Clean Gmail
FAQ

Privacy

Terms of ServicePrivacy PolicyFAQContact support

Privacy Policy

How InboxGone accesses, uses, stores, and protects account and Gmail data.

Effective: 10 August 2026 · Controller contact: [email protected]

1. Controller and scope

InboxGone, operated from Portugal, is the controller for account, support, and service-operation data described here. Google remains responsible for Google services and your Google Account. Contact [email protected] for privacy requests.

2. Data we process

  • Account data: Google name, email address, profile image, account identifiers, login times, and consent record.
  • OAuth data: access and refresh tokens, granted scopes, and token expiry information needed to connect Gmail.
  • Gmail-derived data: message identifiers, label identifiers, filter queries, counts, sizes and cleanup state required for previews, background processing, History and Undo.
  • Support data: ticket text, replies, status, and attachments you choose to upload.
  • Technical and security data: request, deployment, worker, error and audit information reasonably needed to operate and protect the service.

3. How Gmail data is used

Gmail data is used only to provide user-facing analysis, preview, cleanup, background processing, History and Undo features that you request. We do not sell Gmail data, use it for advertising, or use it to train general-purpose AI or machine-learning models. Human access to message content is not part of normal operation and would occur only with your specific permission, for necessary security investigation, or where legally required.

Google Limited Use: InboxGone’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

4. Purposes and legal bases

  • Provide the service and requested Gmail actions: performance of the service agreement and your OAuth authorization.
  • Secure, troubleshoot and prevent abuse: legitimate interests in reliable and secure operation.
  • Support communications and transactional email: performance of the service and legitimate interests in responding to requests.
  • Meet legal obligations and handle claims: compliance with law and legitimate interests.
  • Optional communications, if introduced later: consent where required.

These legal bases correspond, as applicable, to Article 6(1)(a), (b), (c) and (f) of the General Data Protection Regulation (GDPR). This notice is provided in accordance with Articles 12 and 13 GDPR and Portugal’s Law no. 58/2019.

5. Service providers and transfers

We use carefully selected service providers where necessary to deliver authentication, cloud infrastructure, data storage, network protection, communications and billing. They may process personal data only for the relevant service purpose and under applicable contractual and security safeguards. Where personal data is transferred outside the EEA, we use a lawful mechanism under Articles 44–49 GDPR, such as an adequacy decision or Standard Contractual Clauses, where required.

6. Retention

Account and OAuth data are retained while your account is active. Cleanup records are retained to provide History and Undo until deleted under the service’s retention process. Support records and attachments are retained while needed to resolve the case and for a reasonable follow-up period. Security and audit records may be retained for a limited period appropriate to investigation and legal obligations. We will publish precise retention periods before public launch and shorten or delete data when it is no longer necessary.

7. Security

We apply modern technical and organisational safeguards appropriate to the risks involved, supported by established cloud and network-security services. We regularly assess and improve these protections in line with Article 32 GDPR. No online service can guarantee absolute security, and we will make any legally required breach notifications under Articles 33 and 34 GDPR.

8. Cookies

InboxGone currently uses essential authentication and security cookies needed to sign in and maintain a session. We do not currently use advertising cookies. If optional analytics or marketing cookies are introduced, we will provide appropriate notice and consent controls before setting them where required.

9. Your rights

Subject to Articles 15–22 GDPR and applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. You may also revoke InboxGone in your Google Account permissions. Send requests to [email protected]. We may need to verify your identity.

You may complain to Portugal’s data-protection authority, the Comissão Nacional de Proteção de Dados (CNPD), or the supervisory authority where you live or work.

10. Children

InboxGone is not directed to children and the private beta is limited to users aged 18 or older.

11. Changes

We will update the effective date when this Policy changes. If a change materially affects Google user data or your rights, we will provide prominent notice and request renewed consent where required.

© 2026 InboxGone
TermsPrivacyFAQ