Secure & restricted access
InboxBrief only requests the read permissions required to generate your digests. We cannot send, modify, or delete your messages.
Security
InboxBriefs is built from the ground up to protect your data. Here's exactly how.
Pillars
InboxBrief only requests the read permissions required to generate your digests. We cannot send, modify, or delete your messages.
OAuth tokens, IMAP passwords, and summary contents are encrypted at rest with AES-256-GCM. Your data remains completely unreadable.
Your emails never touch our database. InboxBrief reads them in memory to generate the digest, then discards them immediately.
You can disconnect any mailbox from your dashboard at any time. The OAuth token is revoked immediately and access stops instantly.
No emails are ever sold or shared with third parties. Your emails are never used to train public AI models.
Your rights (access, rectification, portability, deletion) are guaranteed via self-service. A DPA agreement is available upon request.
Long threads become a short summary. See key points without opening every email.
Action items surface at the top. The rest stays behind without distracting you.
No hidden fees, no secret processing. All our policies and subprocessors are public.
Beyond principles, here is what concretely happens to your data: who processes it, for how long, and your recourse.
Trusted providers process some data on our behalf, under our instructions. We never sell your personal information:
| Provider | Role | Processing location |
|---|---|---|
| Clerk | Authentication and identity management | United States |
| Google / Microsoft / Yahoo | Mailbox access (OAuth, read-only) | United States |
| Anthropic | AI summary generation (data not used for training) | United States |
| Stripe | Payment processing (we never see your card) | United States / international |
| Cloud infrastructure | Hosting, database, email delivery, scheduled jobs | United States |
Email content is not stored: it is read to produce the summary, then discarded. Only the encrypted summary is kept. When you delete your account, all associated data is permanently erased.
If a security incident affected your data, we would notify you promptly with the nature of the incident, the data involved and the measures taken.
Access, rectification, portability, erasure: account deletion is self-service and immediate. A data processing agreement (DPA) is available on request.
The infrastructure InboxBriefs runs on holds SOC 2 / ISO 27001 certifications (authentication, DB, payments, AI), and our application controls are public.
Read the full privacy policy·Compliance questions or DPA requests: privacy@inboxbriefs.com
14 days free, no credit card. Your data stays under your control.