InBoard Privacy Policy

Last updated: August 18, 2026

InBoard provides an email accountability service that helps users identify commitments, responsibilities, deadlines, follow-ups, waiting states, and other items requiring attention. This Privacy Policy explains how InBoard collects, uses, stores, shares, and protects personal information when you use the service.

Questions or privacy requests can be sent to hello@useinboard.com.

Information InBoard processes

When you create or use an InBoard account, we may process account information such as your name, email address, authentication information, connected mailbox information, subscription status, and product usage information.

When you connect Gmail, Google Workspace, Microsoft Outlook, or Microsoft 365, InBoard accesses mailbox information necessary to provide its email-accountability features.

Depending on the message and provider, this processing may include message subjects and content, sender and recipient information, timestamps, conversation context, provider message and thread identifiers, and limited attachment metadata such as filenames. InBoard does not access or analyze attachment file contents as part of its normal mailbox-processing flow.

InBoard also necessarily processes information about people who communicate with an InBoard user, such as sender or recipient names and email addresses and information contained in their communications. We use this information only as necessary to provide, secure, and maintain the service for the InBoard user.

How we use mailbox information

InBoard uses mailbox information to provide its core user-facing functionality, including identifying and maintaining:

  • commitments and responsibilities;
  • tasks and follow-ups;
  • deadlines and urgency;
  • whether action is expected from the user or another participant;
  • changes in responsibility or status;
  • daily recaps and other accountability information.

We do not use mailbox information for advertising, advertising personalization, credit decisions, data brokerage, or unrelated profiling, and we do not sell mailbox information.

Gmail and Google Workspace data

When you connect a Google account, InBoard requests read-only Gmail access. InBoard does not use this permission to send, modify, or delete your Gmail messages.

Google Workspace information is accessed and used only to provide and improve InBoard's user-facing email-accountability features, maintain and secure those features, comply with applicable law, and otherwise as permitted by Google's applicable policies.

InBoard's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google's Limited Use requirements apply to both source information received through Google APIs and information derived from it. Accordingly, the limitations described in this section also apply to accountability information InBoard derives from Gmail messages.

We do not transfer Google Workspace information to advertising platforms, data brokers, or information resellers, and we do not use it for advertising, retargeting, personalized advertising, or lending or credit-worthiness purposes.

Human access to Google Workspace message content is not part of InBoard's routine operations. Human access is limited to circumstances permitted by Google's policies, such as where a user affirmatively authorizes access to specific information, access is necessary to investigate a security issue, bug, or abuse, or access is required by law.

AI processing

InBoard uses OpenAI's API to perform parts of its email-accountability analysis.

To provide this functionality, information transmitted to OpenAI may include message subjects, limited message excerpts, sender and participant information, timestamps, conversation context, and previously derived accountability state. Some processing stages apply additional redaction or pseudonymization before transmission.

InBoard does not send email attachment file contents to OpenAI as part of its normal mailbox-processing flow.

OpenAI processes this information on InBoard's behalf to provide the requested AI functionality. InBoard's OpenAI API organization is not opted into voluntary sharing of API inputs or outputs for model improvement or training, and InBoard configures its applicable OpenAI requests not to request provider-side application storage.

What InBoard stores

InBoard is designed to minimize durable storage of source email content.

During mailbox processing, source message content may be held transiently in memory so that InBoard can analyze it. InBoard does not maintain a durable database copy of source email subjects, body previews, or raw message payloads as part of its normal processing architecture.

InBoard does store information derived from mailbox activity that is needed to provide the service. Depending on the circumstances, this can include:

  • thread and provider identifiers;
  • participant information;
  • accountability status and ownership;
  • tasks and commitments;
  • deadlines and waiting states;
  • summaries and descriptions;
  • evidence or excerpts supporting an accountability item;
  • relationship and interaction state;
  • recap information;
  • sync and operational metadata.

Some derived fields, particularly evidence or commitment information, may contain limited language originating from an email message. Therefore, although InBoard does not maintain a durable raw-email archive, some stored accountability information may remain personal information derived from email.

OAuth credentials

InBoard stores OAuth access and refresh credentials where required to maintain a connected mailbox. These credentials are encrypted at rest.

Disconnecting a mailbox stops future synchronization, attempts to revoke the applicable provider authorization, and removes the associated OAuth credentials and mailbox-scoped InBoard data according to the deletion process described below.

Retention and minimization

InBoard retains personal information only for as long as reasonably necessary for the purposes for which it is processed, subject to legal, security, billing, and operational requirements.

Active accountability information may remain while it is needed to provide the service.

For resolved accountability items, InBoard automatically minimizes content-heavy derived information after approximately 90 days.

Certain operational records have shorter or longer retention periods according to their purpose. For example, terminal job records and content-bearing recap payloads are generally deleted or minimized after approximately 30 days, while certain operational sync and state-history records may be retained for up to approximately 365 days.

Expired OAuth authorization-state records are removed through automated retention processing.

These periods do not require InBoard to retain information that is no longer necessary, and information may be deleted sooner when a mailbox or account is deleted.

Disconnecting a mailbox

You can disconnect a connected mailbox through InBoard.

When you disconnect a mailbox, InBoard stops syncing it, attempts to revoke the provider authorization, removes the associated OAuth credentials, and deletes mailbox-scoped messages, threads, tasks, participants, and related accountability information.

Certain user-level information that is not exclusively attributable to the disconnected mailbox may remain where necessary to operate the remaining InBoard account. Certain recap-delivery records may be retained in minimized form without the content-bearing payload.

Deleting your InBoard account

You can delete your InBoard account through profile settings.

Account deletion removes your InBoard profile, connected mailboxes, OAuth credentials, mailbox-derived accountability information, and sign-in access, subject to limited information that we may need to retain for legal, security, fraud-prevention, financial, or compliance purposes.

Provider authorizations are revoked on a best-effort basis as part of mailbox/account deletion.

Service providers and international processing

InBoard uses service providers to operate the service. Depending on how you use InBoard, these may include:

  • Google — Gmail API and Google authentication;
  • Microsoft — Microsoft Graph and Microsoft authentication;
  • OpenAI — AI-assisted email-accountability analysis;
  • Supabase — database and authentication services;
  • Railway — backend application hosting;
  • Vercel — frontend hosting and delivery;
  • MailerSend — transactional email and daily recap delivery;
  • Stripe — subscription and payment processing;
  • PostHog — product analytics;
  • Google Analytics — website analytics.

These providers may process personal information only for the purposes for which InBoard uses their services and subject to their applicable contractual and privacy obligations.

InBoard's infrastructure and service providers operate in multiple jurisdictions. For example, portions of InBoard's current infrastructure operate in Canada and the United States. Personal information may therefore be processed outside your province, country, or the European Economic Area, where it may be subject to the laws applicable in those jurisdictions.

Where required, InBoard uses contractual or other appropriate mechanisms intended to protect personal information transferred to service providers in other jurisdictions.

Analytics

InBoard uses analytics to understand service usage, reliability, and product performance.

Google Analytics may be used for website analytics. PostHog may be used for product analytics. InBoard does not intentionally send Gmail message content or Gmail-derived task, evidence, summary, sender, or subject content to these analytics systems.

PostHog client IP storage is disabled in the current production configuration.

Analytics information is not used to sell mailbox information or to serve advertisements based on mailbox content.

Payments

Payments are processed by Stripe. InBoard does not receive or store complete payment-card numbers. InBoard stores limited billing information such as Stripe customer and subscription identifiers as necessary to administer subscriptions and maintain appropriate financial records.

Security

InBoard uses technical and organizational safeguards appropriate to the nature of the information it processes. These include encryption of OAuth credentials at rest, encrypted transport, tenant isolation and database access controls, authentication and authorization controls, administrative MFA protections, rate limiting, dependency and security testing, logging minimization, prompt-injection protections for AI processing, and procedures for revoking mailbox access and deleting data.

No online service can guarantee absolute security.

Your privacy choices and rights

You can disconnect a mailbox or delete your InBoard account through the product.

You may also contact hello@useinboard.com to request access to personal information about you held by InBoard, request correction of inaccurate information, request deletion where applicable, ask questions about how information is used or disclosed, withdraw consent where processing depends on consent, or raise a privacy concern or complaint.

These rights may vary depending on where you live and may be subject to legal exceptions.

If you are not an InBoard user but believe InBoard processes personal information about you because you communicated with an InBoard user, you may also contact us regarding your personal information. We may need sufficient information to verify the request and determine whether and how we can appropriately respond without compromising another person's privacy or legal rights.

Privacy accountability

InBoard is responsible for personal information under its control and for maintaining a privacy-management program appropriate to its activities.

Privacy questions, requests, or complaints may be directed to the person responsible for privacy at:

InBoard — Privacy Officer
hello@useinboard.com

We will investigate privacy complaints and respond as appropriate under applicable law.

Changes to this policy

We may update this Privacy Policy as InBoard evolves or as legal, regulatory, or provider requirements change.

If we materially change how Google user data or other personal information is collected, used, stored, or shared, we will provide notice and obtain additional consent where required before applying the new use.