
Email and workspace data
When you connect an email account or use a hosted Inboxer mailbox, we may process:
- Email addresses and contact information.
- Message subjects, bodies, headers, participants, timestamps, and identifiers.
- Threads, folders, labels, read status, stars, assignments, comments, drafts, and mailbox actions.
- Attachments, inline images, and links contained in messages.
- Provider synchronization state, change cursors, delivery information, and error records.
- Provider authorization tokens and permissions required to operate the connected account.
Email content may contain personal information about people who are not Inboxer users. Workspace customers are responsible for having an appropriate basis to collect and process information they place in Inboxer.
Domain and hosted-mail data
- Domain ownership-verification records and nameserver information.
- MX, SPF, DKIM, DMARC, return-path, and related DNS records.
- Domain verification, provisioning, sending, and receiving status.
- Hosted mailbox addresses, message-routing information, delivery events, and bounce or complaint information.
Technical and usage information
- IP address, browser type, device information, operating system, and approximate location derived from an IP address.
- Login activity, session information, pages or features used, and interaction timestamps.
- API requests, synchronization activity, audit events, diagnostics, crash information, and security events.
- Cookie and similar-technology identifiers used for authentication, security, preferences, and, where enabled, service analytics.
Information from other sources
We may receive information from email and identity providers you authorize; domain, DNS, and email-infrastructure providers; authentication, hosting, payment, security, monitoring, and analytics providers; and workspace administrators who invite you or manage your account.
3. How we use information
We use personal information to:
- Create and administer accounts and workspaces.
- Authenticate users and maintain secure sessions.
- Connect, synchronize, display, search, organize, send, receive, and manage email.
- Perform mailbox actions requested by users, including changes that synchronize with connected providers.
- Provision and verify domains, hosted mailboxes, and email-routing records.
- Manage workspace members, invitations, teams, roles, assignments, and audit history.
- Process subscriptions, payments, invoices, and account changes.
- Provide support and respond to communications.
- Detect spam, fraud, abuse, security incidents, and unauthorized access.
- Monitor reliability, diagnose errors, maintain infrastructure, and improve user-facing functionality.
- Comply with legal obligations and enforce our agreements.
Where applicable law requires a legal basis, we generally process information because it is necessary to perform a contract, comply with law, protect legitimate interests such as service security and reliability, or because you have provided consent. You may withdraw consent where processing depends on consent, but doing so does not affect earlier lawful processing.
4. Connected email providers
Inboxer accesses connected email accounts only after a user authorizes the connection. We request permissions needed for enabled features, such as reading and synchronizing messages, sending replies, managing drafts, or applying mailbox actions.
Provider authorization tokens are treated as confidential credentials. Inboxer uses them to operate requested features and does not expose them to other workspace users except where required for authorized workspace functionality.
You may disconnect a provider through Inboxer or revoke access through the provider. Disconnecting stops future access but may not immediately remove information already synchronized into Inboxer. You may separately request or perform deletion of retained Inboxer data.
Google Workspace data
Inboxer's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Inboxer uses Google Workspace data only to provide or improve user-facing Inboxer email features. We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train generalized artificial-intelligence or machine-learning models.
Inboxer personnel do not access Google message content except when the user gives specific permission for support, when access is necessary to investigate security or abuse, when required by law, or in other circumstances permitted by Google's Limited Use requirements.
5. Email images, links, and attachments
Email messages may contain remote images or tracking technologies controlled by the sender. Where supported, Inboxer retrieves remote images through a protected proxy so the sender does not receive a direct request from your browser.
Proxied remote images may be cached temporarily with file-size, content-type, workspace-isolation, and expiration limits. Cached images are removed after their configured expiration period or earlier when operationally necessary.
Inboxer sanitizes supported HTML email content and restricts scripts, forms, embedded frames, and other active content. These measures reduce risk but cannot guarantee that every message, attachment, or external link is safe. Exercise care before opening attachments or visiting links from unknown senders.
6. Automated processing and artificial intelligence
Inboxer may use automated systems for synchronization, routing, spam and abuse prevention, security monitoring, diagnostics, and similar operational functions.
We do not use private email content or Google Workspace API data to train public or generalized AI models. If Inboxer later introduces optional AI features that process email content, we will provide additional disclosures and controls before using email data for those features.
Inboxer does not currently use email content to make decisions that produce legal or similarly significant effects about individuals.
7. How we disclose information
We do not sell personal information or email content. We do not share personal information for cross-context behavioral advertising.
We may disclose information to:
- Service providers: Companies that provide cloud hosting, databases, authentication, payments, email delivery and receiving, domain provisioning, security, monitoring, customer support, or related infrastructure.
- Workspace administrators and members: Information may be visible according to workspace roles, shared mailbox access, assignments, and collaboration settings.
- Connected providers: We exchange data with authorized email, identity, DNS, and domain providers to perform requested actions.
- Professional advisers: Lawyers, accountants, auditors, insurers, and consultants where reasonably necessary.
- Authorities or other parties: When we reasonably believe disclosure is required by law or necessary to protect rights, safety, users, or the Services; investigate fraud or abuse; or respond to lawful process.
- Business transaction participants: In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal requirements.
We require service providers to process information only for contracted purposes and to apply appropriate safeguards.
8. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, maintaining security, complying with law, resolving disputes, and enforcing agreements.
Retention depends on the type of information and how it is used:
- Account and workspace information is generally retained while the account or workspace remains active.
- Connected email data is retained according to workspace settings, synchronization requirements, deletion actions, and provider behavior.
- Messages placed in Inboxer's recycle bin may be permanently removed after 30 days unless restored sooner.
- Proxied remote-image cache entries generally expire after seven days.
- Provider tokens are retained while the connection remains active and are deleted or invalidated when no longer required, subject to secure backup-deletion cycles.
- Billing, transaction, audit, fraud-prevention, and security records may be retained longer when required for legal, accounting, dispute-resolution, or security purposes.
- Backups may retain deleted information for a limited period before being overwritten or securely removed.
Deleting information from Inboxer does not necessarily delete the corresponding information from a connected provider unless the selected Inboxer action is designed to synchronize that deletion.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These may include encryption in transit, encryption or protected storage for sensitive credentials, access controls, workspace separation, audit logging, authentication protections, rate limits, security monitoring, and restricted employee access.
No method of transmission or storage is completely secure. We cannot guarantee absolute security. You are responsible for protecting your credentials, using appropriate account-security features, and promptly reporting suspected unauthorized access.
10. International processing
Inboxer and its service providers may process information in the United States and other countries where privacy laws may differ from those in your location.
Where required, we use recognized safeguards for international transfers, such as adequacy decisions, contractual protections, or other lawful transfer mechanisms.
11. Your privacy rights and choices
Depending on your location and applicable law, you may have the right to:
- Request access to personal information.
- Request correction of inaccurate information.
- Request deletion of information.
- Request a portable copy of certain information.
- Restrict or object to certain processing.
- Withdraw consent where processing relies on consent.
- Opt out of the sale or sharing of personal information, although Inboxer does not currently sell personal information or share it for cross-context behavioral advertising.
- Appeal our response to a privacy request where applicable.
- Lodge a complaint with an appropriate data-protection authority.
You may also update account and workspace information, disconnect connected providers, revoke authorization through provider settings, manage workspace members and permissions, delete messages, mailboxes, or domains through available controls, and control optional cookies through available consent tools or browser settings.
We may need to verify your identity and authority before completing a request. Some rights are subject to exceptions. We will not discriminate against you for exercising applicable privacy rights. If your account is managed by an organization, submit workspace-data requests to that organization first. We may assist the organization in responding.
Authorized agents may submit requests where permitted by law, subject to verification of their authority.
12. Cookies and similar technologies
Inboxer uses cookies and similar technologies required for authentication, security, session management, fraud prevention, and user preferences. We may also use limited analytics technologies to understand service performance and usage.
You can restrict cookies through browser settings, but blocking required cookies may prevent login or other Services from functioning. Where legally required, Inboxer will request consent before using non-essential cookies.
13. Communications
We may send service-related communications, including authentication notices, security alerts, billing messages, synchronization or delivery warnings, policy updates, and support responses. These communications are necessary to operate the Services and may not be optional while you maintain an account.
Marketing communications, if offered, will include an available unsubscribe method. Unsubscribing from marketing does not stop essential service communications.
14. Children's privacy
Inboxer is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information to Inboxer, contact us so we can investigate and take appropriate action.
15. Third-party services
The Services may contain links to third-party websites or integrate with third-party providers. Their privacy practices are governed by their own policies. Inboxer is not responsible for the privacy or security practices of services that it does not control.
16. Changes to this Privacy Policy
We may update this Privacy Policy as the Services, providers, or legal requirements change. We will post the revised policy and update its effective date.
If a change materially affects how we use previously collected personal information, we will provide additional notice or obtain consent when required by law or provider policy.
17. Contact us
To ask a privacy question or submit a privacy request, contact:
- Inboxer legal entity:
- GetInboxer.com
- Privacy email:
- help@getinboxer.com
