Privacy Policy
Effective August 15, 2026 · How Inbox Distro collects, uses, shares, retains, and protects personal information.
1. Scope and roles
This policy covers the Inbox Distro website, subscription service, customer portal, support, and related communications. Inbox Distro controls account, billing, website, and support information. For email messages and contacts supplied by a customer, that customer is the controller and Inbox Distro acts as its service provider or processor.
2. Information we collect
- Accounts: names, business names, email addresses, roles, time zones, authentication records, and preferences.
- Mailbox and message metadata: mailbox addresses, OAuth authorization data or protected connection credentials, sender and recipient addresses, subjects, timestamps, message identifiers, rules, assignments, forwarding results, tags, and delivery diagnostics.
- Transient email processing: Inbox Distro temporarily accesses message bodies, headers, and attachments in memory only as needed to evaluate rules, apply customer-requested modifications, and forward a message. Inbox Distro does not retain those bodies, full headers, attachments, or .eml copies after processing.
- Billing: plan, invoice, subscription, payment status, and Stripe identifiers. Complete card numbers are processed by Stripe and are not stored by Inbox Distro.
- Technical usage: IP address, browser and device details, session activity, security logs, service health, API activity, and diagnostics.
- Analytics: consented page views, referral sources, approximate location, device data, and interactions collected through Google Analytics.
- Support: messages, screenshots, attachments, and support communications submitted directly to support.
3. How we use information
We use information to provide and secure accounts; connect mailboxes; transiently process, route, modify, and forward messages according to customer instructions; maintain message metadata and delivery analytics; provide reports and APIs; process subscriptions; send service communications; prevent abuse; investigate failures; provide support; improve performance; and comply with law. We do not sell customer email content, use it to build advertising profiles, or retain full mailbox messages on Inbox Distro servers.
4. Legal bases
Where a legal basis is required, processing relies on contract performance, legitimate interests in operating and securing the service, legal obligations, or consent for optional analytics and advertising technology. Consent can be withdrawn through the site privacy choices.
5. Service providers and disclosures
We use providers needed for hosting, infrastructure, customer-selected mailboxes, Stripe payments, Resend system email, consented Google analytics and marketing, monitoring, and professional services. Providers receive only access reasonably needed for their function. Information may also be disclosed for valid legal process, protection against fraud or security incidents, or a business transaction subject to appropriate safeguards.
6. Google API data and Limited Use
Inbox Distro’s use and transfer to any other application of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Inbox Distro does not use, transfer, or sell raw, aggregated, anonymized, or derived Google Workspace API data to create, train, or improve generalized or foundational artificial-intelligence or machine-learning models. Inbox Distro does not send Google Workspace API data to third-party AI or machine-learning services. The production service does not integrate an AI/ML model, model gateway, or model hub for processing Google mailbox data.
7. Customer responsibilities
Customers must have authority to connect every mailbox and process its messages, contacts, employees, and personal information. Customers are responsible for required notices, consent, retention instructions, permissions, and privacy requests concerning their email data.
8. Retention and deletion
Inbox Distro does not retain full email bodies, full headers, attachments, or .eml copies in its production database, file storage, exports, or backups. Message metadata, routing decisions, delivery results, account configuration, audit history, fraud-prevention records, billing records, and support submissions are retained as needed to provide and secure the service. Administrators may request an export or verified account deletion. Deleted metadata may remain in protected backups for up to 14 days. Billing, security, and transaction records may be retained longer where reasonably necessary or legally required.
9. Security and incidents
Safeguards include encrypted transport, encrypted and revocable OAuth tokens, mailbox-specific authorization where supported, role-based access, session controls, access and error logs, backups, and monitoring. Inbox Distro requests only the mailbox permissions needed to read, organize, and forward customer-selected mail. Customers can revoke a connected mailbox at the provider or in Inbox Distro. No system is completely secure. Customers should use strong unique passwords, enable MFA, limit administrative and mailbox access, review forwarding rules, and promptly report suspected compromise. If we confirm a security incident affecting customer data, we will investigate, contain, remediate, and notify affected customers or authorities when required by applicable law.
10. Privacy rights
Depending on location, people may have rights to know, access, correct, delete, restrict, or obtain a copy of personal information, and to opt out of certain sharing or targeted advertising. Inbox Distro does not sell personal information. Requests about data controlled by a customer should be sent to that customer. Other requests may be sent to support@inboxdistro.com. We may verify identity and authority.
11. International use, children, and changes
The service is operated from Utah, United States, and providers may process information in other locations. Inbox Distro is a business service and is not directed to children under 13. Material policy changes will be posted and, when appropriate, communicated to account administrators.
12. Contact
Inbox Distro is operated in Utah, United States. Privacy questions, rights requests, and security reports may be sent to support@inboxdistro.com. We will respond within the period required by applicable law.