Effective September 24, 2026
Privacy Policy
Inbox Scrub is an inbox audit. It connects to your mailbox, groups messages by sender, scores each sender, and lets you delete and unsubscribe in one pass. Doing that means asking for access to your email, so this policy is specific about what is read, what is stored, and what is never touched.
The short version: Inbox Scrub reads message metadata, not message bodies. It moves nothing without your action. It does not sell your data and does not use it to train models.
- 01
Who this covers
This policy covers the Inbox Scrub website at https://inboxscrub.com, the waitlist, and the Inbox Scrub application at https://app.inboxscrub.com (together, the “Service”). It applies to anyone who visits the site, joins the waitlist, or connects a mailbox.
- 02
What Inbox Scrub reads from your mailbox
When you connect a mailbox, Inbox Scrub requests read access so it can build the audit. From each message it reads:
- the sender address and display name, and the sending domain
- the date received and the message size
- whether the message is unread, archived, in Trash, or in a folder or label
- list-unsubscribe headers, so it can unsubscribe you when you ask
Message bodies and attachments are not read, not stored, and not used for any purpose. Subject lines are not stored; if a future version needs them for a feature, this policy will be updated first.
- 03
What Inbox Scrub does with it
The metadata is used to compute per-sender statistics: total volume, percentage unopened, percentage archived, monthly rate, twelve-month trend, storage used, and an estimate of the storage energy that deleted mail no longer needs. These numbers are shown to you and to nobody else.
Inbox Scrub is read-only until you approve an action. Deleting messages from a sender or unsubscribing happens only when you choose it, and deletions go to your mailbox’s Trash, where your provider keeps them for its normal retention period (thirty days for Gmail). Senders on your protected list are excluded from every bulk action.
- 04
Google user data and the Limited Use requirement
Inbox Scrub’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Gmail data is used only to provide and improve the audit features you see in the app. It is not transferred to others except as needed to provide the Service, to comply with the law, or as part of a merger or acquisition with notice to you. It is not used for advertising. No human reads it except with your permission, for security purposes, to comply with the law, or in aggregated, anonymized form.
You can revoke Inbox Scrub’s access at any time from your Google Account permissions page. Revoking access disconnects the mailbox immediately.
- 05
Account and waitlist information
To create an account you give an email address, a password, and a display name. Passwords are stored as one-way hashes. Sign-in, verification, and password-reset emails are sent through a transactional email provider.
If you join the waitlist, Inbox Scrub keeps your email address in order to send one invitation when your place comes up. It is not added to a newsletter. You can ask for it to be removed at any time by writing to hello@inboxscrub.com.
- 06
Analytics
Inbox Scrub uses PostHog to understand how the site and app are used: pages viewed, buttons pressed, errors, and, on the website, session recordings of your interactions with the page. Mailbox data and message metadata are never sent to analytics. Analytics events are tied to a random identifier and, once you sign in, to your account. You can opt out by enabling your browser’s “Do Not Track” setting or by writing to hello@inboxscrub.com.
- 07
Where data is kept and who processes it
Inbox Scrub runs on a small set of infrastructure providers, each bound by its own data-processing terms:
- Supabase, for the database and authentication (United States)
- Vercel, for hosting the website and app
- Resend, for transactional email
- PostHog, for analytics (United States)
Data is stored in the United States. If you use the Service from elsewhere, your data is transferred to and processed there.
- 08
How long data is kept
- Mailbox metadata and audit results: for as long as the mailbox is connected. When you disconnect a mailbox or delete your account, the audit is deleted within 24 hours.
- Account information: until you delete your account.
- Waitlist addresses: until you are invited or ask to be removed.
- Analytics events: up to 12 months.
- Server logs: up to 30 days.
Backups may hold copies for a short period after deletion; they are overwritten on a rolling schedule.
- 09
What Inbox Scrub does not do
- Sell or rent your data.
- Use your mailbox data, or any user content, to train machine-learning models.
- Show advertising or share data with advertisers.
- Send email from your account or to your contacts.
- Move, delete, or unsubscribe anything without your explicit action.
- 10
Your choices and rights
You can disconnect a mailbox, change your account details, or delete your account from the app’s settings. You can also write to hello@inboxscrub.com to ask what data Inbox Scrub holds about you, to have it corrected or deleted, or to receive a copy of it. Requests are answered within 30 days.
Depending on where you live, you may have additional rights under laws such as the GDPR, the UK GDPR, or the California Consumer Privacy Act, including the right to object to processing and the right to complain to a supervisory authority. Inbox Scrub does not discriminate against you for exercising them.
- 11
Security
Connections are encrypted in transit. Mailbox access tokens are stored encrypted and are never shown in the app. Access to production systems is limited to the people who operate the Service. No system is perfectly secure, so if you believe your account has been accessed without permission, write to hello@inboxscrub.com right away.
- 12
Children
The Service is not directed at children under 16, and Inbox Scrub does not knowingly collect their data. If you believe a child has created an account, write to hello@inboxscrub.com and it will be removed.
- 13
Changes to this policy
This is the first version. When the policy changes in a way that matters, the effective date at the top is updated and, for connected mailboxes, you receive an email before the change takes effect. Continuing to use the Service after that date means you accept the updated policy.
- 14
Contact
Questions about this policy or your data go to hello@inboxscrub.com.