1. Who this policy covers
This Privacy Policy applies to OneInbox, available at tryoneinbox.co, its dashboard, and related services (together, the “Service”). In this policy, “OneInbox,” “we,” “us,” and “our” refer to the operator of the Service.
By using the Service, you acknowledge the practices described here. This policy does not govern the privacy practices of Google, Microsoft, your email provider, or other third-party services you choose to connect.
2. Data we collect
Account and profile information
We collect information you provide when creating or managing an account, such as your name, email address, authentication details, preferences, subscription status, and support communications.
Connected mailbox information
When you connect a mailbox, we process the mailbox address, provider and connection settings, OAuth tokens or encrypted app-password credentials, folders, message metadata, message contents, attachments, read/archive state, and sent-message information needed to provide a unified inbox.
Usage and technical information
We may process basic service logs, IP address, browser and device information, requested pages, timestamps, errors, and diagnostic information to operate, secure, and improve the Service. We do not use third-party advertising trackers.
Billing information
Payments are processed by Stripe. We receive subscription and transaction information such as plan, payment status, and Stripe customer identifiers, but we do not store full card numbers.
3. Google user data
If you connect Gmail using Google OAuth, OneInbox requests your Google email address and permission to access Gmail. This access may include reading, displaying, organizing, modifying, sending, and deleting Gmail messages and attachments, as well as maintaining access while you are not actively using the Service.
How OneInbox uses Google user data
- To connect the Gmail account you select and identify its email address.
- To synchronize messages, threads, folders or labels, attachments, and read/archive state into your unified inbox.
- To let you search, read, organize, archive, delete, compose, and reply to email from the correct connected address.
- To refresh authorization and keep synchronization working until you disconnect Gmail or revoke access.
- To maintain security, prevent abuse, troubleshoot failures, and provide support you request.
How Google user data is stored and protected
OAuth refresh tokens are encrypted at rest with AES-256-GCM using an application key held outside the database. Message data is transmitted only over TLS and stored on access-controlled infrastructure that encrypts data at rest, so the Service can provide synchronization, search, and message history. Row-level security policies isolate each user’s data from other customers, and the specific protection mechanisms in section 6 apply to all Google user data.
How Google user data is shared
We do not sell Google user data. We do not use it for advertising, credit decisions, or to build general-purpose profiles. We disclose it only to service providers acting on our behalf where necessary to operate the Service, when you explicitly direct us to do so, or when required by law. Those providers may process data only to provide their contracted services to us.
OneInbox does not use Google user data to train generalized artificial-intelligence or machine-learning models. If you separately enable an optional AI feature, only the content needed to perform the feature you requested may be processed for that request, as disclosed in-product.
4. How we use data
We use personal data to provide and maintain the Service; authenticate users; connect and synchronize mailboxes; send messages you direct us to send; process subscriptions; communicate about the Service; respond to support requests; prevent fraud and abuse; diagnose problems; comply with law; and improve reliability and usability.
We do not sell or rent personal information. We do not use mailbox contents for targeted advertising.
6. Storage and security
We protect sensitive data, including Google user data, with specific technical mechanisms at every stage:
- Encryption in transit. All connections between your browser or device and OneInbox, and between OneInbox and your mailbox providers, use TLS. Mail is never fetched or sent over unencrypted connections.
- Encryption at rest. Mailbox passwords and OAuth refresh tokens are encrypted with AES-256-GCM using a dedicated application key that is held outside the database, so database access alone cannot expose your credentials. Message data and backups are stored on infrastructure that encrypts all data at rest with AES-256.
- Access controls. Every API request is authenticated and scoped to the signed-in user's own records, and row-level security policies in the database isolate each customer's data. Production access is restricted to authorized personnel on a need-to-know basis.
- Key and credential management. Encryption keys and provider credentials are stored in the hosting platform's secret manager, never in source code or version control.
- Monitoring and incident response. Application and sync activity are logged. If we become aware of a data breach affecting your personal data, we will notify affected users without undue delay, consistent with applicable law including the Australian Notifiable Data Breaches scheme.
- Secure deletion. Disconnecting a mailbox or deleting your account removes the associated credentials and synced mail from active systems, and residual copies age out of encrypted backups on a fixed schedule.
No method of storage or transmission is completely secure. You are responsible for safeguarding your OneInbox login and the devices you use to access the Service.
7. Retention and deletion
We retain account information while your account is active and as needed for legitimate business, security, billing, and legal purposes. We retain synchronized mailbox data only for as long as needed to provide the Service under the applicable retention settings.
Disconnecting a mailbox stops future synchronization and removes the connected account and its stored mailbox data from active systems. You can also revoke Google access at any time from your Google Account permissions. Limited records may remain temporarily in encrypted backups or where retention is required by law.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal data. You may disconnect a mailbox in OneInbox, revoke OAuth access through the provider, or request deletion of your OneInbox account and associated data.
You may make a privacy or deletion request through our contact page. We may need to verify your identity before completing a request.
9. Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Higher minimum ages may apply where required by local law.
10. Changes to this policy
We may update this policy as the Service changes. We will publish the updated version here, revise the date above, and provide additional notice when a change materially affects how we use personal data.
11. Contact us
Questions, privacy requests, and account-deletion requests can be sent to ross@tryoneinbox.co or submitted through the OneInbox contact page.