Privacy notice
Privacy Policy
This notice explains how we process personal data when you visit AI Inbx, create an account, or use the email platform.
Last updated: 1 September 2026
1. Controller
- Controller
- Address
- Represented by
- Pau Jordi Kraft Carné, Managing Director
2. Our privacy roles
We are the controller for data about visitors, account holders, prospective customers, and our contractual relationship with a customer.
Where a customer determines why and how email content, recipients, contacts, and other data are processed, the customer is the controller and we act as its processor under our Data Processing Agreement. The DPA applies according to the actual data-protection roles. A person using AI Inbx solely for personal or household purposes may fall outside the GDPR's controller obligations; we remain responsible for our own processing described in this notice.
If an email sent through AI Inbx concerns you, please contact the sender first. We assist our customer with valid data-subject requests.
3. Website, hosting, and device storage
When you access the website, our hosting provider processes technical request data such as your IP address, date and time, requested URL, referrer, browser, operating system, response status, and user agent. This is necessary to deliver and secure the website. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is a secure, reliable, and abuse-resistant service.
The website and application are hosted by Vercel. We use no advertising cookies and no analytics or cross-site tracking tools.
We use only storage that is necessary or expressly requested:
- Authentication cookies keep you signed in, protect login flows, and preserve security state. Session cookies generally expire within seven days or earlier when you log out; temporary OAuth cookies expire after the login flow.
- Theme preference may be saved as a
themevalue in your browser's local storage. It remains until you change it or clear browser storage.
This storage is required to provide the account features or preference you requested and therefore does not require consent under Section 25(2) TDDDG. Because no optional tracking technology is used, we do not display a cookie banner.
4. Accounts and customer relationship
When you register or administer a workspace, we process your name, email address, password hash or social-login identifier, profile image where provided, login and session data, IP address, user agent, accepted contract versions and acceptance time, workspace membership and role, invitations, settings, support correspondence, and contractual or billing records.
Processing is necessary to create and perform the contract, manage the account, provide support, and keep the service secure. The basis is Article 6(1)(b) GDPR where the account holder is a contracting party, and otherwise Article 6(1)(f) GDPR, based on our and the customer's legitimate interest in administering and securing the customer relationship. Records that must be retained under commercial or tax law are processed under Article 6(1)(c) GDPR.
If you choose GitHub, Google, or Discord login, that provider sends us the identity information displayed during the authorization flow. The provider separately processes the login under its own privacy terms. Email-and-password registration is available as an alternative.
The required registration and contract fields are necessary to enter into and administer the contract. Without them, we cannot create or provide the account. Optional profile fields and optional integrations are identified as such in the interface.
5. Email platform and connected mailboxes
To provide the service on a customer's instructions, we may process:
- email addresses, display names, subject lines, message bodies, headers, attachments, thread and mailbox data;
- sending domains, DNS records, API keys in hashed form, webhook URLs, and connected Gmail or Microsoft mailbox credentials;
- delivery, bounce, complaint, unsubscribe, scheduling, pacing, and suppression information; and
- open and click events, including time, URL, IP address, and user agent where the customer enables or uses those events.
This processing is performed to transmit, receive, organize, search, secure, and report on email. For account holders, the legal basis is Article 6(1)(b) GDPR. For customer content, the customer determines the applicable legal basis and instructs us under Article 28 GDPR.
Customers are responsible for providing required notices and obtaining any consent needed for their email communications or engagement tracking. Connected mailbox data is accessed only after authorization and within the scopes shown by Google or Microsoft.
6. AI classification and smart threading
AI Inbx uses automated systems to classify inbound email, detect reply context and opt-out language, and place ambiguous messages into a likely thread. Depending on the message, this can involve sending limited message text, subject, sender and recipient details, selected headers, attachment names and types, and short excerpts from candidate threads to OpenAI. Message text used for semantic thread matching is indexed with Upstash.
These features organize email and produce suggestions for the customer; they do not make decisions that have legal or similarly significant effects on an individual within the meaning of Article 22 GDPR. OpenAI states that API inputs and outputs are not used to train its models by default. Its standard abuse-monitoring logs may be retained for up to 30 days unless stricter retention controls apply.
7. Recipients and service providers
We disclose personal data only where necessary to provide the service, comply with law, protect rights and security, or follow a customer's instructions. Processor categories include:
- Vercel for application hosting and technical logs;
- Amazon Web Services for email delivery, receipt, queues, and object storage in the region selected for the workspace;
- managed database, search, cache, and queue infrastructure, including Upstash;
- OpenAI for email classification and smart threading;
- Stripe, including Sold through Link, for checkout, payment, indirect-tax handling, fraud prevention, disputes, and transaction-level support when a paid plan uses Managed Payments;
- Google, Microsoft, GitHub, or Discord when a user or customer chooses the relevant login or mailbox connection.
A current subprocessor list and the contractual safeguards applying to customer content are included in the DPA. Payment providers may also act as independent controllers for regulated payment, tax, fraud-prevention, and customer-support activities under the notices shown at checkout. We may also disclose data to professional advisers, authorities, or courts where legally required.
8. International data transfers
Some providers are based in, or can access data from, countries outside the European Economic Area. Where no adequacy decision applies, we use appropriate safeguards under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses, together with supplementary measures where required. Where a recipient is certified under the EU–U.S. Data Privacy Framework, transfers may also rely on the relevant adequacy decision.
Mail storage can be located in the EU (Frankfurt) or the United States (N. Virginia), depending on the region selected by the customer. Contact us for information or a copy of the relevant transfer safeguards, subject to necessary redactions.
9. Retention and deletion
- Website request and security data is retained only for the period needed to operate, diagnose, and protect the service, subject to the hosting provider's configured log period.
- Account and contract data is kept for the life of the account and then deleted or restricted, except where statutory retention duties apply. German commercial and tax records are generally kept for six to ten years, depending on the record.
- Customer content is kept for the customer-selected service period and then deleted or returned in accordance with the DPA. Raw inbound MIME copies held for reprocessing expire after 30 days.
- Suppression records may be retained while needed to prevent further unwanted or undeliverable email and demonstrate compliance.
- Backups, provider logs, and data queued for secure deletion are removed on their applicable rotation cycles unless preservation is required by law or for a specific security incident or legal claim.
10. Your rights
Subject to the GDPR's conditions and exceptions, you have the right to access, rectify, erase, restrict, and receive your personal data, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing.
Contact me@paukraft.com to exercise these rights. We may need to verify your identity. For data controlled by an AI Inbx customer, contacting that customer directly is usually the fastest route.
You may also complain to a supervisory authority. Our lead local authority is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.
11. Security and policy changes
We use technical and organizational safeguards appropriate to the risk, including encrypted transport, access controls, credential protection, logical tenant separation, and monitoring. No system can guarantee absolute security.
We update this notice when the service, providers, or legal requirements change. The date above identifies the current version. We will provide additional notice of material changes where required.