Privacy Policy
Effective August 23, 2026
Inbox Control ("we," "us") is a Gmail cleanup tool operated by its founder in Florida, USA. This policy explains exactly what we access, what we store, and what we will never do. It is written to be read, not skimmed.
What we access in your Gmail
- Metadata only: sender, subject line, date, Gmail labels and categories, and read/unread status.
- Never message content. We connect using Google's metadata-only Gmail permission, which makes message bodies and attachments technically inaccessible to us. This is enforced by Google, not merely promised by us.
- If you separately approve the mark-read permission, we use it for exactly two operations: removing the unread label from messages you approved, and restoring it if you use Undo. We never use it to read, send, delete, archive, or move mail.
What we store
- Your account basics: email address, name, and profile picture from Google sign-in.
- An encrypted copy of the credential Google issues us (AES-256-GCM), so features you enabled, such as nightly clean, can run without you being signed in. Deleted when you disconnect.
- Your protected senders, safety settings, and automation choices.
- Your activity record: a plain-English log of scans, actions, and setting changes.
- For undo: the Gmail message IDs (not contents) each action touched, kept 31 days, then deleted automatically.
Data is stored with our database provider (Neon, hosted on AWS in the United States) and our hosting provider (Vercel). We do not use analytics trackers or advertising pixels on the app.
What we never do
- Never read, store, or process the content of your email.
- Never delete, trash, or archive your messages. The capability does not exist in our system.
- Never sell, rent, or share your data with third parties for their purposes.
- Never use your data to train AI models.
Google API Services: Limited Use disclosure
Inbox Control's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In short: Google user data is used only to provide the features you see, never for advertising, and never transferred except as necessary to provide those features, comply with law, or as part of a merger or acquisition with equivalent protections.
Disconnecting and deleting your data
- Disconnect anytime from within the app. Disconnecting revokes our access with Google itself and deletes our stored credential.
- Delete your account and all data in-app: open Settings → Delete account & all data, type DELETE, and confirm. This immediately revokes our Google access and permanently erases your account, settings, protected senders, activity record, and undo records from our servers. Your Gmail messages are never touched. If you prefer, you can also email gamarkham@gmail.com from your connected address and we will delete everything within 48 hours.
- You can also revoke our access at any time at myaccount.google.com/permissions.
Security
All traffic is encrypted in transit (TLS). Stored credentials are encrypted at rest with AES-256-GCM. Every mailbox-changing request requires a signed, single-use, time-limited approval generated by our servers. Actions are limited server-side to removing or restoring the unread label. Other Gmail operations have no code path.
Changes and contact
If this policy changes materially, we will note it here with a new effective date and inform connected users in the app. Questions: gamarkham@gmail.com.