InboxShare
Privacy policy
Effective / last updated: August 5, 2026
What InboxShare is
InboxShare is a multi-user collaboration workspace for managing a company Gmail inbox. It connects to authorized Gmail accounts or Google Workspace mailboxes, synchronizes conversations into a shared workspace, and helps teammates assign work, leave internal notes, draft replies with optional AI assistance, and send human-approved replies through Gmail. Gmail remains the email provider and source of truth for delivery.
Who this policy covers
This policy describes how the InboxShare application processes information when you sign in, join a workspace, connect mailboxes, or use collaboration and AI features. The organization that operates a given deployment (for example, your employer or the team that invited you) may provide additional notices. This page does not invent a specific company entity, mailing address, or jurisdiction.
Information we process
- Account identity. Sign-in uses email and password via Supabase Auth. We store identifiers needed for membership such as email address, display name when provided, and authentication subject identifiers.
- Workspace and membership data. Organization name and slug, member roles, invitations, and related settings.
- Gmail / Workspace connection data. Connected mailbox addresses, connection status, sync health metadata, import-mode settings, and encrypted mailbox refresh credentials (individual OAuth) or short-lived delegated access tokens minted server-side for Workspace domain-wide delegation. Refresh tokens are encrypted at rest and are not exposed to the browser.
- Synchronized email content. For mailboxes your workspace is authorized to access, InboxShare stores a working copy of conversation metadata and message content needed for collaboration (for example subjects, snippets, plain-text bodies derived from Gmail, participants, timestamps, Gmail identifiers, and sync/source state). Access is limited by tenant and mailbox grants.
- Collaboration content. Assignments, workflow status, internal notes, conversation tags, activity events, and draft/send records created in InboxShare.
- Company knowledge for AI. Text or other approved knowledge sources your workspace owners add for grounded drafting, plus related processing metadata.
- Operational and security data. Structured logs and audit events for sync jobs, configuration changes, and security-relevant actions. Operational logging is designed to avoid email bodies, tokens, and other sensitive payloads.
How we use information
We use this information to provide InboxShare: authenticate users, isolate tenants, synchronize authorized mailboxes, power shared inbox workflows, generate optional AI-assisted drafts grounded in your workspace knowledge, send human-approved replies through Gmail, and support administration, troubleshooting, and security. We do not sell customer data. We do not use synchronized email content for advertising. Subscriptions, payments, and billing are outside the product scope of InboxShare.
Google and Gmail data
Connecting a mailbox is a separate authorization from signing in to InboxShare. Owners authorize Gmail access through Google OAuth and/or Google Workspace domain-wide delegation configured by a Workspace administrator. InboxShare requests only the Google scopes needed for the implemented features (including Gmail modify capability used for sync and sending). Google's own terms and privacy notices also apply to Google services. Disconnecting a mailbox removes local credentials when possible and stops synchronization for that mailbox. Mailbox content purge and organization deletion controls are available to authorized owners in Settings → Data.
AI processing
When a user requests an AI draft, InboxShare may send limited authorized conversation context and approved company knowledge to OpenAI to generate an editable draft. AI output is reviewed and edited by a human before any send; InboxShare does not automatically send AI-generated replies. Draft persistence stores the editable draft and related metadata (for example model/prompt version and token usage counters) rather than unrestricted provider transcripts. Workspace and environment controls can disable AI assistance. Provider data-handling terms are governed by the OpenAI agreement for the deployment; confirm training and retention settings with that agreement.
Service providers
Depending on configuration, InboxShare relies on:
- Supabase — authentication, database, and related backend services
- Netlify — application hosting and scheduled/background functions
- Google — sign-in (when used), OAuth, Gmail API, and Workspace APIs
- OpenAI — optional AI draft generation and related embeddings
These providers process data only as needed to operate the service for your deployment.
Sharing
We share information with service providers as described above, with members of your workspace according to roles and mailbox grants, and when required to comply with law or protect the security of the service. We do not sell personal information.
Retention and deletion
InboxShare retains synchronized mailbox content and collaboration data while needed to provide the workspace features you use. Owners can disconnect mailboxes, purge InboxShare's stored copy of a mailbox (without deleting Gmail itself), export organization data, and request organization deletion from Settings → Data. OAuth credentials are removed on disconnect or deletion workflows when those flows complete. Exact default retention windows for logs and backups are deployment- and operations-dependent; this policy does not invent fixed day counts.
Security
InboxShare is built with tenant isolation (including database row-level security and mailbox grants), HTTPS, encrypted storage of Gmail refresh tokens, server/client secret boundaries, security headers, and audit logging for significant configuration actions. No method of transmission or storage is perfectly secure.
Your choices and rights
Depending on your role, you may update profile information available in the product, leave a workspace when membership controls allow, ask an owner to adjust mailbox grants, disconnect mailboxes, export data, or delete the organization. If applicable law provides additional rights (for example access, correction, or deletion), contact the operator of your deployment using the contact details below. Response processes may vary by operator and jurisdiction.
Cookies and similar technologies
InboxShare uses essential cookies and similar storage for authentication sessions and short-lived OAuth transaction state. The product does not currently ship a third-party marketing or product-analytics SDK in the application codebase. Your browser or hosting environment may still generate ordinary technical request logs.
Children's privacy
InboxShare is intended for business and team use. It is not directed to children, and we do not knowingly collect personal information from children for the purpose of using this service.
Changes
We may update this policy as the product or providers change. The effective / last-updated date at the top of this page will change when material updates are published. Continued use after an update means you acknowledge the revised policy.
Contact
No public support email is configured for this deployment. For privacy questions, contact the organization administrator who operates or invited you to this InboxShare workspace.