Privacy Policy
How UniMail handles your data.
This policy explains what Inboxars (“we”, “us”) collects when you use the UniMail service at mail.inboxars.com and the website inboxars.com, why we collect it, how long we keep it, and the choices you have — including exactly how we treat data from Google and Microsoft accounts you connect.
Summary
- UniMail is a mail client. It reads, organises and sends e-mail from mailboxes you choose to connect. It does nothing with your mail except show it to you and the team members you authorise, keep it searchable, and send what you write.
- We never sell your data and we never use it for advertising.
- Google and Microsoft data is used only to provide the mailbox features you see in the app. Our use of Google user data follows the Google API Services User Data Policy, including its Limited Use requirements (details in section 5).
- Credentials are encrypted at rest (AES-256-GCM). Nobody at Inboxars reads your mail unless you ask us to for support, or the law requires it.
- You stay in control. Disconnect a mailbox and its tokens and synced mail are deleted; revoke access at any time from your Google or Microsoft account; ask us to export or erase your data.
1. Who this policy covers
This policy applies to:
- the hosted UniMail service operated by Inboxars at mail.inboxars.com (the “Service”), and
- the public website at inboxars.com (the “Website”).
UniMail can also be installed by an organisation on its own server. For such a self-hosted installation, that organisation is the data controller and its own privacy notice applies; this policy then describes only the software's behaviour, not who holds your data.
Within a hosted profile, the profile administrator (the customer who set up the team) decides which users and mailboxes belong to the profile. If you are an employee using a mailbox connected by your employer, your employer is the controller of that mailbox data and we process it on their behalf.
2. What we collect
2.1 Account information
When a login is created for you: your name, e-mail address and a password hash (we never store the password itself), your role in the profile, and your preferences (theme, reading-pane layout, signatures, notification settings).
2.2 Mailbox connections
To connect a mailbox we store what is needed to reach it on your behalf:
- Microsoft 365 / Outlook.com: the OAuth tokens Microsoft issues after you sign in (no password).
- Gmail / Google Workspace: the OAuth tokens Google issues after you sign in (no password).
- IMAP / SMTP mailboxes: the server addresses, your user name and the password or app password you enter.
All tokens and passwords are encrypted at rest with a key that lives only on the server.
2.3 Mail data
For every connected mailbox we synchronise and store, in the Service's database, the folders, messages (headers, bodies and attachments), flags and categories, so that mail loads instantly, works across all your mailboxes at once, and is searchable. We also keep the addresses seen in message headers as an address book for autocomplete, and your drafts, outbox and sent items.
2.4 Team and activity data
Follow-up lists, notes, assignments, reply templates, rules, quick texts, campaign (mail merge) recipients and results, and an activity log that records who did what inside the profile (for example, who replied to or archived a message).
2.5 Technical data
Server logs containing timestamps, IP addresses, the browser type and the requested URL, kept for security and troubleshooting. Logs do not contain message bodies or credentials.
2.6 Website
The Website's contact form does not send anything to our servers: it opens a prefilled message in your own mail app. The Website sets no analytics or advertising cookies. Fonts are loaded from Google Fonts, which receives your IP address when the page loads.
3. How we use it
- to provide the Service: synchronising, displaying, searching, organising and sending mail from the mailboxes you connect;
- to run team features you turn on: shared follow-up lists, presence, assignments, notes, mail-merge campaigns;
- to keep the Service secure, prevent abuse and diagnose faults;
- to communicate with you about your account, service changes and support requests;
- to meet legal obligations.
We do not use your data for advertising, profiling, or to train machine-learning models, and we do not sell it.
4. Google user data
If you connect a Gmail or Google Workspace mailbox, you sign in with Google and Google asks you to grant UniMail these permissions (OAuth scopes):
| Scope | Why UniMail needs it |
|---|---|
openid, email, profile | To identify which Google account you connected (its address and display name), so the mailbox is labelled correctly in the app. |
https://mail.google.com/ | To read, organise and send mail in that mailbox through Gmail's IMAP and SMTP servers. Gmail requires this full-mailbox scope for IMAP/SMTP access; narrower Gmail scopes are not accepted for that protocol. It is the only way the app can show your Gmail messages, move or flag them, and send from your address. |
4.1 How we access, use, store and share Google data
- Access. After you sign in, the Service holds the refresh token Google issued, encrypted, and uses it only to obtain short-lived access tokens for IMAP and SMTP connections to your mailbox.
- Use. Google data is used solely to provide user-facing features that are prominent in UniMail: the unified inbox, folder views, search, reading, replying, forwarding, moving, flagging, follow-up lists and sending mail (including mail-merge campaigns you launch). Nothing is used for advertising, and no Google user data is used to develop, improve or train generalised AI or machine-learning models.
- Storage. Messages, attachments and folder structure from your Gmail mailbox are stored in the Service's database so the app is fast and searchable, exactly as they are for every other provider. Tokens are encrypted at rest.
- Sharing. We do not transfer Google user data to anyone except: (a) the members of your own profile whom your administrator authorised to see that mailbox; (b) our hosting provider, which stores the encrypted database on our behalf; (c) if you explicitly invoke an AI action, the excerpt of the message you chose is sent to the AI provider configured by your profile administrator (see section 6); (d) where required by law. We never sell Google user data and never share it with data brokers or advertisers.
- Human access. Staff do not read your Google data. Exceptions are limited to: you asking us for support on a specific message, security investigation of abuse, or a legal obligation, and internal operations on aggregated, anonymised data.
4.2 Limited Use disclosure
UniMail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.3 Your controls
- Disconnect the mailbox in UniMail under Settings → Mail accounts. Its tokens and every message synced from it are deleted from the Service.
- Revoke UniMail's access from your Google account at myaccount.google.com/permissions. The Service can then no longer reach the mailbox; you can remove the stale copy in Settings.
- Ask us to erase everything we hold about you (section 10).
5. Microsoft user data
If you connect a Microsoft 365 or Outlook.com mailbox, you sign in with Microsoft and grant the delegated permissions Mail.ReadWrite, Mail.Send, MailboxSettings.ReadWrite, User.Read and offline_access. They let UniMail read and organise the mailbox, send from it, read and manage categories and folders, identify the account, and keep working in the background after you sign in. Microsoft data is handled exactly as described for Google data above: used only for the features you see in the app, stored encrypted where it is a credential, never sold or used for advertising, and deleted when you disconnect the mailbox.
6. AI features
UniMail can draft replies and follow-ups. AI features are off until a profile administrator enters their own API key for an AI provider (currently OpenAI). When you press an AI action, the text of the message or thread you selected is sent to that provider to produce a draft; nothing is sent automatically, and the AI never sends mail — a person always reviews and presses Send. The provider's own terms govern its processing. Google user data is only ever sent to an AI provider when you yourself trigger an AI action on a specific message.
8. Retention and deletion
- Synced mail is kept for as long as the mailbox stays connected. Disconnecting a mailbox deletes its messages, attachments, folders and credentials from the Service.
- Your login and settings are kept until your profile administrator removes you or the profile is closed, after which they are deleted within 30 days.
- Backups are encrypted and rotated automatically; deleted data disappears from backups within 35 days.
- Server logs are kept for up to 90 days.
- Activity logs (who did what in the profile) are kept for the life of the profile because they are part of the team's audit trail.
9. Security
All traffic uses HTTPS. OAuth tokens and mailbox passwords are encrypted at rest with AES-256-GCM; the encryption key is stored separately from the database. Login sessions use HttpOnly, Secure cookies. HTML mail is sanitised on the server and again in the browser, and remote images are blocked until you allow them. Database backups are encrypted and verified. Access to production systems is limited to named administrators with multi-factor authentication. If we ever discover a breach affecting your data we will notify you and the relevant authorities as the law requires.
10. Your rights
Depending on where you live (for example under the GDPR or UK GDPR) you may have the right to access, correct, export or erase your personal data, to restrict or object to its processing, and to complain to a supervisory authority. Write to privacy@inboxars.com and we will respond within 30 days. If a mailbox was connected by your employer, we may direct the request to them as the controller.
Where we rely on consent (for example your Google or Microsoft sign-in), you can withdraw it at any time by disconnecting the mailbox or revoking access at the provider. Where we process data to perform the contract with your organisation or for our legitimate interests (security, service operation), you can object by contacting us.
International transfers
Our servers are located in the region shown in your profile's settings. Where data leaves that region (for example to reach your mail provider or AI provider) we rely on the provider's standard contractual protections.
Children
The Service is for organisations and is not directed at children under 16. We do not knowingly collect their data.
12. Changes to this policy
When we change this policy we update the effective date above and, for material changes, tell you inside the app or by e-mail before they take effect. Our use of Google user data will always stay within what this policy discloses.
13. Contact
InboxarsPostal address to be added before publishing
privacy@inboxars.com