Zenbox Privacy Policy
Effective Date: 30 September 2025
Zenbox (“we,” “our,” or “us”) respects your privacy and is committed to protecting your personal information.
This Privacy Policy explains how we collects, uses, stores, shares, and deletes information—including data obtained from third-party providers such as Google and Microsoft—when you use Zenbox (the “Service”).
By using Zenbox, you agree to the terms of this Privacy Policy.
1. Information We Collect
We collect the following types of information to operate and improve Zenbox:
1.1. Account & Profile Data
-
Name, email address, and password (hashed and encrypted).
-
Optional profile details, such as nickname and job title, to personalize AI responses.
1.2. Email Data
-
Email content, metadata, and attachments accessed only to provide AI-powered features such as:
-
Prioritization and categorization
-
Summaries and response suggestions
-
Workflow integrations
-
We do not sell or share your emails with third parties for advertising purposes.
1.3. Service Usage Data
- Log files, IP addresses, device type, browser version, and app interactions.
- Used for performance monitoring, analytics, and security.
1.4. Cookies and Tracking
- We use cookies and similar technologies to enhance functionality and measure usage.
- You can manage or disable cookies in your browser settings.
1.5. Connected Email Provider Data (All Providers).
When you connect a third-party email provider (e.g., Google/Gmail, Microsoft Outlook/Graph, IMAP), and depending on features you enable, we may access:
- Account identifiers (e.g., account ID, email address, profile name).
- Mailbox metadata (headers, sender/recipient, subject, timestamps, thread/label/folder IDs).
- Message content & attachments only as needed to deliver features you invoke (e.g., summaries, prioritization, reply suggestions).
- Mailbox actions/settings that you request (e.g., apply labels/categories, archive/move, send/reply).
We strive to access the minimum data necessary for the features you choose.
2. How We Use Information
We use the collected information to:
1. Provide & improve the Service (sync mail, display content, apply tags/categories/folders you choose).
2. AI features you invoke (generate summaries, priorities, reply suggestions from messages you select).
3. User-initiated actions (send, schedule, delegate emails).
4. Security & reliability (fraud/abuse prevention, diagnostics, performance).
5. Communicate service updates, security alerts, or legal notices.
We do not sell your personal information or use it for advertising, and we do not use your content to train generalized AI models.
3. Provider-Specific Disclosures
3.1 Google User Data — Limited Use Compliance
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We access only the Google scopes needed for features you enable.
- We do not sell Google user data or use it for ads.
- We do not permit third-party human access to Google user data except for security/compliance or customer-initiated support.
- Transfers to sub-processors occur only to operate or improve user-facing features and are bound by data-processing terms.
- You may revoke access at any time in your Google Account settings.
Optional Scopes List (include only what you actually use):
gmail.readonly (read to display/summarize), gmail.modify (apply labels/move), gmail.send (send emails on your instruction), userinfo.email, userinfo.profile.
3.2 Microsoft Outlook/Graph Data
When you connect Microsoft accounts, we use Microsoft Graph solely for features you enable (reading mail to display/summarize,
applying categories/folders, sending on your instruction). We do not sell Microsoft data or use it for advertising.
You can revoke access in your Microsoft account settings.
4. How We Share Your Information
We do not sell your personal data.
We only share information in the following circumstances:
-
Service Providers: Trusted third parties for hosting, AI processing, or analytics under strict confidentiality agreements.
-
Legal Requirements: When required by law, court orders, or to protect our legal rights.
-
Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred under the same privacy commitments.
5. Data Storage and Security
5.1. We store your data securely using encryption in transit (TLS) and at rest.
5.2. Access to your data is restricted to authorized personnel only.
5.3. While we implement industry-standard measures, no system is 100% secure, and we cannot guarantee absolute data protection.
6. Retention & Deletion
-
We retain data only as long as necessary to provide the Service, comply with legal obligations, or resolve disputes.
-
Disconnect: You may revoke Zenbox’s access to a provider (e.g., Google/Microsoft) at any time in your account with that provider.
-
Delete: Request account deletion via in-app controls or support@zenbox.so. We will delete stored personal data and purge caches/derived artifacts within a reasonable period, subject to legal holds and backup cycles.
-
Backups: Deleted data may persist in encrypted backups for a limited time until routine purge.
7. Your Rights
Depending on your location (e.g., under GDPR, CCPA), you may have the following rights:
-
Access and Portability: Request a copy of your personal data.
-
Correction: Update or correct inaccurate information.
-
Deletion: Request deletion of your personal data.
-
Restriction and Objection: Limit or object to certain processing.
To exercise these rights, contact us at privacy@zenbox.so.
8. International Data Transfers
Zenbox may process your data in countries outside your residence. We ensure that appropriate safeguards (e.g., Standard Contractual Clauses) are in place for cross-border data transfers.
9. Children’s Privacy
Zenbox is not intended for individuals under 18. We do not knowingly collect personal data from minors. If we learn that we have inadvertently collected data from a child, we will delete it promptly.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or within the Service. Your continued use of Zenbox after changes indicates acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or your data, contact us:
Email: privacy@zenbox.so