Privacy
What this service reads, where it goes, and what is kept. Last updated 2026-09-16.
Who we are
InboxTrace is the controller of the personal data described here. Write to privacy@inboxtrace.app about anything on this page. Our full trading details are at the bottom.
What happens in your browser and is never uploaded
When you drop a mailbox file, or when a connected mailbox is searched, the emails are read by code running in your own browser. Parsing, shortlisting the emails that look like travel, pairing departures with returns, counting days, and building the report all happen on your device. We do not store your mailbox, your emails, the absences found, or the report; on the connected path the matching emails pass through our server in transit, and on the Takeout path they never leave your device at all. There is no database on our side and nothing is written to one.
The two places email content goes
Two things do leave your device, and only when you start them. Both are named here so you can decide before you connect or run.
1. The mail connector, when you connect a mailbox
If you press Connect Gmail or Connect Outlook, the connection is made through Nylas, Inc., a mail API vendor, on their EU infrastructure. Nylas holds the access grant to your mailbox and runs the search queries we send it; the matching emails pass through Nylas to your browser. Nylas states that it does not retain the content of Google and Microsoft mailboxes. We never see the grant: it is kept in a signed cookie in your browser and used by our server only to forward your own requests. You do not need to connect at all: you can export your mailbox yourself and drop the file instead, and then no connector is involved.
2. The model provider, when you run
To turn a booking email into dates, the emails that look like travel (roughly one in a hundred) are sent to a language model to be read. Each one is sent as its subject, sender, recipients, date, attachment names and text. By default they go through our server, which adds our key and forwards them without logging or storing their content, to Google Gemini on Google Cloud Vertex AI. We use Vertex AI's global endpoint, which means Google may process the request in any of its regions rather than one we have pinned. If you choose the advanced option and enter your own Anthropic API key, the same emails go from your browser straight to Anthropic under your own account and never touch our server. You can also choose to send nothing, in which case the run stops after the shortlist and no absences can be built.
Why: this is the only way the service can read a booking. What is sent is limited to the shortlisted emails, and we are working to send only the passages that matter rather than whole messages.
Whose data: booking emails often name other people, such as partners, children and co-travellers, and travel insurance emails can contain health information. If that is the case for your mailbox, you are sending their data too. Only run the service on a mailbox you are entitled to use in this way.
What happens when you pay
Payment is taken by Stripe, Inc. on their own checkout page. Your card details go to Stripe and never to us or through our servers. Stripe asks for your email address so it can send a receipt, and tells us that the payment succeeded.
We then use that address once, to send you a link that reopens your report. The mail is sent by Resend, Inc., an email delivery service. Your address passes through Stripe to us to Resend and is not written to any store of ours at any point: the link is sent and the address is dropped. It is the only email we send you, there is no mailing list, and we will not write to you again.
What the link contains is the identifier of your Stripe payment, nothing about your mailbox or your report. Opening it asks Stripe whether that payment succeeded and, if so, unlocks the report in whichever browser you opened it in. Anyone with the link can do that, so treat the email as you would a receipt.
Cookies
We set two cookies, both marked httpOnly so page scripts cannot read them, and both signed so they cannot be forged. We use no analytics and no advertising cookies.
- The connection cookie (
inboxtrace_grant) is set when you connect a mailbox. It holds the connector's identifier for your mailbox, your email address and which provider it is. It lasts 24 hours, and is deleted when you press Disconnect. - The unlock cookie (
inboxtrace_unlock) is set when a payment is confirmed. It holds only the word paid and the time of the payment. It lasts 30 days, in the browser where you paid. We keep no record of who paid; the payment record is held by Stripe, our payment provider, under their own privacy notice, and we never see your card details. - A short-lived state cookie (
inboxtrace_connect_state, 10 minutes) protects the connection step against forgery and holds a random value only.
While you pay, your browser keeps the run you just did in its own session storage so the result is still there when you come back. That stays on your device and is not sent to us.
Disconnecting, and what that deletes
The grant is handed back automatically when a run finishes, and Disconnect does the same at any time. For Google, deleting the grant also revokes the access token; for Microsoft and other providers the provider token stays active, so remove InboxTrace in your account settings there as well. Note that the connection cookie lasts 24 hours: after that this site can no longer reach the grant to delete it, which is why a finished run hands it back. And clears the connection cookie. If the connector cannot be reached, the cookie is still cleared and the page tells you to remove the app from your account settings as well. Because we store nothing, there is nothing further of yours on our side to delete; closing the tab discards the run and the report unless you saved or printed them.
Lawful basis (UK GDPR)
- Running the service, including sending the shortlisted emails to the model provider: performance of a contract with you (Article 6(1)(b)).
- Connecting your mailbox through the connector: your consent (Article 6(1)(a)), which you give at the provider's screen and withdraw by disconnecting.
- Sending you the link that reopens your report, and keeping a record of the payment: performance of the same contract (Article 6(1)(b)).
- Where an email contains health or other special category data, you are sending it for your own purposes. We rely on your explicit consent (Article 9(2)(a)), given when you choose to run the service knowing what is sent. [unverified] This basis has not been confirmed by a solicitor, and the alternative reading is that the processing is outside UK GDPR entirely because it is yours and personal to you. We have written down the more demanding of the two.
International transfers
Some of the vendors above process data outside the United Kingdom: Nylas on EU infrastructure, Google Cloud wherever its global Vertex endpoint routes the request, Stripe and Resend in the United States, and Anthropic in the United States when you use your own key.
[unverified] The transfer safeguard has not been settled with a solicitor. The mechanisms that would apply are UK adequacy regulations for the EEA, the UK Extension to the EU-US Data Privacy Framework where a vendor is certified under it, or the ICO's International Data Transfer Agreement. We have not yet confirmed which of these each vendor relies on, and we would rather say so than name one we have not checked. Ask at privacy@inboxtrace.app and we will tell you where we have got to.
Your rights
You have the usual rights under UK GDPR: access, correction, erasure, restriction, portability and objection. Because we keep nothing about you, most of these are met by the fact that there is nothing to return or delete; write to privacy@inboxtrace.app and we will confirm that. You can complain to the Information Commissioner's Office at ico.org.uk.
Analytics
None. No analytics, tracking or advertising scripts run on these pages. If that changes, this notice will say so first.
InboxTrace is a trading name of Theodoros Poulopoulos, a sole trader in England and Wales, at 61 Bridge Street, Kington, Herefordshire, HR5 3DJ. Write to privacy@inboxtrace.app.