Privacy Policy
Last updated: 2026
1. What we collect
When you create an Inboxili account, we collect your name, email address, and password (stored as a salted hash, never in plain text). When you use the product, we process the contact data, campaign content, and template data you upload or create — this belongs to you and your workspace, not us. We also collect standard technical data (IP address, browser type, timestamps) for security, fraud prevention, and diagnosing issues.
2. How we use it
We use account data to operate your login and workspace, deliver the emails you ask us to send (via Amazon SES), power AI features you invoke (via OpenAI, per-request, not for model training), process billing (via our payments provider), and improve reliability and security of the service. We do not sell your data or your contacts' data to third parties.
3. Your contacts' data
You are the data controller for the contacts you upload to Inboxili; we act as a processor. You're responsible for having a lawful basis to email the people in your lists. Inboxili supports double opt-in, one-click unsubscribe, and suppression lists to help you stay compliant, but the underlying consent is yours to obtain and document.
4. Third-party processors
We rely on a small number of infrastructure providers to operate Inboxili: Amazon Web Services (email delivery and file storage), OpenAI (AI text generation features), and a payments processor (subscription billing). Each processes only the data necessary to perform its function.
5. Data retention & deletion
We retain account and workspace data for as long as your account is active. You can delete contacts, campaigns, or your entire workspace at any time from within the product; deleted records are removed from active use and purged from backups on a routine schedule.
6. Cookies & tracking
We use a small number of essential cookies to keep you signed in and remember preferences like your theme. When you send campaigns through Inboxili, open and click tracking on those emails is self-hosted on our own infrastructure rather than a third-party tracking pixel — the resulting engagement data belongs to your workspace.
7. Security measures
Passwords are hashed with Argon2id, never stored in plain text. All traffic to and from Inboxili is encrypted in transit over TLS. API keys are hashed at rest and scoped to only the permissions each integration needs, and sessions use short-lived access tokens with rotating, one-time-use refresh tokens.
8. International data transfers
Our infrastructure providers (Amazon Web Services and OpenAI) may process data in regions outside your own. Where that applies, we rely on those providers' standard safeguards for cross-border data transfer.
9. Children's privacy
Inboxili is a business tool and isn't directed at children. We don't knowingly collect account data from anyone under 16. If you believe a child has created an account, contact us and we'll remove it.
10. Changes to this policy
We may update this policy as the product changes. Material changes will be communicated by email or an in-product notice before they take effect.
11. Your rights
You can access, export, correct, or delete your account data at any time from your account settings. If you have questions about your data or this policy, contact us at privacy@inboxili.com.