Privacy Policy

This Privacy Policy describes how InboxBucket ("we", "us") collects, uses, and protects personal data when you use inboxbucket.com and the InboxBucket service. InboxBucket delivers email backups to storage accounts owned and controlled by you; the archived emails themselves reside in your Google Drive, OneDrive, Dropbox, or S3-compatible storage — not on our servers. We retain only the data required to operate the service, as set out below.

Questions regarding this policy may be directed to [email protected].

Overview

  • Archived emails are delivered to storage you own and control. We do not retain message bodies or attachment contents.
  • For each processed email, we permanently retain only headers-level metadata (sender, subject, timestamps, sizes) in order to provide a searchable backup history and delivery status.
  • The full raw message passes through our systems only temporarily during delivery; the staged copy is deleted following successful delivery to your storage.
  • We use cookieless, self-hosted analytics, operate no advertising trackers, and do not sell personal data.
  • Payments are processed by Stripe; card details are transmitted directly to Stripe and never reach our servers.

Data we collect and how we use it

Account data

Upon registration, we store your email address and its verification status. Authentication is passwordless: we either send a one-time code to your email address, or you authenticate via Google or Dropbox, in which case the provider shares your email address and basic profile information with us. We do not collect or store passwords.

Your email address is used to authenticate you and to send transactional messages (verification codes, delivery-failure notifications, and material service announcements). We do not send unsolicited marketing communications.

Storage connection credentials

To deliver backups to your storage, we hold the credentials you grant us: OAuth tokens for Google Drive, OneDrive, and Dropbox, or the access keys you provide for S3-compatible storage. These credentials are encrypted at rest using AES-256-GCM, are excluded from application logs, and are used exclusively to upload your backups and to verify the connection. We request the narrowest authorization scopes each provider permits; for example, Dropbox connections are confined to a dedicated application folder.

Disconnecting a storage provider deletes the stored credentials. You may additionally revoke our access at any time through the provider's own security settings.

Email backup data

When an email arrives at your unique InboxBucket address, two categories of data are processed:

The raw message (temporary). The complete original email (.eml, including body and attachments) is placed in a private staging location only for as long as is required to deliver it to your storage. Following successful delivery, the staged copy is deleted. If delivery fails — for example, because your storage is full or requires re-authentication — the staged copy is retained to permit retries, and the failure is displayed in your dashboard.

Metadata (retained). For each email, we permanently store headers-level metadata: sender address, recipient address, subject line, Message-ID, message size, sent and received timestamps, an attachment manifest (filenames, content types, and sizes — not contents), delivery status including any error, and the path at which the backup was stored in your storage. This data provides your searchable backup history and enables deduplication of provider retries. We do not retain message bodies or attachment contents.

Emails sent to your address may contain personal data relating to their senders. We process such data solely to deliver your backup; we do not read, analyze, or profile message contents. Per-inbox sender allowlists allow you to restrict which senders' messages are processed.

Billing data

Payments are processed by Stripe. Card details are transmitted directly to Stripe and never reach our servers. We store your plan, a Stripe customer reference, and the payment reference associated with your purchase so that refunds and disputes can be attributed to your account. Stripe's processing of your data is governed by the Stripe Privacy Policy.

Analytics

We operate a self-hosted instance of Umami, a privacy-focused analytics tool, on our own infrastructure. It does not use cookies, collects aggregated usage statistics only (pages visited, referrer, browser type, and — on a sampled share of visits — where on a page visitors click and how far down they scroll), does not construct cross-site profiles, and its data is not shared with any third party.

Operational logs

Our servers maintain short-lived technical logs, including IP addresses, for the purposes of security, abuse prevention, and fault diagnosis.

Where your data is processed

Our application servers, database (containing the metadata described above), and analytics are hosted on Hetzner infrastructure in Germany (EU). Inbound email receipt, temporary staging storage, and outbound transactional email are provided by Cloudflare's global network. Payments are processed by Stripe. The complete list of vendors is maintained on our subprocessors page.

Your archived emails reside in the storage destination you designate, under your own agreement with that provider.

Retention

  • Staged raw emails: deleted following successful delivery to your storage; retained only as long as required to retry failed deliveries.
  • Email metadata: retained for the life of your account to preserve your searchable backup history.
  • Account data and credentials: retained for the life of your account.
  • Operational logs: short-lived and rotated automatically.

Upon deletion of your account, your account data, storage credentials, inboxes, email metadata, and any remaining staged messages are deleted. Backups already delivered to your own storage are unaffected and remain under your control.

Your rights

You may request access to, correction of, export of, or deletion of your personal data, and you may object to or request restriction of its processing. For individuals in the EU/EEA and the United Kingdom, these rights arise under the GDPR; we honor equivalent requests from all users. To exercise these rights, contact [email protected] from the email address associated with your account. You also have the right to lodge a complaint with your competent data protection authority.

What we do not do

We do not sell or rent personal data. We do not operate advertising or advertising trackers. We do not access the contents of your emails beyond the automated parsing required to extract the metadata described above and to deliver your backup.

Children

InboxBucket is not directed at children under 16 years of age, and we do not knowingly collect their data.

Changes to this policy

Amendments to this policy will be published on this page with an updated revision date. Material changes will be communicated to you by email.

Contact

Inquiries and requests: [email protected]