This Privacy Policy describes how SenseInbox processes information when you use the SenseInbox website and application.
Information we process
Account and authentication data
We process information needed to authenticate you, maintain your account and enforce plan/access controls.
Connected mailbox data
When you connect Gmail or Microsoft, SenseInbox processes the provider data needed to scan, synchronize, classify, protect, review and—only when separately authorized—perform supported reversible mailbox actions. The product derives metadata and intelligence such as categories, sender profiles, receipt/invoice signals and cleanup recommendations.
Billing data
Checkout and recurring-payment processing is performed through configured payment providers. SenseInbox stores provider identifiers, entitlement/reconciliation records and receipts needed to operate billing; it is not designed to store full payment-card details.
Optional connector data
If you enable MCP or AI connectors, SenseInbox stores connector preferences, scoped-token hashes, encrypted BYOK credentials where applicable, governance settings, usage/audit records and privacy-reduced AI outbound receipts.
How we use information
- Provide mailbox intelligence, review and reversible cleanup features.
- Maintain account security, access controls and entitlements.
- Operate optional connectors you explicitly enable.
- Diagnose reliability, abuse and security issues.
- Provide support, privacy exports and account recovery.
Mailbox authority
Scanning and organize authority are separate capabilities. SenseInbox does not implement a permanent mailbox-delete primitive in the current product surface.
AI processing
External AI processing is optional. When enabled, the product is designed to send derived aggregate portfolio payloads rather than message bodies, subjects, snippets, email addresses, OAuth tokens or payment data. Provider terms and data practices also apply to the AI provider you select.
Data retention and deletion
SenseInbox provides account disconnect and derived-data deletion/export operations. Operational/audit records may be retained where necessary for security, billing reconciliation, legal obligations or recovery. Connector telemetry retention can be governed by account policy where supported.
Sharing
We share information with service providers only as needed to operate the service—for example mailbox providers you connect, payment processors, Cloudflare infrastructure and optional AI providers you enable. We do not sell mailbox content.
Your choices
You can disconnect a mailbox, remove optional AI connectors, revoke MCP tokens, request derived-data export and use available account deletion controls.
Contact
Privacy questions: support@senseinbox.com.