Privacy Policy
Version 1.6 · Effective July 2026
This policy is provided in English only. The English version is the legally binding version. In case of any discrepancy between this document and any translation, this English version prevails.
1. Who we are
in-boxed is operated as a sole trader registered in the Netherlands.
BonDigital (trading as in-boxed)
The Netherlands
KVK: 42079017
VAT: NL005478591B85
privacy@in-boxed.com
A Data Protection Officer has not been appointed, as this is not required for organisations of this size under Article 37 GDPR.
2. How in-boxed works
When you unsubscribe, in-boxed acts entirely from within your browser. After the scan, it reads the List-Unsubscribe and List-Id headers that senders include in their marketing email, and sends the opt-out request directly to the endpoint each sender publishes for this purpose. This is the same technical opt-out signal you would send by clicking "Unsubscribe" in Gmail or Outlook, sent to every sender at once rather than one at a time.
- For senders that support one-click unsubscribe (RFC 8058), your browser sends a single HTTP request to their published unsubscribe endpoint.
- For senders that accept unsubscribe requests only by email, or that are a mailing list (they carry a
List-Idheader) without a machine-readable unsubscribe endpoint, in-boxed prepares a pre-filled opt-out email addressed to the sender's published contact or reply address, which you send yourself.
in-boxed does not route these requests through Gmail or Outlook, and does not send anything from our own servers. Every request originates from your browser. We are a technical intermediary that automates an action you could perform manually.
3. What data we process
We process the minimum data necessary to deliver the service (Article 5(1)(c) GDPR).
| Data | Purpose | Legal basis |
|---|---|---|
| Gmail OAuth token | Grants temporary access to read email headers. Used during your session only. | Art. 6(1)(b) · Contract performance |
| Microsoft OAuth token (if you connect Outlook, Hotmail or Live instead) | Grants temporary access to read email headers via Microsoft Graph. Used during your session only. | Art. 6(1)(b) · Contract performance |
| Email header metadata (From, List-Unsubscribe, List-Id, Reply-To) | To identify newsletters and mailing lists and send opt-out requests from your browser. Read locally; never transmitted to us. Same fields for Gmail and Outlook. | Art. 6(1)(b) · Contract performance |
| Session cookie | Maintains your authenticated state during your visit. | Art. 6(1)(b) · Contract performance |
| Payment confirmation via Stripe | To verify payment and unlock the service. We never see card details. | Art. 6(1)(b) · Contract performance |
| Email address (optional, only if you use the feedback form) | To respond if you report an issue. Provided voluntarily; never taken from your inbox. | Art. 6(1)(a) · Consent |
| Feedback you type (optional sender reports) | If you report a missed or persistent sender, we receive only the text you enter, never inbox data. | Art. 6(1)(a) · Consent |
| Anonymous usage statistics | Cookie-free counts of page views and of a fixed list of product steps (for example: a scan finished, the price was shown, a payment was confirmed) so we can see where people get stuck. No cookie, no identifier, no profile, and nothing that can be traced back to you or to a specific inbox. Counts of senders are recorded only as a range such as "20-49", never as an exact number. | Art. 6(1)(f) · Legitimate interest |
We never access the content of your emails. For Gmail we request only the metadata format, and for Outlook, Hotmail or Live we request only the from, replyTo and internetMessageHeaders fields via Microsoft Graph. Both technically exclude email bodies, subject lines, and attachments.
4. Retention
Your email data is processed entirely within your own browser and is never transmitted to, stored on, or logged by our servers, whether you connect Gmail or Outlook/Hotmail/Live. The scan reads email headers locally on your device and keeps the results in your browser tab only. When you close the tab the data is gone; the short-lived access token (Gmail: valid for about one hour; Microsoft: similarly short-lived, no refresh token in either case) also lives only in your browser. We operate no database and keep no logs containing personal data. The anonymous usage statistics described above are counts only: they are cookie-free, carry no identifier, are never linked to a person or an inbox, and are stored separately from anything you connect. You can revoke access at any time from your Google Account permissions page, or, for Microsoft accounts, from account.live.com/consent/Manage.
5. Data security
We protect your data first and foremost by never collecting it on our side. In addition, the following security measures apply to safeguard the confidentiality and integrity of your data, including sensitive Google and Microsoft user data:
- Encryption in transit. All connections, between your browser and our website, and between your browser and the Gmail API or Microsoft Graph API, are encrypted using HTTPS/TLS. Restricted-scope data is requested directly from Google or Microsoft over this encrypted connection and never passes through our servers.
- No server-side storage. Your email data and access token exist only within your browser tab, for both providers. We operate no database and keep no server-side logs containing personal data, so there is no stored copy of your data that could be breached, leaked, or sold.
- Data minimisation. We request only email header metadata (the
From,List-Unsubscribe,List-IdandReply-Toheaders, or their Microsoft Graph equivalents) and never message bodies, subject lines, or attachments. - Short-lived access. Access tokens expire quickly (Gmail: about one hour) and have no refresh token, so access cannot persist or be reused after your session, for either provider.
- Secure session cookie. The only cookie we set is strictly necessary, HTTP-only, Secure, and SameSite-restricted, and it contains no email data.
- Payment security. Card payments are handled entirely by Stripe (PCI-DSS Level 1 certified). We never receive or store your card details.
Because our servers never receive your email data, the risks associated with a server-side data breach do not apply. You can revoke in-boxed's access at any time from your Google Account permissions page or your Microsoft account's app permissions.
6. OAuth providers and API access
We use Google OAuth 2.0 with the gmail.readonly scope, and, if you connect Outlook, Hotmail or Live instead, Microsoft OAuth 2.0 with the delegated Mail.ReadBasic scope, which Microsoft defines as access to everything about a message except its body, preview body, attachments and extended properties. In both cases the API is called directly from your browser to Google or Microsoft; restricted-scope data never passes through our servers. Our use of Gmail data complies with the Google API Services User Data Policy, including the Limited Use requirements, and we apply the same principles to Microsoft Graph data:
- Email header data is used solely to provide the service you requested
- Email header data is not used for advertising
- No human reads your email header data
- Email header data is not shared with third parties beyond what is necessary to operate the service
7. Sub-processors
| Party | Purpose | Transfer basis |
|---|---|---|
| Google LLC | Gmail API · OAuth and header retrieval | Standard Contractual Clauses |
| Microsoft Corporation | Microsoft Graph API · OAuth and header retrieval, for Outlook, Hotmail or Live accounts | Standard Contractual Clauses |
| Stripe Inc. | Payment processing | Standard Contractual Clauses |
| Vercel Inc. | Application hosting, and cookie-free aggregate usage statistics (Vercel Web Analytics) | Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Error monitoring (EU region). Configured to send no personal data, no IP, no Gmail or Outlook data. | Standard Contractual Clauses |
| Formspree, Inc. | Delivers optional sender-feedback submissions. Only what you voluntarily type. | Standard Contractual Clauses |
We do not sell data. We do not use advertisers or data brokers.
8. Your rights (Articles 15–22 GDPR)
You have the right to access, rectify, erase, restrict, and port your data, and to object to processing. Because we retain no data after your session ends, these rights are automatically fulfilled. To exercise them or ask questions, contact privacy@in-boxed.com. We respond within 30 days.
9. Supervisory authority
You may lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or the supervisory authority in your country of residence.
10. Cookies
One strictly necessary session cookie is set after authentication. It contains only a random session identifier, is HTTP-only and SameSite-restricted, and expires after 1 hour. No tracking or advertising cookies are used. For website statistics we use privacy-friendly, cookieless analytics that record aggregate, anonymous page views together with a fixed, published list of product steps (such as a scan finishing or a payment being confirmed), so we can see where people get stuck and fix it. No cookies, no identifiers and no personal data are collected, and these counts cannot be traced back to an individual. This is entirely separate from your Gmail or Outlook data, which never reaches our servers.
11. Third-party trademarks
Gmail is a trademark of Google LLC. Outlook, Hotmail and Live are trademarks of Microsoft Corporation. in-boxed is not affiliated with, endorsed by, or sponsored by Google LLC or Microsoft Corporation. Use of these names is solely for descriptive purposes to indicate compatibility.
12. Not legal advice
References to GDPR, CAN-SPAM, or other laws on this website are for informational purposes only and do not constitute legal advice. Results depend on sender compliance. If you have legal questions, consult a qualified attorney.