legal
Privacy Policy
Effective: August 12, 2026 · Version 2026-08-12
Who we are
AgentInbox (agentinbox.pro) provides inbound email processing for developers and agent builders. This Privacy Policy describes how we handle personal data when you use our website, dashboard, and services.
Contact us about privacy at [email protected].
What we collect
Depending on how you use agentinbox.pro, we may process:
- Account data — email address and display name from Google sign-in, workspace name, and membership records.
- Legal acceptance records — when you agree to our Terms and Privacy Policy, we store the policy versions accepted, timestamp, IP address, and user agent for audit purposes. These records are retained as part of our compliance history.
- Early-access waitlist — email address (and optional display name) when you request access before your account is allowlisted.
- Inbound email content — sender and recipient addresses, subject, body text and HTML, attachment metadata, message headers, raw
.emlfiles (including attachment bytes within the stored file), and delivery metadata. This often includes personal data about third parties who email your configured addresses. - Configuration data — webhook URLs, domain names, DNS verification records, domain tags, and API key identifiers (we store hashed keys, not plaintext secrets).
- Domain registration data — when you purchase a domain, we submit contact and registration information required by registrars. Configure operator defaults via environment settings where applicable.
- Payment data — when you purchase a domain or subscribe to a paid workspace plan, Stripe collects payment and billing information. We receive limited payment metadata (such as checkout session IDs, Stripe customer and subscription identifiers, and your account email).
- Operational data — IP address, user agent, request paths, and similar log data for security, abuse prevention, rate limiting, and error monitoring.
- Cookies — session cookies for sign-in; a short-lived cookie for the instant demo inbox; an optional cookie storing your marketing/analytics consent choice; and, only after you consent, cookies set by Google measurement scripts.
How we use data
We use personal data to:
- Provide, operate, and improve the service (contract).
- Authenticate users, prevent abuse, and secure the platform (legitimate interest).
- Record and enforce policy acceptance (contract / legal obligation).
- Process domain purchases and workspace plan subscriptions through Stripe (contract).
- Deliver inbound email to your configured webhooks (contract).
- Notify waitlisted users about early access when you have requested it (consent or legitimate interest, depending on context).
- Load optional Google Ads / analytics measurement only when you have consented.
- Comply with legal obligations and respond to lawful requests.
Inbound email and your role
When you configure agentinbox.pro to receive mail for your domains, you decide why inbound mail is collected and how it is used in your application. For that inbound email content, you are generally the data controller and AgentInbox acts as a data processor, handling mail on your instructions (including webhook delivery and retention settings). You are responsible for having a lawful basis to collect and use data in the messages sent to your addresses.
Normalized webhook payloads are delivered to URLs you configure. You control those endpoints and any further processing or sub-processors you engage.
Retention
Inbound email and related delivery records are retained according to your workspace plan:
| Plan | Retention |
|---|---|
| Free | 14 days |
| Build | 30 days |
| Scale | 90 days |
You may delete individual inbound messages from the dashboard before automatic deletion. Account, configuration, and legal acceptance records are kept while your workspace is active and for a reasonable period afterward unless you request deletion or we must retain records for legal reasons.
Demo inbox sessions and orphan demo workspaces are purged automatically after short TTLs described in our operational configuration.
Sharing and sub-processors
We do not sell your personal data. We share data with service providers that help us run agentinbox.pro:
| Provider | Purpose | Location |
|---|---|---|
| Sign-in (OAuth) and optional Google Ads / analytics measurement when you consent | United States | |
| Stripe | Payment processing for domain purchases and workspace plan subscriptions | United States |
| Sentry | Error monitoring and request telemetry | United States |
| Neon | Database hosting | United States |
| Vercel | Application and documentation hosting | United States |
| Cloudflare | DNS, CDN, and object storage (raw email) | United States / global edge |
| Domain registrars | Domain registration and DNS management for purchased domains | Varies by registrar |
| Dedicated mail ingress infrastructure | SMTP receipt for inbound email (MX endpoint) | United States |
Payment processing (Stripe)
We use Stripe to process domain purchase payments. Stripe collects and processes personal data including payment method details, billing address, and device information to operate and improve its services, including fraud prevention and authentication. Stripe uses this information as described in Stripe's Privacy Policy.
Cookies and marketing consent
We use strictly necessary cookies for authentication and the optional instant demo inbox. Optional Google measurement scripts (gtag.js for analytics and/or ads) load only after you grant marketing consent through our cookie banner or footer control. Google may set advertising or analytics cookies as described in Google's Privacy Policy. Error monitoring through Sentry may receive IP address and request metadata as part of operating the service.
You can change your marketing consent preference at any time using the "Cookie preferences" link in the site footer.
Security
We use HTTPS for dashboard and webhook delivery, hash API keys at rest, sign webhook payloads, validate webhook URLs against private-network targets in production, and apply reasonable technical and organizational measures to protect data. No method of transmission or storage is completely secure.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. To exercise these rights, contact [email protected]. We will respond as required by applicable law.
California residents: We do not sell or share personal information for cross-context behavioral advertising. You may contact us with privacy requests as described above.
Children
agentinbox.pro is not directed at children under 16, and we do not knowingly collect personal data from children.
International users
The Service uses infrastructure and sub-processors primarily in the United States. Authorized personnel may access data from other locations as needed to operate the Service. If you access the Service from other regions, your data may be processed in the United States and at the global edge locations of those sub-processors. A standalone DPA is available on request.
Changes
We may update this Privacy Policy from time to time. We will post the revised policy on this page, update the effective date and version identifier, and may require renewed acceptance for material changes before continued dashboard use.
Related documents
See also our Terms of Service.