Privacy policy
InboxOS Private Limited · Last updated 11 August 2026
InboxOS reads your email and sits in on your meetings, so it is fair to want the details. This page sets out exactly what we process, why, how long we keep it, and who else is involved.
1. Who this covers
This policy applies to InboxOS Private Limited (“InboxOS”, “we”), registered in Bengaluru, India, and to the InboxOS web app and the email, calendar and meeting features it provides.
Where you use InboxOS through an employer, that organization is the data controller for the mailbox content we process on its behalf, and we act as its processor. For your account and billing details we are the controller.
2. What we process
- Account details. Your name, email address, workspace, and authentication tokens.
- Mailbox content. With your Google authorization, the messages in your connected mailbox — headers, bodies, attachments metadata, and labels. We read them to categorize and draft, and we write labels and drafts back.
- Calendar data. Event times, titles, attendees and free/busy status, used for scheduling and to decide which calls to join.
- Meeting recordings. Audio, video and transcripts of calls that InboxOS joins, plus the summaries and action items generated from them.
- Usage data. Feature usage, bot-hours consumed, scheduling threads, error logs and diagnostics.
- Billing data. Plan, seat count and metered usage. Card details go directly to our payment processor; we never store full card numbers.
We do not buy personal data from third parties, and we do not build advertising profiles.
3. What we do with it
- Sort and label incoming mail, and hold it for batched delivery.
- Draft replies in your phrasing, for you to review before sending.
- Answer questions about your mailbox, with sources.
- Join calls, produce recaps, and create reminders from action items.
- Coordinate scheduling and place calendar invitations.
- Operate, secure, debug and bill for the service.
InboxOS never sends an email on your behalf without you approving it, with the single exception of scheduling messages you have explicitly delegated to the scheduling agent on a given thread.
4. AI processing and model training
Categorization, drafting, summaries and mailbox Q&A are performed by large language models. To do that, the relevant email or transcript text is sent to our model provider for the duration of the request.
We do not use your mailbox content, transcripts or drafts to train models — not our own and not our providers’. We contract for zero data retention with our model provider where that option exists, so prompt content is not persisted on their side after the response is returned.
Model output can be wrong. Drafts and summaries are suggestions to review, not statements of fact, and you stay responsible for anything you send.
5. Google user data
InboxOS’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Gmail and Calendar data is used only to provide the features described above; it is not transferred to others except as needed to provide those features, to comply with law, or as part of a merger or acquisition; it is not used for advertising; and no human reads it except with your explicit permission, for security purposes, or where required by law.
You can revoke our access at any time from your Google account permissions, which stops all further processing.
6. Meeting recording and consent
Recording laws vary, and some jurisdictions require every participant to consent. The meeting bot appears in the participant list under a name you control, and you can set rules for which meetings it joins.
You are responsible for obtaining the consent your jurisdiction requires before recording a call. If you are unsure, announce the recording at the start of the meeting.
7. How long we keep it
- Meeting video: 7 days on Starter, 30 days on Pro, 90 days on Team, and a negotiated window on Enterprise.
- Transcripts and summaries: 90 days on Starter, 1 year on Pro, 2 years on Team.
- Mailbox content: we hold derived data (labels, categories, embeddings and drafts) for as long as your account is active. Held mail waiting on a delivery slot stays in your mailbox — it is not copied out to be stored by us.
- Logs and diagnostics: up to 90 days.
- Billing records: as long as tax and accounting law requires.
Close your account and we delete or irreversibly anonymize the rest within 30 days, other than backups which age out within a further 90 days.
9. Your rights
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to processing, or port it elsewhere. You can also withdraw consent by disconnecting your Google account.
Email privacy@inboxhq.com and we will respond within 30 days. If you are in the EU or UK you can complain to your local supervisory authority.
10. Legal bases (EU and UK)
- Contract: processing your mail, calendar and meetings to deliver the service you signed up for.
- Legitimate interests: security, abuse prevention, debugging and service improvement.
- Consent: optional integrations, and meeting recording where consent is the applicable basis.
- Legal obligation: tax, accounting and lawful requests.
11. Security
Data is encrypted in transit and at rest. Access to production systems is restricted, logged, and requires multi-factor authentication. OAuth tokens are stored encrypted and are never exposed to the browser.
No system is perfect. If we suffer a breach affecting your data we will notify you and any required regulator without undue delay.
12. International transfers
Your data is processed in more than one country. Application hosting, the database and the job queue run in Singapore. Meeting recording and transcription run in the United States, as does the AI processing described in section 4. Billing is processed in India. The subprocessor table in section 8 names who operates each.
By using InboxOS you accept that your data is processed in these locations.
14. Children
InboxOS is a workplace tool and is not intended for anyone under 16. We do not knowingly collect their data, and will delete it if we learn we have.
15. Changes
We will update this page when our practices change and move the “last updated” date. For changes that materially affect your rights we will email you at least 30 days beforehand.
16. Contact
Privacy questions: privacy@inboxhq.com. Anything else: support@inboxhq.com. We are registered in Bengaluru, India.
See also our terms of service.