Security
InboxBriefs is built from the ground up to protect your data. Here's exactly how.
InboxBriefs cannot send, delete or modify your emails. Access is strictly limited to reading, through the official authorization flow of each provider (OAuth for Gmail, Outlook and Yahoo, read-only IMAP for private servers).
OAuth tokens, IMAP passwords and summary content are encrypted at rest with AES-256-GCM. Even in the event of unauthorized access to our database, the data remains unreadable.
Your emails never touch our database. InboxBriefs reads them in memory to generate the summary, then forgets them. Only the summary is kept, and you can delete it anytime.
You can disconnect any inbox from your dashboard. The OAuth token is revoked immediately and access stops. For IMAP connections, the encrypted password is removed from our system.
No email is ever sold or shared with third parties. InboxBriefs uses only strictly necessary cookies for the service to work. You can delete your account and all your data at any time.
Beyond principles, here is what concretely happens to your data: who processes it, for how long, and your recourse.
Trusted providers process some data on our behalf, under our instructions. We never sell your personal information. The complete, up-to-date list lives in the privacy policy:
| Provider | Role | Processing location |
|---|---|---|
| Clerk | Authentication and identity management | United States |
| Google / Microsoft / Yahoo | Mailbox access (OAuth, read-only) | United States |
| Anthropic | AI summary generation (data not used for training) | United States |
| Stripe | Payment processing (we never see your card) | United States / international |
| Cloud infrastructure | Hosting, database, email delivery, scheduled jobs | United States |
Email content is not stored: it is read to produce the summary, then discarded - only the encrypted summary is kept. When you delete your account, all associated data (connected mailboxes, rules, summaries, conversations) is permanently erased within minutes. One anti-abuse exception: an irreversible hashed identifier per mailbox, which prevents resetting the free trial by re-creating an account.
If a security incident affected your data, we would notify you promptly at your account address, with the nature of the incident, the data involved and the measures taken. Mailbox access can be revoked at any time from your dashboard - or directly at Google, Microsoft or Yahoo.
Access, rectification, portability, erasure: account deletion is self-service and immediate; for any other request, write to privacy@inboxbriefs.com. A data processing agreement (DPA) is available on request for Team & Enterprise customers.
InboxBriefs is not yet SOC 2 certified - we are an independent product and we say so plainly. The infrastructure it runs on, however, is: our subprocessors (authentication, database, payments, AI) hold their own SOC 2 / ISO 27001 certifications, and our application-level controls (read-only access, AES-256-GCM, non-retention) are documented publicly on this page.
Read the full privacy policy·Compliance questions or DPA requests: privacy@inboxbriefs.com
14 days free, no credit card. Your data stays under your control.