Privacy policy
Last updated July 2026.
What this covers
This describes how InboxAgent handles data belonging to the Shopify brands that use it, and the data of their customers that passes through it. It does not cover the separate consumer-facing services of Google, Shopify, or any other company you connect to your account — read their own privacy policies for that.
What we read and store
When you connect Gmail, InboxAgent reads the last twelve months of your support inbox's sent replies once, to learn your policies and your tone, and then reads new inbound and outbound mail on an ongoing basis to classify and draft replies. When you connect Shopify, it reads order, fulfillment, and customer records needed to answer order-status questions. We store your emails, the drafts generated from them, and the order data needed to answer customer questions.
OAuth tokens for Gmail and Shopify are encrypted at rest with AES-256-GCM. They are never stored or logged in plain text.
Your data is never used to train any model
Your email content and your customers' data are used only to answer your customers. They are never used to train any AI model, ours or anyone else's, and never shared with or made visible to any other InboxAgent account. Every database query in the product is scoped to your workspace; there is no code path that reads across workspaces.
Who else touches your data
A small number of subprocessors do the work of running the product: Anthropic (classifying messages and drafting replies), an embeddings provider (matching new questions against your past replies), Supabase (database and authentication), Shopify and AfterShip (order and shipment lookups), Resend (account and product email), and Sentry (error monitoring). Each is bound to use your data only to provide their service to us, not for their own purposes.
Deleting your data
You can permanently delete everything associated with your workspace at any time from Settings, under Data and audit. That action is irreversible: every email, thread, draft, and setting for the workspace is removed.
Questions
Email privacy@inboxagent.com with any question about this policy or your data.