Information we collect
Account and settings. We process information you provide, including your name, email address, password in protected form, profile image, language, timezone, subscription, calendar display preference, and location preference.
Appointments and contacts. We process appointments, events, reminders, tasks, recurrence rules, locations, invitation responses, trusted providers, and contacts you add or choose to synchronize.
Documents and deliveries. We process documents you upload, scan, or import from connected mailboxes, together with extracted metadata such as category, provider, amount, currency, due date, salary, insurer, and received or upload time. Delivery information may include carrier, order or tracking number, contents, expected date, address, and status.
Support and diagnostics. We process bug reports and support messages you submit, together with limited technical context such as platform, device name, app version, synchronization status, and error information.
Connected services
Connections are optional and require your authorization. Depending on the services you connect, InboxPilot may access:
- Gmail through the Gmail API and Microsoft mailboxes through Microsoft Graph;
- other mailboxes through IMAP and SMTP using the credentials or OAuth authorization you provide;
- Google Calendar, Outlook Calendar, and Apple Calendar;
- Google Contacts and Apple Contacts;
- Google Tasks, Microsoft To Do, and Apple Reminders.
InboxPilot requests only the access needed for enabled features. You can disconnect services or revoke permissions through the provider or app settings.
Email processing
InboxPilot retrieves recent mailbox information to detect appointments, events, deliveries, and supported documents. It is designed not to retain every email. Relevant metadata, a limited message preview where needed for processing, and selected attachments may be retained when they produce an InboxPilot item. Messages rejected as irrelevant are recorded only as needed to prevent repeated analysis.
Outgoing mail is not analyzed for appointment extraction by default. When you explicitly send an invitation or booking request through InboxPilot, the selected mailbox provider processes that message.
AI processing
InboxPilot uses AI to interpret voice requests, selected email content, and supported documents, and to answer questions about your InboxPilot data. Premium research commands may use live web search to compare external providers or services. We send only the information needed for the requested feature. AI output can be incomplete or inaccurate and should be reviewed before acting.
Usage records may include feature purpose, model, token counts, estimated cost, status, and the mailbox involved. These records support usage limits, diagnostics, billing, and abuse prevention.
How we use information
- to authenticate accounts and maintain device sessions;
- to synchronize selected services and create or update InboxPilot items;
- to organize documents, deliveries, appointments, contacts, tasks, and reminders;
- to prepare user-requested drafts, invitations, routes, notifications, and research proposals;
- to enforce subscription limits and reasonable-use protections;
- to provide support, secure the service, prevent duplicate processing, and improve reliability.
Sharing and service providers
We do not sell personal information, mailbox content, documents, contacts, or location data. Information may be processed by hosting, email, calendar, contact, task, AI, mapping, notification, and infrastructure providers only as needed to operate features you use. Connected providers process information under their own terms and privacy policies. We may disclose information where required by law or necessary to protect users and the service.
Security and retention
We use encrypted network connections, restricted server access, protected authentication credentials, private document storage, and authenticated download endpoints. OAuth and service tokens are stored in encrypted form where supported. No online service can guarantee absolute security.
We retain information while your account is active and as needed to provide InboxPilot. You can delete individual documents and disconnect services. Account deletion disables access and active sessions. Limited security, billing, abuse-prevention, and legal records may be retained where reasonably necessary.
Your choices
- Edit profile, language, timezone, location, contacts, providers, and calendar preference in Settings.
- Connect or disconnect supported services and revoke provider permissions.
- Delete imported documents and your InboxPilot account.
- Change microphone, speech, contacts, calendar, location, camera, photo, and notification permissions in iPhone Settings.
- Contact us to request access, correction, export, or erasure where applicable.
Children
InboxPilot is not directed to children under the minimum age required to consent to online services in their country. Contact us if you believe a child provided information without appropriate permission.
Changes and contact
We may update this policy as InboxPilot changes. The revised date will be posted here, with additional notice where required.
For privacy questions or requests, email support@apisx.eu.