Privacy Policy
Last updated: July 10, 2026
TheInboxPilot (“we,” “our,” or “us”) provides email organization tools that help users manage their Gmail inboxes. This Privacy Policy explains how we handle data when you connect your Google account to TheInboxPilot.
Data We Access
When you connect your Google account to TheInboxPilot, we access the following data through the Gmail API:
- Gmail message metadata: sender, recipient, subject, date, and message labels (inbox, spam, promotions, social, updates, forums, important, starred, unread).
The current message review and statistics features do not request message body content. Reply content is supplied by you. We do not access emails belonging to anyone other than the user who connected their account.
How We Use Data
- To display Gmail statistics and recent Inbox or Spam message metadata.
- To apply the message action you select, such as marking a message as read, starring it, moving it to Inbox, or moving it to Trash.
- To store your rules, templates, preferences, and activity records.
- To send replies from your Gmail account when you explicitly approve them through the dashboard.
Data Storage and Security
- All data is encrypted in transit using Transport Layer Security (TLS).
- OAuth access tokens and refresh tokens are encrypted at rest using AES-256-GCM.
- Other account data is stored in a SQLite database with filesystem permissions restricted to the application account.
- We do not sell, rent, or trade your data. Infrastructure providers process data only as needed to operate the service.
- We do not use your data for advertising, marketing, or any purpose unrelated to providing the TheInboxPilot service.
Google API Services User Data Policy
TheInboxPilot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This means:
- We use Google user data only to provide and improve the TheInboxPilot service.
- We do not transfer Google user data to third parties except as necessary to provide the service (for example, our infrastructure providers), and only after ensuring those parties comply with the same restrictions.
- We do not use Google user data for advertising purposes.
- We do not allow humans to read user data unless: (a) we have the user’s explicit consent; (b) it is necessary for security purposes (such as investigating abuse); or (c) it is necessary to comply with applicable law.
Your Control
- You can view what data is associated with your TheInboxPilot account at any time through the dashboard.
- You can request a copy of your data, correction of inaccurate data, or deletion of your data by contacting support@theinboxpilot.in. We respond to all requests within 30 days.
- You can revoke TheInboxPilot’s access to your Google account at any time through your Google Account permissions page. Revoking access stops Gmail API access but does not automatically delete the local TheInboxPilot account.
- You can revoke Google access and delete the local TheInboxPilot account from the Settings page in the dashboard.
Data Retention
We retain your data while your local TheInboxPilot account is active. A successful disconnect from Settings revokes Google access and immediately deletes the local user record and associated activity, rules, templates, preferences, and send-request records. Removing access only from Google does not notify the application to delete local data, so you must also use Settings or contact support to request deletion.
Changes to This Policy
Changes to this Privacy Policy will be published on this page with an updated effective date.
Contact
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: support@theinboxpilot.in