legal
Privacy Policy
Last updated: June 27, 2026
Who we are
AgentInbox (agentinbox.pro) provides receive-only inbound email processing for developers and agent builders. This Privacy Policy describes how we handle personal data when you use our website, dashboard, and services.
Contact us about privacy at privacy@agentinbox.pro.
What we collect
Depending on how you use agentinbox.pro, we may process:
- Account data — email address and display name from Google sign-in, workspace name, and membership records.
- Early-access waitlist — email address (and optional display name) when you request access before your account is allowlisted.
- Inbound email content — sender and recipient addresses, subject, body text and HTML, attachments, message headers, raw
.emlfiles, and delivery metadata. This often includes personal data about third parties who email your configured addresses. - Configuration data — webhook URLs, domain names, DNS verification records, and API key identifiers (we store hashed keys, not plaintext secrets).
- Payment data — when you purchase a domain, Stripe collects payment and billing information. We receive limited payment metadata (such as checkout session IDs and your account email).
- Operational data — IP address, user agent, request paths, and similar log data for security, abuse prevention, rate limiting, and error monitoring.
- Cookies — session cookies for sign-in and, for the instant demo, a short-lived cookie that ties your browser to a demo inbox session.
How we use data
We use personal data to:
- Provide, operate, and improve the service (contract).
- Authenticate users, prevent abuse, and secure the platform (legitimate interest).
- Process domain purchases through Stripe (contract).
- Deliver inbound email to your configured webhooks (contract).
- Notify waitlisted users about early access when you have requested it (consent or legitimate interest, depending on context).
- Comply with legal obligations and respond to lawful requests.
Inbound email and your role
When you configure agentinbox.pro to receive mail for your domains, you decide why inbound mail is collected and how it is used in your application. For that inbound email content, you are generally the data controller and AgentInbox acts as a data processor, handling mail on your instructions (including webhook delivery and retention settings). You are responsible for having a lawful basis to collect and use data in the messages sent to your addresses.
Retention
Inbound email and related records are retained according to your workspace plan:
| Plan | Retention |
|---|---|
| Free | 14 days |
| Build | 30 days |
| Scale | 90 days |
Account and configuration data is kept while your workspace is active and for a reasonable period afterward unless you request deletion or we must retain records for legal reasons.
Sharing and sub-processors
We do not sell your personal data. We share data with service providers that help us runagentinbox.pro:
| Provider | Purpose | Location |
|---|---|---|
| Sign-in (OAuth) and optional Google Ads measurement | United States | |
| Stripe | Payment processing for domain purchases | United States |
| Sentry | Error monitoring and request telemetry | United States |
| Neon | Database hosting | United States |
| Vercel | Application hosting | United States |
| Cloudflare | DNS, CDN, and object storage | United States / global edge |
| Domain registrars | Domain registration and DNS management | Varies by registrar |
Inbound email content is delivered to webhook URLs you configure. You control those endpoints and their privacy practices.
Payment processing (Stripe)
We use Stripe to process domain purchase payments. Stripe collects and processes personal data including payment method details, billing address, and device information to operate and improve its services, including fraud prevention and authentication. Stripe uses this information as described in Stripe's Privacy Policy.
Cookies
We use strictly necessary cookies for authentication and the optional instant demo inbox. When configured, we load Google's gtag.js for Google Ads measurement and conversion tracking; Google may set advertising or analytics cookies as described in Google's Privacy Policy. Error monitoring through Sentry may receive IP address and request metadata as part of operating the service.
Security
We use HTTPS for dashboard and webhook delivery, hash API keys at rest, and apply reasonable technical and organizational measures to protect data. No method of transmission or storage is completely secure.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. To exercise these rights, contact privacy@agentinbox.pro. We will respond as required by applicable law.
California residents: We do not sell or share personal information for cross-context behavioral advertising. You may contact us with privacy requests as described above.
Children
agentinbox.pro is not directed at children under 16, and we do not knowingly collect personal data from children.
International users
We are based in the United States. If you access the service from other regions, your data may be processed in the United States and other locations where our sub-processors operate.
Changes
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may be communicated through the dashboard or by email where appropriate.
Related documents
See also our Terms of Service.