Privacy Policy
Last updated: May 8, 2026
The short version
- We process emails sent to your mailboxes so we can deliver them as webhooks to your endpoint. That’s the only thing we do with your email content.
- We store the raw email, parsed contents, and attachments for as long as your mailbox retention setting (30 days during the free beta).
- We don’t sell your data, and we don’t use email contents to train AI models.
- We use Cloudflare (compute, storage, email routing) and Backblaze B2 (raw email and attachment storage) as sub-processors.
- You can delete your account at any time. Deletion purges your data within 30 days.
1. Who we are
“Inbound” (“we”, “us”, “our”) operates the email-to-webhook service available at this domain. For privacy-related inquiries, contact privacy@inbound.prosvita.io.
2. Data we process
Account data
- Your email address, hashed password, and account name.
- Recovery codes you generate and the timestamps of their use.
- Billing identifiers when paid plans launch (handled by Stripe; we never see your card details).
Email data
- The raw
.emlmessage we receive on your behalf. - Parsed headers, text body, HTML body, links, and attachments — subject to your per-mailbox processing settings.
- Spam verdict and score from Cloudflare Email Routing.
- Sender, recipient, message-id, and received-at timestamp.
Operational data
- Server logs, IP addresses, and request metadata used for security, abuse prevention, and debugging. Retained on a rolling 30-day window.
3. How we use this data
- To deliver the service. Receiving, parsing, signing, and dispatching email to your webhook endpoint.
- To keep the service reliable. Detecting failed deliveries, handling retries, and showing you the audit log.
- To prevent abuse. Identifying unusual sending or receiving patterns that could disrupt the service.
We do not use your email content to train machine-learning models. We do not sell your data. We do not run platform-side advertising.
4. Where data is stored
- Account state and metadata: Cloudflare D1 (SQLite at the edge). Default region: United States.
- Raw
.emland attachments: Backblaze B2 inus-east-005, with per-prefix lifecycle rules that delete data once it passes your retention window. - SMTP edge: Cloudflare Email Routing handles inbound mail before it reaches our Worker.
EU data residency will be available on paid plans when introduced.
5. Sub-processors
We rely on the following sub-processors. We will publish a versioned list and notify customers in advance of material changes.
- Cloudflare, Inc. — compute (Workers), storage (D1), queues, and Email Routing.
- Backblaze, Inc. — B2 object storage for raw email and attachments.
- Stripe, Inc. — billing (when paid plans launch).
6. Retention
- Raw emails and attachments: retained for the duration set on each mailbox (30 days on the free beta; longer on paid plans).
- Account data: retained until you delete your account. Deletion completes within 30 days.
- Logs: rolling 30-day window.
7. Your rights
Depending on where you live, you have the right to access, correct, delete, port, or restrict the personal data we hold about you, and to object to certain processing. To exercise any of these rights, email privacy@inbound.prosvita.io. We respond within 30 days.
If you live in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority.
8. Security
- HTTPS in transit. Encryption at rest for D1 and B2.
- Webhook signing secrets are envelope-encrypted in our database with a key held by the Worker — they are shown to you once at creation and never readable again.
- Account access is scoped by membership and role.
- An audit log is maintained for sensitive operations.
9. Children
The service is not directed at children under 16, and we do not knowingly collect personal data from them.
10. Changes to this policy
We will revise this page for material changes and update the “Last updated” date. Because the platform does not yet send transactional email (see our Terms), we surface change notices in-app rather than by email.
11. Contact
Questions or requests: privacy@inbound.prosvita.io.
12. Photography & typography
Marketing photographs are sourced from Pexels and Unsplash under their respective free-to-use licenses. The Newsreader typeface is provided by Google Fonts under the SIL Open Font License and self-hosted on this domain (no Google Fonts requests are made from your browser).
This document is v0 and will be reviewed before paid launch.