Privacy Policy
Last updated: September 25, 2026
InboxRevamp helps you organize one Gmail inbox by checking its existing label structure, applying an approved organization and maintaining new mail. This policy describes the data the service processes and retains. InboxRevamp is an early-access service; before public production use, the operator must publish their legal identity and a working privacy contact address in the deployed site's configuration.
Information we process
We process your InboxRevamp account and session information, and, when you choose Connect Gmail, your Gmail address, Google account identifier, OAuth tokens, label identifiers, connection and watch state, synchronization checkpoints, and non-content processing statistics. Your refresh token is encrypted at application level using AES-256-GCM and is not returned to your browser.
During Check, InboxRevamp reads bounded Gmail label metadata and representative message metadata, including sender, subject, date, label membership and Gmail's short snippet. The sample is analyzed to prepare one recommendation; it is not a claim that every message in a large mailbox was semantically analyzed. During Revamp, it reads only approved historical message IDs needed to apply the frozen plan. To maintain new mail, InboxRevamp reads its From and Subject headers, selected mailing-list and automation headers (List-Id, List-Unsubscribe, Auto-Submitted, and Precedence), Gmail's short snippet, and the names and descriptions of your currently enabled categories are sent to the configured inference provider through Vercel AI Gateway. Email body, raw MIME, attachments, and full mailbox contents are not sent to the inference provider by this workflow. The inference provider's own privacy, retention, and processing terms apply to data it receives; review those terms before connecting.
Information we retain
We retain account/session data, the encrypted refresh token, Gmail account and connection state, your category names and descriptions, enabled state and Gmail label IDs, watch/history checkpoints, operational error codes, category and classifier version, processing timestamps, aggregate counts, and a SHA-256 hash of each processed Gmail message identifier for replay protection. Audit records retain Gmail label names, counts and overlap findings plus the bounded message and label IDs needed by the plan. The review plan retains representative message IDs so the Review page can fetch examples from Gmail when you open it. Sender names and subjects shown as examples are returned only for that authenticated review request; they are not stored in the plan. We do not store message bodies, raw MIME, attachments or Gmail snippets in the application database.
How Gmail is used
Gmail authorization is separate from InboxRevamp sign-in. Connecting a mailbox requests the `gmail.modify` scope so the service can read the minimum metadata/snippet described above and apply only the ordinary Gmail user-label changes in an approved plan and the ordinary labels mapped to your approved categories. Revamp adds and verifies an approved destination label before removing a selected source-label membership. Source label objects and Gmail system labels are left in place. We do not send or draft mail, delete, trash, archive, mark read/unread, or change other Gmail labels or system labels. Gmail remains the source of truth and its clients display the labels.
Retention and deletion
Disconnecting Gmail attempts to revoke Google access and removes the local token, mailbox label mapping, audit/plan/apply records, and processing records. Your InboxRevamp category definitions remain so you can reconnect later. It does not delete messages or labels already created in Gmail. Deleting an InboxRevamp account removes the associated local Gmail connection and records through database cascade deletion. Backups may retain deleted records for their normal rotation period. InboxRevamp does not start another structural audit after Revamp unless you choose Run Inbox Check Again.
Security and Google requirements
Access tokens are kept server-side; refresh tokens are encrypted at rest by the application. We do not intentionally log access/refresh tokens or message content. Public deployment must complete Google's applicable OAuth consent, restricted-scope verification, and any required security assessment before inviting users beyond the permitted testing audience.
Product analytics
When enabled for the deployment, Vercel Web Analytics records page views and InboxRevamp sends high-level funnel event names such as Check started, plan approved and Revamp completed. The application does not include Gmail content, account IDs, label names or message IDs in those custom events. Vercel describes Web Analytics as cookie-free and based on anonymized, aggregated measurements; its own privacy terms apply to analytics data it processes.
Contact
The service operator must publish their legal identity and privacy contact address in the deployment before public production use. Until that information is supplied, this page is not a complete public-facing legal notice.