Privacy Policy
Placeholder page describing what this demo actually does today. Before launch, have this reviewed by a lawyer and fill in the bracketed fields — a live product handling Gmail data needs a GDPR-compliant policy tailored to your actual infrastructure and sub-processors.
Data controller
[Company name and address — see Imprint]
What we access
When you connect your Google account, inbx requests access to your Gmail inbox only — not your sent mail — to read incoming message metadata (sender, subject, labels) and apply the labels you've approved. inbx does not read or store the body content of your emails.
Why we process it
Message metadata is processed to generate label suggestions and to apply the labels you've confirmed, under Art. 6(1)(b) GDPR (performance of a contract you've asked us to fulfill).
Third parties
We use Google's Gmail API and OAuth to connect your inbox. [List any additional sub-processors here, e.g. hosting provider, email delivery service.]
Data retention
[Describe how long label history and account data are kept, and how a user can request deletion.]
Your rights
Under the GDPR you have the right to access, correct, delete, or export your data, and to withdraw consent at any time by disconnecting your Google account. To exercise these rights, contact [privacy@yourdomain.com].