1. Scope and operator
InboxUnion is a personal, self-hosted email aggregation application for accounts its operator is authorized to access. This policy applies to the InboxUnion website and application at inboxunion.site.
2. Google data InboxUnion accesses
When you connect a Google account through Google OAuth, InboxUnion requests only identity and read-only Gmail permissions. Depending on the features you use, the application may access:
- Your Google Account email address and basic account identifier.
- Gmail messages, threads, headers, labels, dates, senders, recipients, subjects, and message content needed to display and search mail.
- Attachment metadata such as file name, media type, and size. Attachment bodies are not downloaded during normal synchronization.
- OAuth access and refresh credentials, Gmail history identifiers, watch state, and synchronization status needed to keep the authorized inbox current.
3. How Google data is used
Google user data is used only to provide user-facing InboxUnion features:
- Combine messages from authorized accounts into one inbox.
- Build and query a local search index.
- Display messages and complete conversation threads.
- Synchronize new or changed mailbox data.
- Identify, manage, and disconnect authorized accounts.
InboxUnion does not use Google user data for advertising, credit decisions, surveillance, or the creation of marketing profiles. It does not sell Google user data.
4. Storage and protection
OAuth credentials, account records, indexed message data, attachment metadata, and synchronization state are stored in the operator-controlled application environment. OAuth credentials are encrypted at rest. Application API keys are stored as hashes rather than raw keys. Access to application routes is authenticated.
No method of storage or transmission is completely risk-free. The operator is responsible for securing the host, database, encryption keys, service-account credentials, backups, and network access used for a self-hosted installation.
5. Sharing and transfers
InboxUnion does not sell or rent Google user data. Data is not shared with third parties except with Google APIs and the infrastructure providers required to operate the application, or when disclosure is legally required. Those providers may process data only as necessary to deliver their infrastructure services.
6. Retention and deletion
Connected-account data is retained while that account remains connected or while the local installation keeps it. Disconnecting an account removes its stored OAuth credentials, account record, indexed messages, attachment metadata, and synchronization state. See the Data Deletion Instructions for exact steps.
Revoking access from your Google Account stops future access, but does not by itself delete data already indexed by the local application. Use InboxUnion's remove-account command as well.
7. Your choices
- Choose which Google accounts to connect.
- Review the requested permissions before authorizing.
- Disconnect any account and delete its local data.
- Revoke InboxUnion from your Google Account connections page.
- Request help with access or deletion through the support contact below.
8. Google API Services User Data Policy
InboxUnion's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
9. Changes and contact
This policy may be updated when the application or its data practices change. The revised date at the top will be updated. Questions or privacy requests can be sent to support@inboxunion.site.
Use of InboxUnion is also subject to the Terms of Service.