Privacy Policy

Last updated 3 August 2026

Who we are

AdaptoInbox is operated by AdaptoIT LLC. It connects to your Gmail or Microsoft 365 mailbox and uses AI to sort, categorise and flag your email according to rules you define.

This policy explains exactly what we access, what we send elsewhere, what we keep, and how to make us delete it.

What we access, and why

When you connect a mailbox you grant specific permissions. We request the narrowest set that makes the product work:

  • Read and modify mail — to read incoming messages so they can be categorised, and to move, label, flag or archive them as your rules direct.
  • Mailbox settings (Microsoft only) — to create your categories in your mailbox so they appear in colour in Outlook.
  • Send mail — used only to send your own daily briefing to you, and only if you turn it on.
  • Calendar — to create events when you turn an email into one.
  • Tasks — to add a follow-up to your to-do list when you ask.

We never read mail in a mailbox you have not connected, and disconnecting an inbox stops all access to it immediately.

What we send to an AI model

Categorising email requires a language model to read it. For each incoming message we send:

  • The sender's name and address
  • The subject line
  • The first 1,000 characters of the message body

We do not send the full message body for categorisation, and we do not send attachments at any point.

If you explicitly ask for a suggested reply, we send the subject and the first 2,000 characters of that one message so a draft can be written. That happens only when you click the button, never automatically.

On adaptoinbox.com the model is Claude, operated by Anthropic. Content sent to Anthropic's API is used solely to return a result to you. It is not used to train Anthropic's models or ours. For customers on a dedicated deployment, the model runs inside your own Microsoft Azure subscription and your email content never reaches our infrastructure or Anthropic's at all.

What we store

For each processed message we keep a record containing:

  • The sender's name and address, the subject line, and when it arrived
  • The message's ID in your mail provider, so we don't process it twice
  • Which categories were assigned and what action was taken

We do not store the body of your email. The preview sent for categorisation is held in memory for the duration of the request and is never written to our database.

We also store your account details, the categories and rules you create, your follow-up list, and your conversations with the setup assistant.

Access tokens for your mailbox are encrypted at rest using AES-256-GCM with a key held separately from the database.

Google user data and Limited Use

AdaptoInbox's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we do not:

  • Sell, rent or trade your Google user data to anyone
  • Use it for advertising, or transfer it to advertising platforms or data brokers
  • Use it to develop, improve or train generalised AI or machine-learning models
  • Allow humans to read it, except with your explicit consent for a specific support request, where required by law, or where necessary for security purposes such as investigating abuse

Google user data is used only to provide and improve the features you can see in the product.

Who else processes your data

We use a small number of providers to run the service. Each processes data only to deliver the service to you:

  • Vercel — hosting for the application
  • Neon — the database where your records are stored
  • Anthropic — the Claude model that categorises email and drafts replies
  • Google and Microsoft — your mail provider, accessed with the permissions you granted
  • Stripe — payment processing, if and when paid plans are introduced. Stripe receives billing details; it does not receive your email data.

We do not sell your data, and we do not share it with anyone for their own purposes.

How long we keep it, and how to delete it

Processing records are kept while your account is open so the product can show your history and avoid reprocessing the same message.

Deleting your account permanently deletes your data. Use Delete Account in Settings. This removes your user record and everything attached to it — connected mailboxes and their stored tokens, categories, rules, processing history, follow-ups and chat history. It is immediate and cannot be undone.

Disconnecting a single mailbox removes that mailbox's stored tokens and ends our access to it, while leaving the rest of your account intact.

You can also revoke our access directly at any time, from your Google account permissions or your Microsoft account.

Nothing we delete on our side changes your actual mailbox. Emails we moved or labelled stay where they are, in your control.

Security

Mailbox tokens are encrypted at rest. All traffic is served over HTTPS. Access to production systems is limited to the people who operate the service.

No system is perfectly secure. If we discover a breach affecting your data, we will notify you.

Your rights

Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to certain processing. Account deletion is available to everyone, immediately, in Settings. For anything else, contact us and we will action it.

Children

AdaptoInbox is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

If we change this policy we will update the date at the top. If a change materially affects how we handle your email data, we will tell you in the product before it takes effect.

Contact

Questions about privacy, or a request about your data: privacy@adaptoinbox.com

AdaptoIT LLC