Privacy Policy
1.What this app does
Inbox Census reads your Gmail inbox's metadata — who sent you mail, how much, how big, how old — and turns it into a ranked list of senders. You review that list and choose which senders to archive or trash in bulk. The entire process runs in your browser. There is no server behind Inbox Census that your mail data ever passes through.
2.What we access, and why
We request Gmail message metadata only — never message bodies. Specifically:
- From, size, date, labels — to build the sender-level counts, sizes, and read status shown in the census.
- List-Unsubscribe, List-Id, and related bulk-mail headers — to determine whether a sender is bulk mail (marketing, newsletters, notifications) as opposed to a person you correspond with.
- Whether you've ever sent mail to an address — read from your own Sent mail, metadata only — to protect real correspondents from being bulk-selected by default.
The Gmail API is called with format=metadata specifically; the body of a message is never requested, never fetched, and never rendered.
| Data | Accessed via | Processed | Stored | Leaves browser? |
|---|---|---|---|---|
| Message metadata (From, size, date, labels, List-Unsubscribe) | Gmail API | In-memory aggregation | Derived census + message-id lists in IndexedDB, until you wipe it | Never |
| Message bodies | Never requested | — | — | Never |
| OAuth access token | Google Identity Services | Memory only | Never persisted | Only to Google |
| License key | Paddle | Client-side validation | localStorage (a receipt, not a secret) | To Paddle at purchase |
| Invite request — your email address, only if you ask for a test slot | The invite form on the landing page | Our license worker (Cloudflare) | Cloudflare KV, until you're added to the test list — automatically deleted after 90 days | Yes — to us, only when you submit it. Erase on request: email hello@inboxcensus.com. |
| Analytics events | App | — | Self-hosted (umami at data.reframed.ro) | Aggregate counts only — no mail-derived strings, no IP-based profiling |
| Payment identity (email, card) | — | Paddle (merchant of record) | Paddle | We never receive card data |
| Census export (CSV/JSON) | User-initiated | — | Your own disk | Never to us — it's a download, not an upload |
3.Where processing happens
Everything — reading your metadata, computing sender counts, deciding what's "safe to evict," rendering the census table — runs in JavaScript in your own browser tab. We never see your email. Your mail data moves between your browser and Google's own API — the same Google you already trust with it — and nowhere else.
Don't take our word for it: open your browser's DevTools, click the Network tab, and use the app. Your mail data flows only to gmail.googleapis.com and Google's own sign-in domains. The only other requests you'll see: a single anonymous usage count to our self-hosted analytics (never a string from your mail), and Paddle's checkout domain, only if and when you buy.
4.What is stored, and where
- IndexedDB (your browser only): the derived census — sender aggregates and message-id lists — persists locally so you don't have to rescan every visit. A visible "Wipe local data" button clears it completely; we suggest wiping on sign-out.
- localStorage (your browser only): your license key, if you've purchased. It's a receipt, not a secret.
- Nothing, server-side. There is no server. We have no database, no logs of your mail, no backend to breach.
- Invite requests (landing page only): the address you type into the invite form is kept by us until you're allowlisted, 90 days at most — the one thing we hold server-side, and only because Google's test-user list is filled by hand.
5.Third parties
- Google (Gmail API, Google Identity Services): the only place your mail metadata is ever sent or read from. Governed by Google's own privacy policy.
- Paddle: our merchant of record for payments. Paddle handles your card details and checkout — we never receive or store card data. See Paddle's privacy policy.
- umami analytics (self-hosted at data.reframed.ro): aggregate, cookie-free usage counts only (e.g. "senders_found: 214"). Never mail content, sender addresses, subjects, or any string derived from your mail.
6.Limited Use statement
Inbox Census's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely: we do not transfer Gmail data to any other party, no human at Inbox Census ever reads your mail, we do not use Gmail data for advertising, and we do not use Gmail data to train any AI or machine-learning model — there is no AI anywhere in this product.
7.Your controls
- Wipe local data — one button in the app clears IndexedDB and memory. Available any time, suggested on sign-out.
- Sign out — revokes the access token client-side immediately.
- Revoke access at the source — you can revoke Inbox Census's access at any time from your own Google Account: Security → Third-party access. This works even if you never open our app again.
8.GDPR basics
- Controller: LMR Digital Productions SRL (CUI 44795685, Trade Reg. J2021014648406), Str. Dristorului 114, Bl. 13C, Sc. 1, Et. 1, Ap. 1, Sector 3, 031543 Bucharest, Romania. Contact: hello@inboxcensus.com.
- Legal basis: your consent (Google OAuth grant) and contract performance (delivering the service you're using).
- Profiling: none. Triage decisions are deterministic rules over message headers you can read yourself — never machine learning, never behavioral profiling.
- Right to erasure: trivially satisfied. We hold no server-side copy of your mail or census data — it lives only in your own browser until you delete it yourself. A request to us for erasure will be answered honestly: we never had anything to erase.
- Contact for any data-protection question: hello@inboxcensus.com.
9.Changes & contact
If this policy changes, the "last updated" date at the top of this page will change with it. Material changes will also be reflected on the landing page. Questions about anything on this page: hello@inboxcensus.com.