This Privacy Policy explains how Inbox("Inbox", "we", "us") collects, uses, stores, shares and protects information when you use our website and services (the "Service"). Inbox lets you manage advertising campaigns across multiple ad platforms from one workspace and through AI assistants over the Model Context Protocol (MCP).
By using the Service you agree to this Policy. If you do not agree, do not use the Service.
1. Information we collect
Information you provide
- Account details: name, email address and password (passwords are hashed, never stored in clear text).
- Workspace and organization details you create.
- Billing information, processed by our payment provider (we do not store card numbers).
- Brand knowledge, campaign briefs and instructions you enter.
- Support requests and correspondence.
Information from connected advertising platforms
When you connect an ad account (for example Google Ads, Meta, Amazon, TikTok, LinkedIn, Microsoft and others), you authorize Inbox through OAuth to access that platform's API on your behalf. Depending on the platform and the scopes you grant, we may access:
- Advertising account, campaign, ad group, ad and keyword structures.
- Performance and reporting metrics (spend, impressions, clicks, conversions).
- Assets and creatives you choose to manage.
- Audience and configuration data needed to perform the actions you request.
We access this data only to provide the features you ask for. We store OAuth connections through our integration provider; we do not receive or retain your platform login passwords.
Information collected automatically
- Usage and tool-call logs (which actions were run, when, and their result) for security, auditing and quota metering.
- Device and log data such as IP address and browser type.
- Strictly necessary cookies for authentication and session management. See our Cookie Policy.
2. Google user data and Limited Use
Inbox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, for data accessed through the Google Ads API and other Google APIs:
- We access and use Google user data solely to provide and improve the user-facing features of Inbox that you request (managing and reporting on your Google Ads campaigns).
- We do not sell Google user data.
- We do not use Google user data for serving advertising, and we do not transfer it to data brokers, information resellers or for any other unrelated purpose.
- We do not allow humans to read Google user data unless: you give explicit consent for specific data (for example, to resolve a support request); it is necessary for security purposes (such as investigating abuse); to comply with applicable law; or the data has been aggregated and anonymized.
- Access to Google user data by our AI models is limited to performing the operations you instruct, and is not used to train generalized AI or machine learning models.
3. How we use information
- To operate, maintain and provide the Service and the actions you request across connected platforms.
- To power AI features (the Inbox Copilot and Creative Studio) that act only on your instruction and within your connected accounts.
- To authenticate you, enforce roles and permissions, and meter usage against your plan.
- To detect, prevent and investigate fraud, abuse and security incidents.
- To provide support and communicate service and account notices.
- To comply with legal obligations.
4. AI processing and sub-processors
Inbox uses third-party sub-processors to deliver the Service. We share only the data necessary for each provider's function, under contractual confidentiality and data-protection terms:
- Supabase (managed PostgreSQL database and hosting of application data).
- Unified.to (advertising-platform API integration and OAuth connection storage).
- OpenRouter and the underlying model providers (large-language-model inference for the Copilot).
- fal.ai (AI image generation for Creative Studio).
- DigitalOcean Spaces (object storage for generated creatives).
- Stripe (payment processing).
- Resend (transactional email).
- Cloud hosting providers (Vercel, Render) for running the application.
Prompts and content sent to LLM providers are used only to generate the response you requested. Google user data is not used to train models.
5. How we share information
We do not sell your personal information. We share information only:
- With the sub-processors above, to run the Service.
- With the advertising platforms you connect, to carry out the actions you request.
- With members of your own workspace, according to the roles you assign.
- When required by law, legal process, or to protect rights, safety and security.
- In connection with a merger, acquisition or asset sale, subject to this Policy.
6. Data retention and deletion
We retain your data for as long as your account is active or as needed to provide the Service. You may disconnect any ad account at any time, which revokes our access. You may request deletion of your account and associated personal data by contacting us; we will delete or anonymize it within a reasonable period, except where retention is required by law. Audit logs may be retained for a limited period for security and compliance.
7. Security
We use encryption in transit (TLS), hashed credentials, role-based access control, write-action approval gates and audit logging. No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices. See our Security page for more.
8. Your rights
Depending on your location, you may have rights to access, correct, export or delete your personal data, and to withdraw consent. You can revoke platform access at any time from Connections, or from the platform's own account settings (for Google, at myaccount.google.com/permissions). To exercise any right, contact us below.
9. International transfers
Your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted on this page with a new "Last updated" date.
12. Contact
Questions or requests: [email protected].