agentinbox
ProductDocsBlogGet startedPricing
receivingSign inCreate instant inbox

legal

Privacy Policy

Last updated: June 27, 2026

Who we are

AgentInbox (agentinbox.pro) provides receive-only inbound email processing for developers and agent builders. This Privacy Policy describes how we handle personal data when you use our website, dashboard, and services.

Contact us about privacy at privacy@agentinbox.pro.

What we collect

Depending on how you use agentinbox.pro, we may process:

  • Account data — email address and display name from Google sign-in, workspace name, and membership records.
  • Early-access waitlist — email address (and optional display name) when you request access before your account is allowlisted.
  • Inbound email content — sender and recipient addresses, subject, body text and HTML, attachments, message headers, raw .eml files, and delivery metadata. This often includes personal data about third parties who email your configured addresses.
  • Configuration data — webhook URLs, domain names, DNS verification records, and API key identifiers (we store hashed keys, not plaintext secrets).
  • Payment data — when you purchase a domain, Stripe collects payment and billing information. We receive limited payment metadata (such as checkout session IDs and your account email).
  • Operational data — IP address, user agent, request paths, and similar log data for security, abuse prevention, rate limiting, and error monitoring.
  • Cookies — session cookies for sign-in and, for the instant demo, a short-lived cookie that ties your browser to a demo inbox session.

How we use data

We use personal data to:

  • Provide, operate, and improve the service (contract).
  • Authenticate users, prevent abuse, and secure the platform (legitimate interest).
  • Process domain purchases through Stripe (contract).
  • Deliver inbound email to your configured webhooks (contract).
  • Notify waitlisted users about early access when you have requested it (consent or legitimate interest, depending on context).
  • Comply with legal obligations and respond to lawful requests.

Inbound email and your role

When you configure agentinbox.pro to receive mail for your domains, you decide why inbound mail is collected and how it is used in your application. For that inbound email content, you are generally the data controller and AgentInbox acts as a data processor, handling mail on your instructions (including webhook delivery and retention settings). You are responsible for having a lawful basis to collect and use data in the messages sent to your addresses.

Retention

Inbound email and related records are retained according to your workspace plan:

PlanRetention
Free14 days
Build30 days
Scale90 days

Account and configuration data is kept while your workspace is active and for a reasonable period afterward unless you request deletion or we must retain records for legal reasons.

Sharing and sub-processors

We do not sell your personal data. We share data with service providers that help us runagentinbox.pro:

ProviderPurposeLocation
GoogleSign-in (OAuth) and optional Google Ads measurementUnited States
StripePayment processing for domain purchasesUnited States
SentryError monitoring and request telemetryUnited States
NeonDatabase hostingUnited States
VercelApplication hostingUnited States
CloudflareDNS, CDN, and object storageUnited States / global edge
Domain registrarsDomain registration and DNS managementVaries by registrar

Inbound email content is delivered to webhook URLs you configure. You control those endpoints and their privacy practices.

Payment processing (Stripe)

We use Stripe to process domain purchase payments. Stripe collects and processes personal data including payment method details, billing address, and device information to operate and improve its services, including fraud prevention and authentication. Stripe uses this information as described in Stripe's Privacy Policy.

Cookies

We use strictly necessary cookies for authentication and the optional instant demo inbox. When configured, we load Google's gtag.js for Google Ads measurement and conversion tracking; Google may set advertising or analytics cookies as described in Google's Privacy Policy. Error monitoring through Sentry may receive IP address and request metadata as part of operating the service.

Security

We use HTTPS for dashboard and webhook delivery, hash API keys at rest, and apply reasonable technical and organizational measures to protect data. No method of transmission or storage is completely secure.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. To exercise these rights, contact privacy@agentinbox.pro. We will respond as required by applicable law.

California residents: We do not sell or share personal information for cross-context behavioral advertising. You may contact us with privacy requests as described above.

Children

agentinbox.pro is not directed at children under 16, and we do not knowingly collect personal data from children.

International users

We are based in the United States. If you access the service from other regions, your data may be processed in the United States and other locations where our sub-processors operate.

Changes

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may be communicated through the dashboard or by email where appropriate.

Related documents

See also our Terms of Service.

agentinbox
ProductDocsBlogAdd your domainPricingPrivacyTerms
receive-only · no outbound smtp