Privacy Policy.
The left column is the formal legal policy. The right column is what it actually means — including proof you can verify in the code.
Last updated: May 2026
Account data: When you register, we collect your name, email address, and authentication credentials via Google or Microsoft OAuth.
Usage data: We record verdict counts per filter run (junk, review, or legitimate), timestamps, and your account settings.
Email content: We do not collect, store, or retain email content. Email text is transmitted transiently to Anthropic's API for scoring and is not retained by us at any point.
Payment data: Billing is handled entirely by Stripe. We do not store payment card information.
We use collected information solely to:
— Provide and operate the email filtering service
— Authenticate your identity and maintain your account
— Process subscription payments via Stripe
— Send transactional emails via Resend
— Monitor service performance and diagnose issues
We do not use your data for advertising, profiling, or sale to third parties.
To score each email, the sender, subject, and up to 1,500 characters of the body are transmitted to Anthropic's Claude API. This transmission is transient — we do not retain a copy at any point.
Anthropic retains API request data for up to 7 days for abuse monitoring, after which it is permanently deleted. Anthropic's terms explicitly prohibit using API request data for model training.
By using Inbox Filter you consent to this transient processing by Anthropic under their privacy policy.
Anthropic's privacy policy →
Account data is stored in a PostgreSQL database hosted on Railway (US region). We retain account data for as long as your account is active.
Filter log records (verdict counts and timestamps only) are retained to power your dashboard statistics.
You may disconnect your inbox or delete your account at any time from the Settings page. Upon account deletion, all personal data is removed within 30 days.
Inbox Filter uses the following third-party services:
Google / Gmail API — OAuth and inbox access
Microsoft / Outlook API — OAuth and inbox access
Anthropic Claude API — Email scoring
Stripe — Payment processing
Railway — Cloud hosting and database
Resend — Transactional email delivery
Each operates under their own privacy policy.
You may disconnect your inbox at any time from Settings, which immediately revokes our access to your email account.
You have the right to access or delete your personal data. Account deletion can be initiated from the Settings page.
If you are in the European Economic Area, you have additional rights under GDPR including data portability and the right to lodge a complaint with a supervisory authority.
We may update this policy from time to time. Material changes will be communicated by email. Continued use of the service after changes take effect constitutes acceptance of the updated policy.