Privacy Policy
Effective Date: February 4, 2026
Thank you for using InboxAssist. Your privacy and the security of your data are our top priorities. This Privacy Policy explains how we collect, use, store, and protect your information when you use our AI-powered email assistant service.
Who We Are
InboxAssist is operated by Mohamed Hassan Ahmed, a sole trader based in Sweden. For any privacy-related questions or requests, please contact us at [email protected].
Information We Collect
When You Sign Up
When you first interact with InboxAssist through Telegram, we collect:
- Your Telegram user ID
When You Connect Your Email Account
When you authorize InboxAssist to access your email account, we collect:
- Your email address
- Your display name
- Access tokens to read and send emails on your behalf (via IMAP and SMTP)
Email Data During Active Use
While you actively use InboxAssist, we temporarily store:
- Email content (subject, body, attachments)
- Email metadata (from, to, cc, bcc, date, message IDs)
- Summaries and draft responses generated by our AI
- Your messages and commands sent through Telegram
All of this data is encrypted at rest in our database.
Payment Information
When you subscribe to InboxAssist, we collect:
- Subscription status and duration
Your payment details (credit card information, billing address) are handled entirely by Stripe, our payment processor. We never see or store your full payment card details. Please refer to Stripe's Privacy Policy for how they handle your payment information.
Infrastructure Logs
For security and abuse prevention, our proxy infrastructure logs:
- IP addresses of visitors to our website and API endpoints
These logs are kept for a short period in active storage and archived for up to 90 days total. This logging occurs at the infrastructure level and is used solely to prevent abuse and ensure service security.
Analytics
We use Plausible Analytics, a privacy-friendly, cookie-free analytics tool, to understand general usage trends on our website. No personal data is collected through this tool. Learn more at Plausible's Data Policy.
How We Use Your Information
We use your information to:
- Provide the InboxAssist service (reading emails, generating summaries, drafting replies)
- Process your email commands and deliver results to your chat platform
- Maintain your subscription and process payments
- Improve and optimize our service
- Prevent abuse and ensure security
- Communicate with you about service-related matters
How We Process Your Emails
AI Processing
Your email content is sent to OpenAI's API to generate summaries and draft responses. We have configured our OpenAI account with zero data retention, meaning OpenAI does not store or use your emails for training their models. For more information, see OpenAI's API Data Usage Policies.
Data Storage
All your data is stored on our secure VPS server located in Finland (provided by Hetzner). We use encryption to protect:
- Email content and metadata
- Your display name and email address
- Access tokens
- Messages exchanged with InboxAssist
- All other personal information
We currently do not maintain backups of user data.
Third-Party Services
InboxAssist integrates with the following third-party services:
Microsoft (Outlook/Email Provider)
We use OAuth to securely access your email account. We request permissions to:
- Read your emails (IMAP access)
- Send emails on your behalf (SMTP access)
- Access your display name and email address
- Refresh access tokens in the background
When you run the /disconnect command, we revoke all access tokens with Microsoft, ensuring we no longer have access to your email account.
OpenAI
Email content is processed through OpenAI's API to provide AI-powered summaries and draft responses. Zero data retention is enabled, meaning your emails are not stored or used for training by OpenAI.
Stripe
Payment processing is handled by Stripe. They collect and store your payment information according to their privacy policy. We only receive confirmation of your subscription status and duration.
Telegram (or Other Chat Platforms)
InboxAssist delivers summaries and drafts through your chosen chat platform (currently Telegram, with additional platforms planned for the future).
Your interactions with InboxAssist through the chat platform—including commands you send and summaries we deliver—are subject to that platform's privacy policy and data retention practices:
- Telegram: Telegram Privacy Policy
We do not control how your chat platform stores these messages. To delete chat history with InboxAssist within the platform, please refer to your platform's message deletion features.
Data Retention and Deletion
Active Use
While you actively use InboxAssist, we retain your email data and messages to provide the service.
Disconnecting Your Account
You can delete all your email data and account information at any time by using the /disconnect command in Telegram. This will:
- Permanently delete all email content and metadata from our database
- Delete your account information (email address, display name)
- Revoke all access tokens with Microsoft
Please note: This does not delete your chat history with InboxAssist on Telegram. That data remains on Telegram's servers and must be deleted through Telegram.
Inactive Accounts
If you do not interact with InboxAssist for 12 consecutive months, we may automatically delete your account data to minimize data retention. You retain the ability to reconnect at any time.
Infrastructure Logs
IP address logs are retained for short period in active storage and up to 90 days total in archives.
Your Rights
Under the General Data Protection Regulation (GDPR) and other applicable privacy laws, you have the right to:
- Access your data: Request a copy of the personal data we hold about you
- Rectify your data: Correct any inaccurate or incomplete information
- Delete your data: Request deletion of your data (right to be forgotten)
- Restrict processing: Limit how we use your data
- Data portability: Receive your data in a structured, machine-readable format
- Object to processing: Object to certain types of data processing
- Withdraw consent: Withdraw your consent to data processing at any time
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
Data Security
We take data security seriously and implement industry-standard measures to protect your information:
- Encryption at rest: All personal data in our database is encrypted
- Encryption in transit: All data transmission uses HTTPS/TLS encryption
- Access controls: Strict access controls limit who can access user data
- Secure infrastructure: Our servers are hosted in a secure datacenter in Finland
- Token security: All OAuth tokens are encrypted and revoked upon disconnection
However, no method of electronic storage or transmission is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we are responsible to notify you within 72 hours as required by GDPR, to provide information about the breach and steps we're taking to address it.
International Data Transfers
Your data is stored on servers located in Finland (European Union). If you access InboxAssist from outside the EU, your data will be transferred to and processed in the EU, which provides strong data protection under GDPR.
Children's Privacy
InboxAssist is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make significant changes, we use your chosen chat platform in first hand and email secondly to notify you.
The "Effective Date" at the top of this policy indicates when it was last updated. We encourage you to review this policy periodically.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us at:
Email: [email protected]
For general inquiries, you can also reach us at: [email protected]
InboxAssist
© 2025 InboxAssist. All rights reserved.