Data and privacy
Operated by MARTHA TRADE PTE. LTD. (Martha trade). Contact: [email protected]
Data we store
We store your account username, password-derived value, recovery-code hash, sessions and authorizations; deletion, disconnection and credential-change records without mail or passwords for isolated restore checks; connected email addresses, incoming server settings and client credentials; message subjects, addresses, dates, plain-text bodies, synchronization and delivery status, and processing instructions saved for your agent. A username is not a verified email identity.
Mailbox credentials, Webhook URLs and keys, email bodies and custom instructions are encrypted with an application key. Subjects, sender addresses, dates and operational status are stored as database metadata. The encryption key is configured separately from the database. The service must decrypt credentials to receive mail continuously; this is not end-to-end encryption.
If you open the dashboard from a link with public campaign tags (utm_source, utm_medium, utm_campaign, utm_content) and then create an account, we store those tags with your account to count which channels lead to signups. If you arrived from an X ad, we also store X's click ID (twclid) and send it to X's Conversion API, together with the event name and time, when you sign up, first connect a mailbox and first authorize an AI agent, so X can count conversions from our ads. We send X no username, email address, IP address or mail data. We do not store other link parameters, and the tags and click ID are deleted with your account.
Sign in with Google
Google sign-in is optional and does not automatically connect a Gmail mailbox. Sign-in, account linking and identity confirmation redirect you to Google. We request basic identity scopes (openid, email, profile) and identify your account using its stable Google identifier and verified email address. The email address is encrypted. This sign-in flow does not retain Google names, avatars, access tokens or refresh tokens, and does not request Gmail reading, sending or management permissions.
Short-lived authorization state and security checks protect sign-in requests. Identity reconfirmation is short-lived, bound to your current session and usable once. Existing accounts must be linked to Google by you; matching email addresses do not automatically merge accounts. Accounts created through Google have no local password and require Google identity reconfirmation before deletion. Account deletion also removes the Google link stored by this service. Google processes its own sign-in information under its own terms and privacy policy.
Optional mailbox authorization
Where enabled after provider verification, connecting Gmail or Microsoft mail is a separate consent from signing in. Gmail requests gmail.readonly; Microsoft requests delegated Mail.Read, User.Read for mailbox identity and offline_access. These permissions do not allow sending or changing source mail. We encrypt the mailbox access/refresh tokens and synchronization checkpoints, and retain the provider mailbox identifier and email address to keep authorization bound to the correct mailbox. Pausing collection retains this connection; disconnecting removes its saved credentials and provider sync state. Account deletion removes them as well. Restoring a backup requires fresh mailbox authorization. Availability is shown in the mailbox setup page; a Google sign-in button alone does not enable Gmail collection.
How data is used and shared
The connector receives mail through read-only IMAP or, where enabled, read-only provider APIs, and does not send, delete or forward source messages. Enabling Grok delivery for a mailbox sends each new message's subject, sender, date and up to 4,000 body characters, together with your processing instructions, to the Routine Webhook you confirm. That platform analyzes the message and decides whether to notify you. Mail may include other people's personal information; only connect mailboxes you are entitled to process.
When connecting agents through OAuth, you select the permitted mailboxes and scopes. Agents can read authorized mail and saved processing instructions. With your consent, they may also record a decision in the connector, stopping remaining local delivery and retries for that event; requests already sent may still complete. Pausing monitoring does not revoke existing MCP read permissions. Revoke them separately under Authorized agents.
Grok uses your own Routine. As of October 4, 2026, InboxMCP is published and visible in the public Claude Directory as a Community connector; OpenAI plugin version 0.1.2 remains in review and is not published. Both offer standard MCP access. Client compatibility and native proactive notifications must be verified separately. Muse has received all required application materials, but does not yet have an available adapter in this service. HTTP acceptance, an agent decision and delivery of a device notification are distinct states.
Hosting and retention
With permission to save processing progress, we retain a separate checkpoint, batch leases and acknowledgements for each AI connection. These operational records do not change source mail or prove that a notification arrived. A client that supports MCP Events may explicitly subscribe to signed callbacks: the callback receives event and mailbox identifiers and a login-required message link, while the AI retrieves mail and your saved instructions using its authorized tools. Callback addresses and signing secrets are encrypted. Inactive event subscriptions and their secrets are removed after 30 days; delivery records are also removed with the source event. No external state service is required for the built-in batch workflow.
Cloudflare provides website hosting, DNS and HTTPS reverse proxying. The mail backend's isolated containers and persistent database currently run in Google Cloud us-central1 (Iowa, United States). Cloudflare network processing may involve other regions; processing is not necessarily confined to the United States. Network and hosting providers process connection information needed to serve requests. Application access logs do not record message bodies, passwords, recovery codes or complete Webhook URLs.
Message bodies and events are retained for 30 days by default after receipt by the connector. Cleanup retains body-free synchronization cursors and deduplication records to avoid delivering old mail again. Accounts and connection settings remain until you delete them. Encrypted backups target a 30-day retention period, with daily cleanup. Cleanup may run the next day or require operator intervention after an outage; this is not a strict expiry guarantee. Backup restores pause monitoring and revoke sessions and agent authorizations by default. Administrators must reconcile deletions, disconnections and credential changes made since the snapshot before restoring public service.
Subscriptions and PayPal
When paid checkout is enabled and you choose to subscribe, you leave the dashboard to approve payment on PayPal. We send PayPal the selected plan, an internal checkout reference and return addresses, not your mail content, mailbox credentials or agent instructions. We do not collect payment-card numbers, bank login credentials or your PayPal password in the dashboard. PayPal processes payment, payer and device information under its own privacy statement.
We store the link between your account and the subscription, PayPal subscription and payment identifiers, plan and interval, currency, amounts, payment dates, paid-through dates, status and verification records. The approval link is encrypted. These records verify access, prevent repeated payment processing and support cancellations, refunds or disputes. PayPal responses may include payer information, but the integration does not persist payer profiles or raw payment responses. Ordinary billing metadata is not encrypted at the application-field level.
Subscription and payment records remain in the application while the account exists. Account deletion is blocked until subscription cancellation is confirmed; deletion removes the account-linked subscription and payment records. Provider event identifiers and refund or dispute payment identifiers retained separately to prevent repeated processing are not automatically removed with account deletion. Encrypted backups follow the retention described above. Deleting an inboxmcp account does not delete records held independently by PayPal; contact us with questions about billing records.
PayPal Privacy Statement ↗Your controls
You can pause delivery, disconnect a mailbox and clear its credentials, delete mailbox copies from the connector, revoke an agent’s OAuth grant, sign out all devices, or delete your account after password verification (Google-only accounts reconfirm their linked Google identity). A PayPal subscription must have confirmed cancellation before account deletion. The connector cannot recall data already sent to an agent; manage that data on the receiving platform.
This service does not run a mail classification model, score importance, filter messages by their content, or operate a user-notification engine. How an external agent handles messages depends on that platform's service and your settings. Contact the address above for data questions or requests.
Language preference
When you choose a language, we save only that language code in browser storage until you clear it and in a preference cookie that lasts up to one year. The cookie is shared by inboxmcp.ai and its subdomains so the website and workspace use your choice. It contains no account or email data and is not used for advertising or analytics. Clearing browser site data resets the preference; English is the default.