Draft, not yet reviewed by a lawyer.
Privacy
Last updated: [last updated date]
Inbox Atlas shows every sender in your Gmail or Outlook mailbox as a Map and a List, and, if you buy it, cleans the mailbox up with your approval. This page says, in plain words, what it reads, what it keeps, where, who else sees it, and how to delete everything.
In short
- Inbox Atlas reads message details such as the sender, date, subject and the short preview your provider shows. It never reads the body of a message or its attachments.
- It keeps summaries per sender. Subjects and previews are cleared once they have been used, except for the newest few messages from each sender.
- It never stores message bodies, raw messages or attachments on its servers.
- Disconnecting from Settings deletes everything within 24 hours. Backups stay in your own storage.
What we read from your mailbox
For each message, Inbox Atlas reads:
- the sender's address and name, and the recipients (To and Cc);
- the date;
- the subject, and the short preview your mail provider shows (about 150 characters);
- its labels or folders, whether it is unread, and whether it is in your Inbox;
- mailing-list markers (the List-Unsubscribe, List-Id and Precedence headers) and whether the sender passed your provider's authentication checks;
- whether it has an attachment (not the attachment itself), and its size;
- whether you sent it. Mail you sent is not counted in your Map; it only marks the senders you have written to.
It never reads the body of a message or its attachments.
The backup. When you run a cleanup, the messages about to go to Trash are copied in full, as a standard .mbox file with a .csv index, from your mail provider into your own Google Drive or OneDrive. They pass through our servers on the way without being read, analyzed or kept.
What we keep, and for how long
- Sender summaries: for each sender, the counts, dates, share opened and share of mass mail, its part of life and its one-line description. Kept until you disconnect.
- Per-message records: the details listed above. Subjects and previews are kept only until classification and descriptions have used them, plus those of the newest few messages from each sender. The other details are kept until you disconnect.
- The shared organization directory: which part of life an organization's domain belongs to (for example, that a bank's domain is Finance). It is shared by everyone who uses Inbox Atlas and holds no link to you or to any account.
- The undo log: what each cleanup changed, so it can be undone. Kept for 30 days.
- Sign-in tokens: the tokens Google or Microsoft issue so Inbox Atlas can reach your mailbox and your backup folder, encrypted before they are stored.
- Account and billing: your email address, your name as your provider gives it, and your plan. Card details go straight to Stripe and never reach us.
Our logs record ids and counts, never subjects or previews.
Where it is kept
In a database in North America, hosted by Render. The pages and the service that reads your mailbox run there too.
Who else sees your data
| Who | What they get | Why |
|---|---|---|
| Anthropic, our AI processor | Subjects and previews, grouped by sender | To write each sender's one-line description and to sort organizations into parts of life, under terms that forbid training on your data |
| Stripe | Your email address and your payment | To take payments; card details go to Stripe directly |
| Resend | Your email address and the emails we send you | To deliver our emails, such as the note that your Map is ready and Upkeep's weekly proposal |
| Google or Microsoft | What their services already hold | They are your mail provider and hold your backups |
Sender-level subjects and previews go to the AI processor and nowhere else. We do not sell your data, and we do not use it for advertising.
Google API Services: Limited Use
Inbox Atlas's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace APIs (Gmail and Google Drive) will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
In practice: Inbox Atlas uses data from your Gmail and Google Drive only to show you your Map and List and to run the cleanup and Upkeep you ask for. It does not use that data for advertising, does not sell it, and does not use it to train general-purpose models. People at Inbox Atlas do not read it, unless you ask them to, or it is needed for security or to comply with the law.
How to disconnect and delete everything
In Settings, choose Disconnect and delete everything. It stops every job, revokes Inbox Atlas's access to your mailbox and storage, and deletes all the data Inbox Atlas holds about you within 24 hours. Backups stay in your own Drive or OneDrive; they are yours, and you can delete them there. You can also remove Inbox Atlas's access at any time from your Google or Microsoft account settings.
Cookies
One cookie keeps you signed in. There are no advertising or analytics cookies, and no third-party scripts on any page. Your browser also remembers your light or dark choice and your Map or List choice, on your device only.
Your rights
You can ask to see, correct or delete what Inbox Atlas holds about you by writing to [contact email]. [How to complain to a regulator, and response times: to be settled.]
Governing law
[Governing law: to be confirmed. Inbox Atlas is based in Canada and intends to follow the Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA).]
Changes to this page
[How changes are announced: to be settled.]
Contact
[contact email]