Trust Center
Everything you need to know about how TheInboxPilot handles your data and what controls you have.
What Data We Access
When you connect your Gmail account, TheInboxPilot accesses the following data through Google’s Gmail API:
gmail.modifyRead, organize, and manage your inbox- Message metadata: sender, recipient, subject, date, and labels (Inbox, Spam, Promotions, Social, Updates, Forums, Important, Starred, Unread)
- Ability to move emails between tabs and folders, apply labels, mark as read, star, and archive
Powers: Inbox Triage, Category Fix, Smart Rules, Bulk Cleanup, Sender Insights
gmail.sendSend emails on your behalf- Ability to send replies from your Gmail account when you explicitly approve them
- Replies appear in your Sent folder with your identity
Powers: Smart Replies
Why We Need Each Permission
| Feature | Scope Required | Why It’s Needed |
|---|---|---|
| Inbox Triage | gmail.modify | Reads message metadata to categorize emails. Applies labels and marks as read. |
| Category Fix | gmail.modify | Moves emails between Gmail tabs (Promotions to Primary, etc.). Only the Gmail API can change tab assignments. |
| Smart Rules | gmail.modify | Applies labels, stars, marks as read, and archives based on your rules. |
| Bulk Cleanup | gmail.modify | Batch-archives or marks emails as read. Runs only when you initiate it. |
| Sender Insights | gmail.modify | Reads message metadata (sender, subject, date) to generate analytics. Does not read message bodies. |
| Smart Replies | gmail.send | Sends replies through your Gmail account so they appear in your Sent folder. You approve every reply before it sends. |
Data Retention
- Active account: We retain your data only while your TheInboxPilot account is active.
- After disconnection: When you disconnect your Google account or delete your TheInboxPilot account, all associated data is permanently deleted within 30 days.
- Activity log: Activity log entries are retained for the life of your account. After deletion, they are removed along with all other data.
How to Revoke Access
You can stop TheInboxPilot from accessing your Gmail account at any time:
- From TheInboxPilot: Go to Settings > Disconnect Account. This immediately stops all access and schedules your data for deletion.
- From Google: Visit myaccount.google.com/permissions, find TheInboxPilot, and click Remove Access.
Either method immediately stops all Gmail API access. We delete your data within 30 days regardless of which method you use.
Data Encryption
- All data in transit is encrypted using TLS 1.3.
- OAuth access tokens and refresh tokens are encrypted at rest using AES-256-GCM.
- We do not sell, rent, or share your data with any third party.
- We do not use your data for advertising or marketing.
- Access to production data is strictly limited to authorized personnel and requires multi-factor authentication.
Google API Compliance
TheInboxPilot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
For questions about data handling, security, or to exercise your data rights:
Email: support@theinboxpilot.in