Privacy Policy
Effective date: 10 August 2026Last updated: 10 August 2026
1. About Inbox Signal
Inbox Signal is an email attention and reply assistance service operated by Maldicore ([LEGAL ENTITY NAME TO BE CONFIRMED]). This policy explains what information the service handles and why.
With your authorization, Inbox Signal:
- connects to your email account;
- synchronizes recent email information from that account;
- assesses which conversations may require your attention;
- prepares suggested replies where a reply appears appropriate;
- lets you review, edit and approve those replies;
- records your corrections and feedback;
- may suggest reusable rules based on those corrections.
Suggested rules only take effect after you approve them. Inbox Signal does not send email on its own. Every message is sent only after you approve it.
Your use of the service is also governed by our Terms of Service.
2. Information we collect and process
Account information
Your name, email address, account identifier, role and the profile information you enter during onboarding or in Settings.
Business information
Information you enter as Business Context: business or project name, industry, a description of what you do, products or services, typical customers, and any policies or operating notes you add.
Connected email information
When you connect a Gmail account, the service stores:
- the connected email address and connection status;
- email threads and messages from a bounded recent window;
- sender and recipient addresses and display names;
- subject lines and message text needed to assess and reply;
- message and thread identifiers from Gmail, and provider labels;
- attachment metadata only, such as file name, type and size.
Attachment contents are not downloaded and not stored. The service does not read the file itself.
Communication preferences
The tone, length, style and similar preferences you provide, along with what you tell us usually matters to you and what usually does not.
Feedback and learning information
The service stores:
- corrections to an assessment;
- edits you make to a draft before sending;
- skips, with an optional reason;
- draft regeneration events;
- written feedback you provide;
- suggested rules and the rules you approve.
A suggestion does not change how the service behaves simply because the system detected a pattern. It becomes active only when you approve it, and you can switch it off later.
Service and diagnostic information
The service keeps an activity log of actions performed in your account, synchronization state, and records of model calls such as the model name and outcome. If you file an internal problem report, we store the category, your description, the page you were on, an optional conversation reference and the build version. Email bodies and draft text are not copied into a report. Inbox Signal does not run advertising or behavioural analytics tracking. Hosting infrastructure necessarily processes standard request information such as IP address in order to serve the application.
3. Google account and Gmail data
You explicitly authorize Inbox Signal to connect to your Google account. Access is limited to the permissions actually requested at that time. The service currently requests:
- read access to Gmail (
gmail.readonly), so conversations can be synchronized, assessed and summarized; - send access (
gmail.send), so an approved reply can be sent from your account on the original conversation.
Inbox Signal does not delete, archive, forward or modify your mail. Sending happens only after you explicitly approve a specific message.
The Google connection is established through the connector service used by our application platform. Google OAuth refresh tokens are not stored in the Inbox Signal application database. What the application holds is an encrypted, server-side reference used to make authorized Gmail requests on your behalf. It is never exposed to the browser. Disconnecting Gmail in Settings removes that stored reference.
Inbox Signal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. [GOOGLE DISCLOSURE WORDING TO BE VERIFIED AGAINST CURRENT GOOGLE POLICY]
4. How we use information
We use the information above to:
- provide and operate the service;
- synchronize the email you authorized;
- assess which conversations need your attention;
- prepare suggested replies;
- apply your Business Context and communication preferences;
- record your corrections and generate learning suggestions;
- apply learned rules you have approved;
- show activity and performance information for your organization;
- maintain security, diagnose failures and improve reliability.
Inbox Signal does not sell your information and does not use it for advertising. AI processing is performed by a third-party model provider reached through our platform's AI gateway. [AI PROVIDER DATA-USE AND TRAINING TERMS TO BE VERIFIED AND STATED] We will state that provider's data-use position here once it has been confirmed in writing, rather than making a claim we cannot yet support.
5. AI processing
Inbox Signal uses AI models to triage conversations, summarize intent, generate reply drafts and analyse feedback patterns. Relevant thread content, contact information, Business Context and preferences are sent to the model for those purposes.
Safeguards built into the product:
- AI output can be wrong, and the product is designed on that assumption;
- when an assessment is uncertain, or when a model call fails, the conversation is surfaced for your attention rather than hidden;
- reply drafts are always subject to your review and editing;
- drafts are checked for business commitments that are not supported by the information you provided, and unsupported commitments are removed or flagged;
- sending requires your explicit approval;
- learned suggestions require your approval before they affect behaviour.
Instructions contained inside an email are treated as untrusted content, not as instructions to the system.
6. How information is shared
We do not sell personal information. Information is processed by service providers only as necessary to operate the product:
- Google, for Gmail access and sending, and for Google sign-in if you use it;
- our application platform and its cloud backend, which provide hosting, the database, authentication and the AI gateway;
- the AI model provider reached through that gateway, which processes the content sent for triage and drafting.
[FULL NAMED SUBPROCESSOR LIST TO BE CONFIRMED AND PUBLISHED]
We may also disclose information where required by law, to protect the security of the service, or in connection with a corporate transaction affecting the service.
7. Data retention
We keep information for as long as reasonably necessary to provide the service, meet legal obligations, resolve disputes and maintain security. Synchronization imports a bounded recent window of email rather than your whole mailbox.
Fixed retention periods have not yet been set. [RETENTION PERIODS TO BE DEFINED] In the meantime, the deletion controls described below are available at any time.
8. Data deletion and account deletion
Settings currently offers two confirmed deletions.
Delete imported email. This removes imported threads, messages and contacts for your organization, resets synchronization so it starts clean, and removes copied email and draft wording from stored feedback records. The feedback record itself is kept without that wording, so the audit history of what happened remains intact. Rules you approved remain in place.
Delete account. This deletes your user account and the stored Gmail connection reference. If you are the last member of your organization, the organization and its data are deleted as well. If colleagues still belong to the organization, their data is not deleted when you leave.
Deleting data in Inbox Signal does not delete anything in your Gmail mailbox. Backups and infrastructure logs held by our providers may persist for a limited period before being overwritten.
9. Security
Protections implemented in the product include:
- authenticated access to all product data;
- tenant isolation enforced at the database level with row-level security;
- privileged operations performed server-side only;
- the Gmail connection reference stored encrypted and readable only by server-side code;
- an append-only activity log written by the server, not by the browser;
- API keys and model credentials held server-side and never sent to the browser.
No service can promise perfect security. We do not hold, and do not claim, any security certification.
10. International processing
Inbox Signal relies on cloud infrastructure and service providers that may process information in more than one country. We do not currently guarantee that your information is stored or processed in a particular country or region. [DATA RESIDENCY AND TRANSFER MECHANISM TO BE CONFIRMED]
11. Your choices and controls
Within the product you can:
- connect, disconnect or reconnect your Gmail account;
- view and edit your profile and Business Context;
- edit your communication preferences;
- approve, edit, dismiss or switch off learned rules;
- inspect conversations that were handled quietly and correct them;
- delete imported email;
- delete your account.
Depending on where you live, you may have additional statutory privacy rights, such as rights of access, correction, deletion or objection. Contact us and we will respond in line with applicable law. [JURISDICTION-SPECIFIC RIGHTS WORDING REQUIRES LEGAL REVIEW]
12. Children's privacy
Inbox Signal is a business tool and is not directed at children. A minimum user age has not yet been set as a matter of policy. [MINIMUM AGE REQUIREMENT TO BE DECIDED]
13. Changes to this policy
We may update this policy as the product changes. When we do, the effective and last updated dates at the top of this page will change. Material changes will be communicated in the product where appropriate.
14. Contact
Privacy questions: [PRIVACY CONTACT REQUIRED]
Operator: Maldicore [LEGAL ENTITY NAME AND REGISTERED ADDRESS REQUIRED]