Privacy Policy
How Easterday Strategy Group LLC ("we", "us") handles your information when you use Inbox Triage at getinboxtriage.com.
What Inbox Triage does
Inbox Triage connects email accounts you already own to the AI agent you choose (for example Claude or ChatGPT) over MCP. Your agent can list, read, draft, label, archive, and trash messages within a recent triage window, and send a message only after you approve it in chat. This website is for your account, connecting inboxes, billing, and documentation.
Information we collect
- Account details: your name, email address, and password (stored only as a salted hash). If you sign in with Google, we receive your name, email address, and Google account ID.
- Mailbox connections: OAuth tokens for Google and Microsoft, an Apple app-specific password for iCloud, or a mailbox password for other IMAP accounts. These are encrypted at rest (AES-256-GCM).
- Synced mail: message headers and plain-text bodies for the newest messages in the folders you select (about 300 per folder for iCloud, IMAP, and Microsoft; about 40 for Gmail), plus attachment names and sizes. We do not store attachment files; when your agent asks for one, it is passed through once.
- Agent access: API keys (stored only as hashes) and the OAuth grants you approve for your agent.
- Billing: your plan, subscription status, and Stripe customer and subscription IDs. Card details are handled by Stripe and never reach us.
- Activity: a short log of account events, such as connecting or disconnecting an inbox, sync errors, drafts and approved sends, label and archive changes, and API key changes.
- Marketing preference: whether you opted in to product updates, and when.
How we use it
- To run the service: sync your selected folders, let your agent act on your instructions, and keep your account secure.
- To send account emails you need, such as email confirmation and password reset. Stripe sends payment receipts.
- To send product updates and tips, only if you opted in. Every such email has an unsubscribe link, and you can change this in Settings at any time.
- To troubleshoot problems and protect the service from abuse.
We do not sell your information, do not use your email content for advertising, and do not use your email content to train AI models.
Google user data
Inbox Triage's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Gmail data only to provide the features you use: syncing your triage window, and letting the AI agent you connect read, draft, label, archive, trash, and (after your approval) send mail.
- We transfer Gmail data only to the AI agent you connect, at your direction, to provide those features, or as needed for security or to comply with the law.
- We do not use Gmail data for advertising, do not sell it, and do not use it to develop or train generalized AI or machine learning models.
- No person at Inbox Triage reads your Gmail data unless you give us permission for a specific message, it is needed for security or to investigate abuse, or the law requires it.
Signing in with Google uses only your basic profile (name and email address). Gmail access is requested separately, only when you choose to connect a Gmail inbox.
Your AI agent
When your agent reads your mail through Inbox Triage, that content is sent to the AI provider you chose and handled under that provider's own terms and privacy policy. You control which agent you connect and can revoke its access at any time.
Service providers
These companies process data on our behalf so the service can run.
| Provider | Role |
|---|---|
| Fly.io | Application hosting, storage, and database |
| Stripe | Billing and payments |
| Resend | Sending account emails and product updates |
| Cloudflare | Domain name service and forwarding of support email |
| Sign in with Google, and Gmail and Google Workspace connections | |
| Microsoft | Outlook and Microsoft 365 connections |
Retention and deletion
- Disconnecting an inbox deletes its stored credential and synced messages.
- Deleting your account in Settings removes your account, inboxes, synced mail, stored credentials, API keys, and agent access, and cancels your subscription.
- Database backups roll over and deleted data leaves them within 30 days.
- Stripe keeps billing records as required for tax and accounting.
You can also revoke access from the provider side at any time: Google account permissions, Microsoft app permissions, or Apple app-specific passwords.
Security
Credentials are encrypted at rest, connections use HTTPS, and passwords are never requested in chat. See Security for details. If a breach ever affects your data, we will tell you promptly and as the law requires.
Your choices and rights
You can see and change your account details in Settings, opt out of product updates, and delete your account. To request a copy of your data or ask a question, email help@getinboxtriage.com. Depending on where you live, you may have additional rights to access, correct, or delete your information; we will respond to requests within 30 days.
Children
Inbox Triage is not intended for anyone under 18, and we do not knowingly collect information from children.
Changes
If we change this policy, we will update the date below, and we will email you before material changes take effect.
Last updated: September 17, 2026. Easterday Strategy Group LLC, Florida. Contact: help@getinboxtriage.com. See also Terms of Service.