InboxXray
Home Analyse Pricing Blog

Legal

Privacy Policy

Last updated: July 2026

The Short Version

We process email data such as headers, optional body excerpts, links, and attachment hashes solely to generate security reports. If you enable extension-only Website Protection, we also process capped security signals from the page you are viewing to detect phishing and scam indicators. We do not sell your data, use it for advertising, create a browsing history, or use it to train AI models.

1. Information We Collect

We adhere to the principle of Data Minimization, collecting only what is strictly necessary to provide security analysis.

Account Information

Email address, display name, and secure authentication metadata managed via Stack Auth.

Analysis Metadata (Headers and .eml Files)

Routing servers, timestamps, authentication results (SPF/DKIM/DMARC), and message metadata needed for email security analysis. When you upload an .eml file, InboxXray parses it to extract headers, links, body text needed for the selected checks, and attachment metadata. Raw headers and uploaded email content are processed for the request and are not stored in our permanent databases.

Links and Attachment Hashes (Optional)

When link or attachment scanning is enabled, InboxXray may process extracted URLs and SHA-256 hashes of attachments. Browser extension attachment scans send hashes and capped file names to InboxXray, not attachment bytes. For .eml uploads, the file is parsed server-side to calculate attachment hashes; attachment contents are not sent to public threat intelligence providers.

Security Findings

We store the results of your analysis, such as risk scores, summaries, link reputation outcomes, and attachment hash outcomes, for up to 14 days to provide you with a recent history.

Email Content (Optional)

If you enable AI Analysis, a snippet of the email body (up to 3,000 characters) is processed. This is handled ephemerally and is not stored by InboxXray after the report is generated.

Website Protection Signals (Optional)

Website Protection is an extension-only feature that works without an InboxXray account. It is off until you enable it and grant optional website access. For the current page, the extension may send the URL, page title, up to 3,000 characters of visible security-relevant text, capped link destinations, form action and method, and boolean indicators showing whether a form contains email, password, or payment fields. It may also indicate that the page was opened from supported webmail. InboxXray does not send typed form values, passwords, payment card details, cookies, screenshots, browser storage, or full page HTML.

Payment Data

Handled entirely by Stripe. We only see the last 4 digits of your card and subscription status.

2. How We Use Your Information

We use the information collected strictly to:

  • Provide real-time security and phishing analysis.
  • Detect phishing, impersonation, and scam indicators on the current website when Website Protection is enabled.
  • Authenticate your account and manage subscriptions.
  • Detect and prevent abuse of the InboxXray service.

Note: We will never use your data for advertising, sell it to third parties, or share it with data brokers.

3. Data Sharing & Restricted Disclosures

We share data only with the following essential service providers. All transfers are encrypted via TLS.

Google API Limited Use Disclosure

InboxXray's use and transfer of information received from Google APIs to any other app will adhere to the Google API Service User Data Policy, including the Limited Use requirements. We do not use Google User Data to serve advertisements, and we do not sell Google User Data to third parties.

AI Analysis & Data Privacy (Anthropic API)

For users who opt-in to AI-powered threat assessment:

  • No Training: Data is processed via Anthropic's Commercial API tier. This explicitly prohibits the use of customer data for training foundation models.
  • Zero Retention: Email content is processed ephemerally and is not retained by the AI provider after the analysis is complete.

Security & Infrastructure Providers

Google Web Risk
When the relevant protection feature is enabled, email links or the current website URL may be checked for known phishing, malware, unwanted software, or social-engineering threats. Only the URL is sent; page text, email content, typed values, cookies, and user identifiers are not shared.
urlscan.io
URLs extracted from emails are checked against urlscan.io's community threat database. For Email Protection, an unavailable result may be submitted for analysis with unlisted visibility (not publicly indexed, but accessible to urlscan.io and its data partners). Website Protection only searches existing history for the exact current URL and does not submit a new website scan. Only the URL is sent; no email content, page text, typed values, user identifiers, or personal data are shared.
CIRCL Hashlookup
Attachment SHA-256 hashes are checked for known file indicators. Attachment contents are not sent to CIRCL.
MalwareBazaar
Attachment SHA-256 hashes are checked against abuse.ch malware intelligence when configured. We send hashes and limited file metadata only, not attachment file contents.
ThreatFox
Attachment SHA-256 hashes are checked against abuse.ch indicator intelligence when configured. We send hashes and limited file metadata only, not attachment file contents.
Website Threat Intelligence
Website Protection compares URLs with locally cached URLhaus indicators and may use Google Web Risk, exact-URL urlscan.io history, URLhaus hostname intelligence, and RDAP domain registration data according to the configured risk policy. Provider clean or unavailable results never override warning signs found locally. Page text, form signals, cookies, typed values, screenshots, and account identifiers are not sent to these providers.
Stack Auth
Manages secure login and identity.
Stripe
Manages PCI-compliant payment processing.
IP/DNS Services
Technical metadata (IP addresses from headers) is checked against reputation databases to identify geographic anomalies.

4. Browser Permissions Transparency

To function as a browser extension, we request the following permissions:

  • storage: To store local session state, onboarding state, and scan preferences.
  • identity: To support secure browser-based OAuth flows, including Stack Auth login and Microsoft Graph connection for Outlook users.
  • scripting: To inject the packaged Website Protection scanner into the current public webpage only after you enable Website Protection and grant website access.
  • Required host permissions: To run on Gmail, Outlook Web, Yahoo Mail, Microsoft Graph, Yahoo Mail API endpoints, and InboxXray API domains needed for email analysis and report delivery.
  • Optional website host permissions: To inspect capped security signals on ordinary HTTP and HTTPS pages only after you enable Website Protection. These broad permissions are not required at installation.

5. Data Retention & Deletion

  • Raw Header Data and Uploaded Email Content: Processed for the requested analysis and discarded after the report is generated.
  • Analysis Reports: Stored for 14 days to allow you to review your history. Reports may include findings, checked link counts, and attachment hash results. This period is strictly limited to user-requested utility; data is automatically purged thereafter.
  • Website Protection Page Signals: Processed for the current check and not stored as browsing history or added to email analysis history. Operational security logs may contain the checked hostname, verdict, timestamp, extension version, IP address, and request metadata for service protection and troubleshooting.
  • Account Data: Retained while the account is active. You may delete your account and all associated data at any time via the Settings dashboard.

6. Data Security

We implement industry-standard security to protect your information:

  • Encryption: All production traffic between the web app, browser extension, and InboxXray APIs uses HTTPS/TLS. Analysis history is encrypted at rest.
  • Isolation: Your analysis history is stored as encrypted JSON and is only accessible to your authenticated account.
  • Network Protection: Browser certificate validation and HTTPS/TLS protect production requests from ordinary network interception.

Accuracy Disclaimer: Email threat analysis is probabilistic. InboxXray supplements but does not replace human judgment.

7. Your Rights (GDPR / CCPA)

Regardless of your location, you have the right to:

  • Access & Export: Download your analysis history.
  • Deletion: Permanently remove all your data from our systems.
  • Opt-out: Disable Website Protection, AI analysis, link scanning, attachment scanning, or History storage at any time.

8. Cookies & Local Storage

We do not use third-party tracking cookies, analytics pixels, or advertising trackers. We use only essential cookies, LocalStorage, and extension storage for authentication, preferences, and feature controls.

  • Authentication: Session tokens keep you signed in and allow InboxXray API requests over HTTPS. They are not shared with advertising or analytics providers.
  • User Preferences: Onboarding state, dismissed guidance, and optional scan toggles are stored locally so the interface behaves consistently.
  • Storage Boundary: Browser and extension storage are scoped by the browser origin and extension permission model.

We do not store raw email bodies, attachment bytes, typed website form values, payment card details, or passwords in LocalStorage or extension storage.

9. Contact Us

For any privacy concerns or to exercise your data rights, please contact our Data Protection Officer:

[email protected]
InboxXray

Your data stays private. We never store your email content.

Home Pricing Blog Privacy Policy Terms of Service Contact