Privacy Policy
Last updated: March 13, 2026
1. Overview
Attimo Labs LLC (“we,” “us,” “our”) operates InboxDetox. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. We take the privacy of email communications seriously and handle your data with care.
2. Information We Collect
Account information: When you sign up via Google OAuth, we receive your name and email address from Google. We do not receive or store your Google password.
Email content: When emails are forwarded to your InboxDetox address, we receive and store the sender’s email address, subject line, and body text. This is necessary to provide the translation service.
Usage data: We collect basic usage information such as when messages are received and whether you have viewed them.
Payment information: Payment is processed by Stripe. We do not store your credit card number or payment details. We receive and store basic subscription status information from Stripe.
Email content: When emails are forwarded to your InboxDetox address, we receive and store the sender’s email address, subject line, and body text. This is necessary to provide the translation service.
Usage data: We collect basic usage information such as when messages are received and whether you have viewed them.
Payment information: Payment is processed by Stripe. We do not store your credit card number or payment details. We receive and store basic subscription status information from Stripe.
3. How We Use Your Information
We use your data to: provide and operate the InboxDetox service; process and translate incoming emails using the Anthropic Claude AI API; deliver translated emails to your inbox; maintain your message history and dashboard; send weekly curriculum emails and track your progress through them; store and use your voluntary reflection responses to improve your experience over time; process subscription payments; and communicate with you about your account.
4. AI Processing
Email content is sent to Anthropic’s Claude API for translation and analysis. Anthropic processes this data according to their own privacy policy and API terms. We do not use your email content to train AI models. You can review Anthropic’s privacy practices at anthropic.com/privacy.
5. Third Parties We Share Data With
We share your data only with the service providers listed below, and only to the extent necessary to operate InboxDetox. We do not sell your email content or personal information to any third party.
| Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Anthropic | AI processing — email content is sent to the Claude API for translation and analysis. | Email subject, body, and sender address. | View → |
| Postmark (ActiveCampaign) | Email delivery — receives and sends emails on our behalf, including curriculum emails and translated replies. | Email sender address, subject, and body. | View → |
| Stripe | Payment processing — handles all subscription billing. | Name, email address, and payment card details (card details are processed directly by Stripe and never stored by us). | View → |
| Supabase | Database and authentication hosting — stores your account data, message history, and curriculum responses. | All account and service data described in Section 2. | View → |
| Google (OAuth / Gmail API) | Authentication and, where permitted, sending emails on your behalf via Gmail send-as. Used for replies initiated both from the InboxDetox dashboard and from Gmail directly (when you reply to a translated message in your inbox). | Name and email address (OAuth); outbound reply content and recipient address (Gmail send-as). | View → |
| Vercel | Application hosting and serverless infrastructure — serves the InboxDetox web application and processes all inbound email webhooks. | All data that passes through the application, including email content received via inbound webhook, IP addresses, and standard web request metadata. | View → |
6. Google API Data
InboxDetox uses Google OAuth to authenticate your account and, where you have granted permission, the Gmail API to send emails from your address (“send-as” access). Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google account data (name, email address) only to create and identify your InboxDetox account.
- We use Gmail send-as permission to deliver translated email replies on your behalf. This covers two reply paths: replies composed within the InboxDetox dashboard, and replies you write directly in Gmail by hitting Reply on a translated message (which InboxDetox receives, strips of quoted content, and forwards to your correspondent via your Gmail address).
- We do not use Google user data to serve advertisements.
- We do not allow humans to read your Gmail data except with your explicit permission or as required by law.
- We do not share Google user data with any third party except as described in Section 5 above, solely to operate the service.
7. Data Storage and Security
Your data is stored in Supabase-managed databases hosted on secure cloud infrastructure. Translated emails and message metadata are stored in your account to power the InboxDetox dashboard. Original emails are retained by your email provider in your archive (Gmail’s All Mail folder, or Outlook’s Archive). We use industry-standard security practices including encrypted connections and access controls.
8. Sensitive Content
InboxDetox processes potentially sensitive personal communications. We treat email content as confidential. Only automated systems and essential infrastructure personnel with a need to know may access email content, and only for the purpose of maintaining service operation.
9. Curriculum and Reflection Data
InboxDetox includes an optional weekly curriculum — a series of emails from your chosen guide covering healthy communication practices. Each curriculum email includes a reflection prompt. If you choose to respond to a prompt, your response is stored in your account. These responses are used solely to improve your InboxDetox experience and inform future curriculum content. You are never required to submit a reflection response. You may request deletion of your reflection responses at any time by contacting us at support@inboxdetox.me.
10. Data Retention
We retain your account data, translated message history, and curriculum responses for as long as your account is active. If you cancel your account, we will delete your data within 90 days. You may request deletion of your data at any time by contacting us at support@inboxdetox.me.
11. Your Rights
You have the right to access the personal data we hold about you, request correction of inaccurate data, request deletion of your data, export your data, and opt out of non-essential communications. To exercise any of these rights, contact us at support@inboxdetox.me.
12. Children's Privacy
InboxDetox is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify active subscribers of material changes by email. Continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact
For privacy-related questions or requests, contact us at support@inboxdetox.me.