Privacy Policy
Last updated: August 9, 2026
This Privacy Policy explains what information InboxOK ("InboxOK," "we," "us") collects when you use inboxok.com, app.inboxok.com, and api.inboxok.com (the "Service"), why we collect it, and the choices you have. If anything here is unclear, email support@inboxok.com — we'll answer directly.
1. What We Collect
To run your account, we store:
- Your email address — used to sign you in (magic link / one-time code) and send alerts.
- The domains you add and their public DNS records (SPF, DKIM, DMARC), blacklist status, and inbox-placement test results — the data the Service exists to show you.
- Billing information — handled directly by Stripe. We store a Stripe customer/subscription reference, never your card number.
- API keys you generate — stored as a one-way hash, not in plain text; we can't recover a lost key, only issue a new one.
- Webhook URLs you configure, and your notification preferences (which alert emails you receive).
- Basic technical logs (IP address, timestamps, request metadata) generated by normal API and web traffic, used for security and debugging.
2. What We Deliberately Don't Collect
- We never see the content of your outbound email, your customer lists, or your SMTP credentials.
- Inbox-placement testing sends diagnostic messages only to InboxOK's own seed mailboxes — never to your actual customers or contacts.
- We don't run any third-party analytics or advertising trackers on the Service. There is no ad tech here.
3. How We Use This Information
- To run the domain checks and placement tests you've requested, and alert you to the results.
- To authenticate you and secure your account.
- To process billing for paid plans.
- To respond to support requests.
- To maintain and improve the Service's reliability and security.
We do not sell your information, and we do not use it for advertising.
4. Third-Party Service Providers
Running the Service means some data necessarily passes through infrastructure we rely on:
- Supabase — handles authentication (magic links / one-time codes) and stores your account's login identity.
- Stripe — processes payments for paid plans; holds your card details, not us.
- Resend — delivers the transactional emails we send you (sign-in links, alerts, digests).
- Mail-Tester — powers real inbox-placement testing; we send diagnostic test emails to Mail-Tester-provided addresses, never your data.
- Railway and Vercel — host the backend API and web dashboard respectively.
Each of these providers processes data under their own privacy policy, and only for the purpose of operating InboxOK on our behalf. We don't hand your data to anyone beyond this list.
5. Cookies
We use a small number of strictly functional, first-party cookies to keep you signed in (an httpOnly session cookie set after you verify a magic link or code). We don't use cookies for advertising or cross-site tracking, and we don't run any third-party analytics scripts on the Service.
6. Data Retention
We keep your account data for as long as your account is active. Domain check history is kept to power the trending health view the Service is built around. If you close your account (see below), we delete your account data within a reasonable period, except where we're required to keep billing records for tax or legal purposes.
7. Your Choices
- You can turn off digest and non-critical alert emails anytime from your dashboard's notification settings.
- You can revoke any API key from your dashboard at any time.
- To close your account and request deletion of your data, email support@inboxok.com from your account email. We don't yet have a self-serve delete-account button — until we do, this is the reliable way to reach us and we'll action it directly.
8. Security
We use industry-standard practices to protect your data in transit (HTTPS everywhere) and at rest, including storing API keys as one-way hashes rather than plain text. No method of transmission or storage is 100% secure, so we can't guarantee absolute security, but we take reasonable steps to protect your information.
9. Children's Privacy
The Service is not directed at children, and we don't knowingly collect information from anyone under 18.
10. International Data Transfers
InboxOK's infrastructure providers (listed in Section 4) operate internationally, which means your data may be processed in countries other than your own, including the United States. We rely on those providers' own security and compliance practices for that processing.
11. Changes to This Policy
We may update this Privacy Policy as the Service evolves. We'll update the "Last updated" date above, and for material changes, notify active account holders by email.
12. Contact
Questions about this policy or your data? Email support@inboxok.com.