Trust Center
Everything you need to know about how TheInboxPilot handles your data and what controls you have.
What Data We Access
When you connect your Gmail account, TheInboxPilot accesses the following data through Google’s Gmail API:
gmail.modifyRead, organize, and manage your inbox- Message metadata: sender, recipient, subject, date, and labels (Inbox, Spam, Promotions, Social, Updates, Forums, Important, Starred, Unread)
- User-selected actions to mark as read, star, move from Spam to Inbox, or move to Trash
Powers: Gmail statistics, message review, and user-selected message actions
gmail.sendSend emails on your behalf- Ability to send replies from your Gmail account when you explicitly approve them
- Replies appear in your Sent folder with your identity
Powers: User-approved templated replies
Why We Need Each Permission
| Feature | Scope Required | Why It’s Needed |
|---|---|---|
| Gmail Statistics | gmail.modify | Reads Gmail profile and label counts for the dashboard. |
| Message Review | gmail.modify | Reads recent Inbox or Spam message metadata. It does not request message bodies. |
| Message Actions | gmail.modify | Applies the mark-read, star, move-to-Inbox, or move-to-Trash action that you select. |
| Templated Replies | gmail.send | Sends a reply through your Gmail account after you preview and approve it. |
Data Retention
- Active account: We retain your data only while your TheInboxPilot account is active.
- After disconnection: A successful disconnect from Settings revokes Google access and immediately deletes the local account and associated data.
- Activity log: Activity log entries are retained for the life of your account. After deletion, they are removed along with all other data.
How to Revoke Access
You can stop TheInboxPilot from accessing your Gmail account at any time:
- From TheInboxPilot: Go to Settings > Disconnect Account. A successful disconnect revokes Google access and immediately deletes the local account data.
- From Google: Visit myaccount.google.com/permissions, find TheInboxPilot, and click Remove Access.
Either method stops Gmail API access. Removing access only from Google does not delete the local TheInboxPilot account, so use Settings or contact support if you also want the local data deleted.
Data Encryption
- All data in transit is encrypted using Transport Layer Security (TLS).
- OAuth access tokens and refresh tokens are encrypted at rest using AES-256-GCM.
- Other account data is stored in a SQLite database with filesystem permissions restricted to the application account.
- We do not sell, rent, or trade your data. Infrastructure providers process data only as needed to operate the service.
- We do not use your data for advertising or marketing.
Google API Compliance
TheInboxPilot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
For questions about data handling, security, or to exercise your data rights:
Email: support@theinboxpilot.in