Free to scan. €4.99 once, only if you decide to clean up. No account, no subscription.
← Back to in-boxed

Privacy Policy

Version 1.6 · Effective July 2026

This policy is provided in English only. The English version is the legally binding version. In case of any discrepancy between this document and any translation, this English version prevails.

1. Who we are

in-boxed is operated as a sole trader registered in the Netherlands.

BonDigital (trading as in-boxed)
The Netherlands
KVK: 42079017
VAT: NL005478591B85
privacy@in-boxed.com

A Data Protection Officer has not been appointed, as this is not required for organisations of this size under Article 37 GDPR.

2. How in-boxed works

When you unsubscribe, in-boxed acts entirely from within your browser. After the scan, it reads the List-Unsubscribe and List-Id headers that senders include in their marketing email, and sends the opt-out request directly to the endpoint each sender publishes for this purpose. This is the same technical opt-out signal you would send by clicking "Unsubscribe" in Gmail or Outlook, sent to every sender at once rather than one at a time.

in-boxed does not route these requests through Gmail or Outlook, and does not send anything from our own servers. Every request originates from your browser. We are a technical intermediary that automates an action you could perform manually.

3. What data we process

We process the minimum data necessary to deliver the service (Article 5(1)(c) GDPR).

DataPurposeLegal basis
Gmail OAuth tokenGrants temporary access to read email headers. Used during your session only.Art. 6(1)(b) · Contract performance
Microsoft OAuth token (if you connect Outlook, Hotmail or Live instead)Grants temporary access to read email headers via Microsoft Graph. Used during your session only.Art. 6(1)(b) · Contract performance
Email header metadata (From, List-Unsubscribe, List-Id, Reply-To)To identify newsletters and mailing lists and send opt-out requests from your browser. Read locally; never transmitted to us. Same fields for Gmail and Outlook.Art. 6(1)(b) · Contract performance
Session cookieMaintains your authenticated state during your visit.Art. 6(1)(b) · Contract performance
Payment confirmation via StripeTo verify payment and unlock the service. We never see card details.Art. 6(1)(b) · Contract performance
Email address (optional, only if you use the feedback form)To respond if you report an issue. Provided voluntarily; never taken from your inbox.Art. 6(1)(a) · Consent
Feedback you type (optional sender reports)If you report a missed or persistent sender, we receive only the text you enter, never inbox data.Art. 6(1)(a) · Consent
Anonymous usage statisticsCookie-free counts of page views and of a fixed list of product steps (for example: a scan finished, the price was shown, a payment was confirmed) so we can see where people get stuck. No cookie, no identifier, no profile, and nothing that can be traced back to you or to a specific inbox. Counts of senders are recorded only as a range such as "20-49", never as an exact number.Art. 6(1)(f) · Legitimate interest

We never access the content of your emails. For Gmail we request only the metadata format, and for Outlook, Hotmail or Live we request only the from, replyTo and internetMessageHeaders fields via Microsoft Graph. Both technically exclude email bodies, subject lines, and attachments.

4. Retention

Your email data is processed entirely within your own browser and is never transmitted to, stored on, or logged by our servers, whether you connect Gmail or Outlook/Hotmail/Live. The scan reads email headers locally on your device and keeps the results in your browser tab only. When you close the tab the data is gone; the short-lived access token (Gmail: valid for about one hour; Microsoft: similarly short-lived, no refresh token in either case) also lives only in your browser. We operate no database and keep no logs containing personal data. The anonymous usage statistics described above are counts only: they are cookie-free, carry no identifier, are never linked to a person or an inbox, and are stored separately from anything you connect. You can revoke access at any time from your Google Account permissions page, or, for Microsoft accounts, from account.live.com/consent/Manage.

5. Data security

We protect your data first and foremost by never collecting it on our side. In addition, the following security measures apply to safeguard the confidentiality and integrity of your data, including sensitive Google and Microsoft user data:

Because our servers never receive your email data, the risks associated with a server-side data breach do not apply. You can revoke in-boxed's access at any time from your Google Account permissions page or your Microsoft account's app permissions.

6. OAuth providers and API access

We use Google OAuth 2.0 with the gmail.readonly scope, and, if you connect Outlook, Hotmail or Live instead, Microsoft OAuth 2.0 with the delegated Mail.ReadBasic scope, which Microsoft defines as access to everything about a message except its body, preview body, attachments and extended properties. In both cases the API is called directly from your browser to Google or Microsoft; restricted-scope data never passes through our servers. Our use of Gmail data complies with the Google API Services User Data Policy, including the Limited Use requirements, and we apply the same principles to Microsoft Graph data:

7. Sub-processors

PartyPurposeTransfer basis
Google LLCGmail API · OAuth and header retrievalStandard Contractual Clauses
Microsoft CorporationMicrosoft Graph API · OAuth and header retrieval, for Outlook, Hotmail or Live accountsStandard Contractual Clauses
Stripe Inc.Payment processingStandard Contractual Clauses
Vercel Inc.Application hosting, and cookie-free aggregate usage statistics (Vercel Web Analytics)Standard Contractual Clauses
Functional Software, Inc. (Sentry)Error monitoring (EU region). Configured to send no personal data, no IP, no Gmail or Outlook data.Standard Contractual Clauses
Formspree, Inc.Delivers optional sender-feedback submissions. Only what you voluntarily type.Standard Contractual Clauses

We do not sell data. We do not use advertisers or data brokers.

8. Your rights (Articles 15–22 GDPR)

You have the right to access, rectify, erase, restrict, and port your data, and to object to processing. Because we retain no data after your session ends, these rights are automatically fulfilled. To exercise them or ask questions, contact privacy@in-boxed.com. We respond within 30 days.

9. Supervisory authority

You may lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or the supervisory authority in your country of residence.

10. Cookies

One strictly necessary session cookie is set after authentication. It contains only a random session identifier, is HTTP-only and SameSite-restricted, and expires after 1 hour. No tracking or advertising cookies are used. For website statistics we use privacy-friendly, cookieless analytics that record aggregate, anonymous page views together with a fixed, published list of product steps (such as a scan finishing or a payment being confirmed), so we can see where people get stuck and fix it. No cookies, no identifiers and no personal data are collected, and these counts cannot be traced back to an individual. This is entirely separate from your Gmail or Outlook data, which never reaches our servers.

11. Third-party trademarks

Gmail is a trademark of Google LLC. Outlook, Hotmail and Live are trademarks of Microsoft Corporation. in-boxed is not affiliated with, endorsed by, or sponsored by Google LLC or Microsoft Corporation. Use of these names is solely for descriptive purposes to indicate compatibility.

12. Not legal advice

References to GDPR, CAN-SPAM, or other laws on this website are for informational purposes only and do not constitute legal advice. Results depend on sender compliance. If you have legal questions, consult a qualified attorney.

13. Contact

privacy@in-boxed.com

Terms of ServiceBack to in-boxed