← Back to InboxForge
Privacy Policy
Last updated: [fill in date]
Before you publish this: this is a starting draft, not legal advice. It's written for what InboxForge's code actually does today, but you (the operator) are the "data controller" for real users — have this reviewed by a lawyer familiar with your jurisdiction (and GDPR/CCPA if you'll have EU or California users) before relying on it, and especially before submitting it as part of Google's OAuth verification. Replace every bracketed placeholder below with your real details.

This Privacy Policy explains what data [Your Business/App Name] ("InboxForge," "we," "us") collects through the InboxForge application (the "Service"), how it's used, and how you can control or delete it.

1. What we collect

When you connect your Google account, InboxForge requests the following access, and stores only what's needed to provide the features you use:

  • Gmail messages and metadata (subject, sender, snippet, body) — used to classify emails, draft/send replies you approve, and power search inside the app.
  • Gmail send access — used only to send replies and campaign emails you've configured or approved; InboxForge never sends anything without either your explicit approval or automation settings you've turned on yourself.
  • Google Calendar events (read-only) — displayed inside the app; never modified.
  • Your basic Google profile (name, email address, profile photo) — used to identify your account.
  • Data you enter directly — contacts, deals, automation rules, campaign content, and business-profile text you type into the app.

2. How we use it

Email content is sent to Google's Gemini API for AI classification and reply drafting. We do not use your data to train any AI model, and we do not sell, rent, or share your data with data brokers or advertisers.

3. Data isolation between accounts

InboxForge is multi-tenant: every account's emails, contacts, deals, and settings are stored under that account's own identifier and are never visible to, or accessible by, any other account on this platform — including other InboxForge users. Only the administrator of this specific installation can see aggregate, non-content statistics (such as how many emails a user has synced) for operational purposes.

4. Where data is stored

Data is stored in a database operated by [Your Business/App Name], hosted on [your cloud provider, e.g. Google Cloud]. OAuth tokens are encrypted at rest. Access to the underlying server is limited to [you / your team].

5. Data retention and deletion

We retain your data for as long as your account is active. You can permanently delete your account and all associated data at any time from Settings → Danger Zone inside the app, or by emailing [contact email] — we will delete it within 30 days of a verified request.

6. Third-party services

InboxForge uses the Google Gmail API, Google Calendar API, and Google's Gemini API to provide its features. Your use of InboxForge is also subject to Google's own Privacy Policy. Google's limited use requirements apply: InboxForge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Your rights

You can access, correct, export, or delete your data at any time from within the app, or by contacting us at [contact email].

8. Changes to this policy

We'll update the date at the top of this page when this policy changes. Material changes will be communicated to active users.

9. Contact

[Your Business/App Name] — [contact email]