Privacy policy

InboxOS Private Limited · Last updated 11 August 2026

InboxOS reads your email and sits in on your meetings, so it is fair to want the details. This page sets out exactly what we process, why, how long we keep it, and who else is involved.

1. Who this covers

This policy applies to InboxOS Private Limited (“InboxOS”, “we”), registered in Bengaluru, India, and to the InboxOS web app and the email, calendar and meeting features it provides.

Where you use InboxOS through an employer, that organization is the data controller for the mailbox content we process on its behalf, and we act as its processor. For your account and billing details we are the controller.

2. What we process

  • Account details. Your name, email address, workspace, and authentication tokens.
  • Mailbox content. With your Google authorization, the messages in your connected mailbox — headers, bodies, attachments metadata, and labels. We read them to categorize and draft, and we write labels and drafts back.
  • Calendar data. Event times, titles, attendees and free/busy status, used for scheduling and to decide which calls to join.
  • Meeting recordings. Audio, video and transcripts of calls that InboxOS joins, plus the summaries and action items generated from them.
  • Usage data. Feature usage, bot-hours consumed, scheduling threads, error logs and diagnostics.
  • Billing data. Plan, seat count and metered usage. Card details go directly to our payment processor; we never store full card numbers.

We do not buy personal data from third parties, and we do not build advertising profiles.

3. What we do with it

  • Sort and label incoming mail, and hold it for batched delivery.
  • Draft replies in your phrasing, for you to review before sending.
  • Answer questions about your mailbox, with sources.
  • Join calls, produce recaps, and create reminders from action items.
  • Coordinate scheduling and place calendar invitations.
  • Operate, secure, debug and bill for the service.

InboxOS never sends an email on your behalf without you approving it, with the single exception of scheduling messages you have explicitly delegated to the scheduling agent on a given thread.

4. AI processing and model training

Categorization, drafting, summaries and mailbox Q&A are performed by large language models. To do that, the relevant email or transcript text is sent to our model provider for the duration of the request.

We do not use your mailbox content, transcripts or drafts to train models — not our own and not our providers’. We contract for zero data retention with our model provider where that option exists, so prompt content is not persisted on their side after the response is returned.

Model output can be wrong. Drafts and summaries are suggestions to review, not statements of fact, and you stay responsible for anything you send.

5. Google user data

InboxOS’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Gmail and Calendar data is used only to provide the features described above; it is not transferred to others except as needed to provide those features, to comply with law, or as part of a merger or acquisition; it is not used for advertising; and no human reads it except with your explicit permission, for security purposes, or where required by law.

You can revoke our access at any time from your Google account permissions, which stops all further processing.

6. Meeting recording and consent

Recording laws vary, and some jurisdictions require every participant to consent. The meeting bot appears in the participant list under a name you control, and you can set rules for which meetings it joins.

You are responsible for obtaining the consent your jurisdiction requires before recording a call. If you are unsure, announce the recording at the start of the meeting.

7. How long we keep it

  • Meeting video: 7 days on Starter, 30 days on Pro, 90 days on Team, and a negotiated window on Enterprise.
  • Transcripts and summaries: 90 days on Starter, 1 year on Pro, 2 years on Team.
  • Mailbox content: we hold derived data (labels, categories, embeddings and drafts) for as long as your account is active. Held mail waiting on a delivery slot stays in your mailbox — it is not copied out to be stored by us.
  • Logs and diagnostics: up to 90 days.
  • Billing records: as long as tax and accounting law requires.

Close your account and we delete or irreversibly anonymize the rest within 30 days, other than backups which age out within a further 90 days.

8. Who else touches your data

We use the following subprocessors. We do not sell personal data, and we do not share it for anyone else’s marketing.

ProviderPurposeData involved
RenderApplication hosting, background workers, PostgreSQL database and RedisAll service data
OpenAICategorization, draft generation, summaries, mailbox Q&AEmail content and meeting transcripts, as needed per request
Recall.aiJoining calls, recording, and producing transcriptsMeeting audio, video, and transcripts
Amazon Web Services (S3)Storage of meeting recordings and uploaded filesMeeting audio and video, and files you upload for drafting
RazorpaySubscription billingBilling contact and payment details (we never see full card numbers)

We may also disclose data where legally compelled, and will tell you unless we are prohibited from doing so.

9. Your rights

Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to processing, or port it elsewhere. You can also withdraw consent by disconnecting your Google account.

Email privacy@inboxhq.com and we will respond within 30 days. If you are in the EU or UK you can complain to your local supervisory authority.

11. Security

Data is encrypted in transit and at rest. Access to production systems is restricted, logged, and requires multi-factor authentication. OAuth tokens are stored encrypted and are never exposed to the browser.

No system is perfect. If we suffer a breach affecting your data we will notify you and any required regulator without undue delay.

12. International transfers

Your data is processed in more than one country. Application hosting, the database and the job queue run in Singapore. Meeting recording and transcription run in the United States, as does the AI processing described in section 4. Billing is processed in India. The subprocessor table in section 8 names who operates each.

By using InboxOS you accept that your data is processed in these locations.

13. Cookies

We use a small number of cookies and equivalent local storage, and we do not use advertising or cross-site tracking cookies.

  • Strictly necessary: session and authentication, so you stay signed in. These cannot be turned off.
  • Preferences: remembering choices such as your onboarding progress and delivery settings.
  • Analytics: aggregate product usage, so we can see which features are actually used. Set only with your consent where consent is required.

Your browser can block or delete cookies, though blocking the strictly necessary ones will stop sign-in from working.

14. Children

InboxOS is a workplace tool and is not intended for anyone under 16. We do not knowingly collect their data, and will delete it if we learn we have.

15. Changes

We will update this page when our practices change and move the “last updated” date. For changes that materially affect your rights we will email you at least 30 days beforehand.

16. Contact

Privacy questions: privacy@inboxhq.com. Anything else: support@inboxhq.com. We are registered in Bengaluru, India.

See also our terms of service.