Privacy Policy
Effective June 14, 2026
InboxBriefs ("we") protects your personal information. This policy explains what we collect, why, how we protect it, who we share it with, and the rights you may exercise.
The service is operated from the province of Quebec, Canada. We handle your information in accordance with Quebec's Law 25, Canada's PIPEDA and, where it applies, the EU's GDPR.
1. Controller and contact
InboxBriefs is responsible for your personal information. For any question, access request or complaint, write to privacy@inboxbriefs.com.
2. Information we collect
We collect only what the service needs:
- Account: your email address and, where applicable, your name. Authentication runs through Clerk; we never store your password.
- Gmail connection: the account address, a Google identifier and OAuth tokens granting read-only access (gmail.readonly scope), encrypted before being stored.
- Email content: read temporarily to produce a summary. We do not retain your emails; only the generated summaries are stored, encrypted.
- Summaries and conversations: the summaries, the items ranked by priority and your exchanges with the assistant, all encrypted at rest.
- Billing: for the Pro plan, payment is processed by Stripe. We do not store your card number, only a Stripe customer identifier and your subscription status.
- Technical data: logs, IP address, device and browser type and timestamps — for security and the proper operation of the service.
3. Purposes and legal bases
We use your information to:
- Provide the service: connect to Gmail, analyze, summarize and deliver. Basis: performance of our agreement.
- Service communications: deliver summaries and important notices (security, billing, account reconnection). Basis: contract and consent.
- Process payments: manage the Pro subscription and billing. Basis: contract and legal obligations.
- Maintain security: detect and prevent fraud and abuse. Basis: legitimate interest.
- Comply with legal obligations: meet applicable requirements and lawful requests from authorities.
You may withdraw your consent at any time (see “Your rights”). Withdrawal is not retroactive and may limit your use of the service.
4. Gmail access and limited use
InboxBriefs requests only the gmail.readonly scope: we can never send, delete or modify your emails.
Our use of Gmail API data complies with the Google API Services User Data Policy, including its Limited Use requirements: this data is used solely for user-facing features (sorting and summarizing your emails). It is never sold, used for advertising or transferred for any other purpose. No human reads your emails, except with your explicit consent, for security reasons or to comply with the law.
5. Processing by artificial intelligence
Summaries and assistant responses are generated by a model provided by Anthropic. The content needed is sent to its API transiently. In accordance with Anthropic's terms, this data is not used to train its models.
6. Data retention
We retain your information for as long as your account is active and it remains necessary for the purposes above. Email content is not retained: it is processed and then discarded; only the encrypted summary is kept.
When you delete your account, all associated data (connected Gmail accounts, rules, summaries, conversations) is permanently erased within minutes. Certain data required by law (for example billing records) may be retained by the relevant providers for the required period.
7. Information security
We protect your information with technical and organizational measures:
- Application-level encryption: Gmail tokens and sensitive content (summaries, analyzed items, assistant messages, rules) are encrypted with AES-256-GCM before being stored.
- Encryption in transit: all communications are protected by HTTPS/TLS.
- Access isolation: every query is filtered by user and the database enforces row-level security.
- Least privilege: access to systems is restricted to what is strictly necessary.
No method is perfectly secure. In the event of an incident presenting a risk of serious harm, we will take the required measures and notify you in accordance with the law.
8. Service providers
We rely on trusted providers that process information on our behalf, on our instructions. We never sell your personal information.
| Provider | Role | Processing location |
|---|---|---|
| Clerk | Authentication and identity management | United States |
| Gmail access (OAuth, read-only) | United States | |
| Anthropic | AI summary generation | United States |
| Stripe | Payment processing | United States / international |
| Cloud infrastructure providers | Hosting, database, email delivery and job processing | United States |
9. Transfers outside Quebec
Some providers process or store information outside Quebec, notably in the United States. Before any such transfer, we assess the factors required by law and require contractual commitments ensuring an adequate level of protection. By using the service, you understand that your information may be processed in those jurisdictions.
10. Your rights
Subject to applicable law, you may:
- Access the information we hold about you and obtain a copy;
- Correct information that is inaccurate or incomplete;
- Delete your account and associated information from the “Account” page;
- Withdraw your consent or disconnect a Gmail inbox at any time, which immediately revokes our access;
- Request portability of the computerized information you provided to us.
To exercise these rights, write to privacy@inboxbriefs.com. If your rights have not been respected, you may file a complaint with the Commission d'accès à l'information du Québec.
11. Cookies
InboxBriefs uses only essential cookies: the authentication session, cross-site request forgery (CSRF) protection and remembering your preferences (such as language). No advertising or third-party tracking cookies.
12. Minors' information
The service is not directed to persons under 14, and we do not knowingly collect their information. If you believe this has happened, please write to us so we can delete it.
13. Changes to this policy
We may update this policy. The effective date at the top of the page is then updated and, for significant changes, we will notify you by email or through an in-app notice.
14. Contact us
For any question about this policy, write to privacy@inboxbriefs.com. InboxBriefs is operated from the province of Quebec, Canada.