Privacy policy
Last updated 6 October 2026
Inbox is run by Untangle IT (“we”). This policy says what Inbox collects, what it does with it, who can see it,
and how to delete it. Questions: info@untangleit.in.
What Inbox collects
When you sign in with Google
Your name, email address and profile picture, to know who you are and which workspace you belong to.
When you connect a Gmail account
| Google permission | What Inbox does with it |
Read mail (gmail.readonly) | Copies the last 90 days of mail, then new mail as it arrives: sender, recipients, subject, date,
labels and the text of each message, and the names and types of attachments. Attachments themselves are fetched from
Gmail only when you open one, and are not stored. |
Send mail (gmail.send) | Sends the replies and emails you write in Inbox, from your account. |
Modify mail (gmail.modify) | Marks conversations read or unread and archives them when you do so in Inbox. Inbox never deletes your mail. |
Calendars (calendar.readonly, calendar.events) | Shows the events in your calendars (copied for 60 days back and
180 days ahead), and creates, moves, answers or deletes events when you do so in Inbox or someone books time through your booking page. |
When you connect Slack
Inbox posts alerts to the channel you choose. If you add a Slack workspace to the Slack inbox, it reads your direct
messages, the channels you pick and messages that mention you (the last week, then new ones), using your own Slack
access, and sends the replies you write.
What you and your team enter
Clients, contacts, notes, tasks, templates, settings and booking pages. When someone books time through a booking
page, their name, email address and note.
How it is used
Only to provide the features you see in Inbox. We do not use your data for advertising, do not sell it, do not use
it to train AI or machine-learning models, and do not send it to any AI service.
Inbox’s use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements.
Who can see it
- Your workspace. Each company is a separate workspace with its own database; nobody outside it can see its data.
- Within a workspace, a connected mailbox is private to whoever connected it until they share it with teammates.
- Untangle IT staff do not read your data, except with your permission to help with a problem, to keep the
service secure, or where the law requires it.
- No one else. We share data only with the services that run Inbox: Oracle Cloud (our servers), Google
(Gmail, Calendar, and Google Drive, where backups are kept) and Slack (if you connect it).
How it is protected
All traffic uses HTTPS. Google and Slack access tokens are encrypted in the database. Email is shown as text only;
its HTML is never rendered. Access to the servers is limited to Untangle IT administrators.
Keeping and deleting it
- Disconnecting a Gmail account from Inbox deletes the mail Inbox copied from it.
- A workspace owner can delete the workspace (Setup → Team). That deletes all of its data and gives back its
Google and Slack access at once.
- Backups are made nightly and deleted after 30 days.
- You can also remove Inbox’s access at any time from your Google account at
myaccount.google.com/permissions.
- To have your data deleted or exported, email info@untangleit.in.
Children
Inbox is a tool for businesses and is not meant for anyone under 16.
Changes
If this policy changes, the new version is posted here with a new date. Significant changes are announced in Inbox.