Privacy Policy
Inbox Hero · Last updated September 12, 2026
Inbox Hero ("we", "us") provides AI-assisted email organization. This policy explains what data we
access, how we use it, and the choices you have. We built Inbox Hero to be trusted with your inbox, and
we collect and retain as little as possible to do the job.
Information we access
- Your email address, to create and identify your account (passwordless sign-in).
- Google account authorization. When you connect Gmail, Google gives us access tokens to work
with your mail and calendar on your behalf. We request only the scopes our features need:
- gmail.modify — read your mail and apply/move labels (for triage and answering questions).
- gmail.send — send a reply only when you explicitly send it (Quick Reply / compose). We never send on your behalf automatically.
- calendar.readonly — read your calendar events so the assistant can factor in your schedule. Read-only; we never change your calendar.
- userinfo.email / openid — your email address, to identify your account.
- Message metadata and content needed to classify and answer questions — typically headers
(sender, subject, date) and short snippets. We fetch fuller content only when a feature you invoke
requires it.
How we use it
- To triage your inbox — move bulk and automated mail to an "Inbox Hero/Later" label while leaving
important mail in place.
- To answer your questions about your inbox, summarize messages, and surface your top contacts, projects, and tasks.
- To draft and — only when you choose to send — send replies you have reviewed.
- To read your calendar so answers and projects can reflect your upcoming schedule.
- To operate, secure, and improve the service.
AI processing
To classify mail and answer your questions, relevant email text is sent to our AI provider
(via OpenRouter) solely to generate that result. We
send the minimum necessary and never use your email content to train shared foundation models.
Google API Limited Use. Inbox Hero's use and transfer of information received from Google APIs
adheres to the
Google
API Services User Data Policy, including the Limited Use requirements. We do not sell your data, do
not use it for advertising, and do not allow humans to read it except with your consent, for security,
to comply with law, or as required to operate the service.
Storage & security
- OAuth tokens are encrypted at rest (AES-256-GCM). We never see or store your Google password.
- Data is scoped per user and isolated between accounts.
- Connections use TLS. Email content is treated as untrusted input and cannot control the assistant.
Retention & deletion
You can disconnect your mailbox at any time, which immediately deletes the stored access tokens and
cached classifications for that account. To delete your account and associated data entirely, email us.
Contact
Questions or requests: schoettle@gmail.com.