Privacy

What we read, keep, and delete

Inbox Quest works by reading your email. That deserves a plain answer about what happens to it. Last updated September 17, 2026. This policy applies to the closed beta; it will be updated before public launch.

What we access

When you connect a Gmail account, you grant Inbox Quest read-only access to your mailbox (the Gmail read-only scope) and your email address. We use it to list messages, read message headers, and read the text of threads that need a verdict. By default we never send email, change labels, delete mail, or write anything to your mailbox. If you turn on label writing in Settings (off by default, and it asks you to reconnect with Google's modify permission), Inbox Quest adds and removes three labels of its own on your threads (Inbox Quest/Waiting on you, Inbox Quest/Urgent, Inbox Quest/Ally) and still never sends, deletes or moves mail or touches labels it did not create.

What we keep

Message metadata: sender and recipient addresses, subject, date, thread id, and the actions you took (received, sent, archived, marked spam, read). The judge's verdict for each thread: what was asked, whose move it is, urgency, difficulty, whether you promised something, the sender's name as they signed it, and for a scam the reason. Your settings: working hours, timezone, world, class, goals and view. Daily counts built from the above. If you bring your own Anthropic key it is stored encrypted, shown afterwards only by its last four characters, and used for nothing but your own verdicts.

What we never keep

Email body text is never written to our database. It is fetched, sent to the AI judge, and discarded. A short encrypted cache of a thread's text may exist for up to your chosen retention window (7 to 90 days) so the judge does not re-read a thread every time it changes, then it is deleted. Only the verdict stays.

Who sees it

Thread text is sent to our AI provider (Anthropic) to produce the verdict, under terms that forbid training on it. Nobody at Inbox Quest reads your email. Friends who view your party see stats, items and story, never senders, subjects, health or performance. If you turn on developer mode, you can see the prompt and raw response for your own threads; nobody else can. Team accounts do not exist yet; when they do, a manager will see verdicts and subject lines only, never bodies, and members will be told so before joining.

Your keys

OAuth tokens are encrypted at rest with a key that lives only on our servers. You can disconnect an inbox at any time from Settings, or revoke access at myaccount.google.com/permissions. Disconnecting deletes the token immediately; metadata and verdicts follow within 30 days, or at once on request.

Google's rules

Inbox Quest's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the features described here, is never sold, never used for advertising, and never used to train general AI models.

Deletion and questions

To delete your account and everything attached to it, use Settings or write to us through the beta form. We respond within a few days during the beta. A proper contact address arrives with the domain.