Privacy Policy

Last updated: 10/2/2022

The privacy of your data—and it is your data, not ours!—is a big deal to us. In this policy, we lay out: what data we collect and why; how your data is handled; and your rights with respect to your data. We promise we never sell your data: never have, never will.

What we collect and why

Our guiding principle is to collect only what we need. Here’s what that means in practice:

Identity & access

We only ask for personal information when we truly need it to provide the service to you. We collect it by fair and lawful means, with your knowledge and consent. We also let you know why we're collecting it and how it will be used.

When you sign up for an Imbox account, we use only the email address as a unique identifier about you. No other info is needed, as login is handled by your email's provider OAuth system.

We’ll never sell your personal information to third parties, and we won’t use your name or email in marketing statements without your permission either.

Emails and content

We do not store content of any of your emails on our servers in any form. When you connect your email account, we ask Gmail or Outlook for access to only email metadata. Email contents is not needed, accessed or stored.

After you connect your email account, we generate reports and subscriptions lists while you have our website open. As soon as you close your browser, Imbox closes the connection to Gmail/Outlook.

That said, we do store specific metadata of your emails in order to identify if you have unsubscribed from a subscription previously. This is limited only to recipient and sender email addresses of the subscription emails that you have unsubscribed from, as well as timestamp.

Billing information

If you sign up for an Imbox paid plan, you will be asked to provide your payment information and billing address. Credit card information is submitted directly to our payment processor, Stripe, and doesn’t hit our servers. We store a record of the payment transaction, including the last 4 digits of the credit card number, for purposes of account history, invoicing, and billing support. We store your billing address so we can charge you for service, calculate any sales tax due, send you invoices, and detect fraudulent credit card transactions.

Website interactions

We collect information about your browsing activity for analytics and statistical purposes such as conversion rate testing and experimenting with new product designs. This includes, for example, your browser and operating system versions, your IP address, which web pages you visited and how long they took to load, and which website referred you to us. If you have an account and are signed in, these web analytics data are tied to your IP address and user account until your account is no longer active.

Voluntary correspondence

When you email Imbox with a question or to ask for help, we keep that correspondence, including your email address, so that we have a history of past correspondence to reference if you reach out in the future.

When we access or share your information

To provide products or services you’ve requested. We use third party subprocessors, such as cloud computing providers and analytics software, to run Imbox (the service). We establish GDPR-compliant data processing agreements with each subprocessor, extending GDPR safeguards everywhere personal data is processed.

No human looks at your content except for limited purposes with your express permission, for example, if an error occurs that stops an automated process from working and requires manual intervention to fix. These are rare cases, and when they happen, we look for root cause solutions as much as possible to avoid them recurring.

To help you troubleshoot or squash a software bug, with your permission. If at any point we need to access your content to help you with a support case, we will ask for your consent before proceeding.

What happens when you delete your account

If you choose to cancel your account, your content will immediately be removed from our servers. All email reports, subscription metadata and external account tokens will be purged, with no option to recover them.

Changes & questions

We may update this policy as needed to comply with relevant regulations and reflect any new practices. Whenever we make a significant change to our policies, we will refresh the date at the top of this page and take any other appropriate steps to notify users.

Have any questions, comments, or concerns about this privacy policy, your data, or your rights with respect to your information? Please get in touch by emailing us at privacy@imbox.app and we’ll be happy to try to answer them!