Security

Your inbox deserves more than a promise.

InboxBriefs is built from the ground up to protect your data. Here's exactly how.

Read-only access

InboxBriefs cannot send, delete or modify your emails. Access is strictly limited to reading, through the official authorization flow of each provider (OAuth for Gmail, Outlook and Yahoo, read-only IMAP for private servers).

End-to-end encryption

OAuth tokens, IMAP passwords and summary content are encrypted at rest with AES-256-GCM. Even in the event of unauthorized access to our database, the data remains unreadable.

Zero email storage

Your emails never touch our database. InboxBriefs reads them in memory to generate the summary, then forgets them. Only the summary is kept, and you can delete it anytime.

Revocable connections

You can disconnect any inbox from your dashboard. The OAuth token is revoked immediately and access stops. For IMAP connections, the encrypted password is removed from our system.

Privacy and compliance

No email is ever sold or shared with third parties. InboxBriefs uses only strictly necessary cookies for the service to work. You can delete your account and all your data at any time.

Compliance & transparency

Beyond principles, here is what concretely happens to your data: who processes it, for how long, and your recourse.

Subprocessors

Trusted providers process some data on our behalf, under our instructions. We never sell your personal information. The complete, up-to-date list lives in the privacy policy:

ProviderRoleProcessing location
ClerkAuthentication and identity managementUnited States
Google / Microsoft / YahooMailbox access (OAuth, read-only)United States
AnthropicAI summary generation (data not used for training)United States
StripePayment processing (we never see your card)United States / international
Cloud infrastructureHosting, database, email delivery, scheduled jobsUnited States

Data retention

Email content is not stored: it is read to produce the summary, then discarded - only the encrypted summary is kept. When you delete your account, all associated data (connected mailboxes, rules, summaries, conversations) is permanently erased within minutes. One anti-abuse exception: an irreversible hashed identifier per mailbox, which prevents resetting the free trial by re-creating an account.

If an incident happens

If a security incident affected your data, we would notify you promptly at your account address, with the nature of the incident, the data involved and the measures taken. Mailbox access can be revoked at any time from your dashboard - or directly at Google, Microsoft or Yahoo.

Your rights (GDPR / PIPEDA)

Access, rectification, portability, erasure: account deletion is self-service and immediate; for any other request, write to privacy@inboxbriefs.com. A data processing agreement (DPA) is available on request for Team & Enterprise customers.

Certifications

InboxBriefs is not yet SOC 2 certified - we are an independent product and we say so plainly. The infrastructure it runs on, however, is: our subprocessors (authentication, database, payments, AI) hold their own SOC 2 / ISO 27001 certifications, and our application-level controls (read-only access, AES-256-GCM, non-retention) are documented publicly on this page.

Read the full privacy policy·Compliance questions or DPA requests: privacy@inboxbriefs.com

Ready to try with full confidence?

14 days free, no credit card. Your data stays under your control.