Privacy Policy
Last updated: July 23, 2026
inboxrow is a tool for sending cold email from your own mailboxes. This page explains, in plain English, what information we collect, why, and what we do with it.
The short version
- We collect the details you give us when you request access, and the data you bring into the product to run your campaigns.
- We use it to run inboxrow for you — nothing else.
- We never sell your data, and we never use your contact lists or email content for anything except sending your campaigns.
- Ask us to delete your data and we will.
What we collect on this website
When you fill in the “Request access” form, we collect your name, work email, company, and what you plan to send. That's it — we use it to reply to you and set up your access.
The form is delivered to our inbox by Web3Forms, a form-to-email service, which processes your submission for that one purpose.
This website doesn't use analytics or advertising trackers, and doesn't set tracking cookies. The page loads its font from a third-party host (rsms.me), which sees a standard web request (like your IP address) when the font loads.
What we collect when you use inboxrow
If you become a customer, we handle:
- Account details — your name, email, and login information.
- Mailbox connections — the authorization you grant so inboxrow can send from your own mailboxes. We store the connection credentials securely and use them only to send and manage your campaigns.
- Campaign data — the contact lists you upload, the emails you write, and your sending settings.
- Activity data — sends, replies, and delivery status, so your dashboard and reports work.
Google user data and Limited Use
When you connect a Google account, inboxrow asks only for the permission it needs to set up sending from your own mailbox. Specifically, we request access to create and manage the files inboxrow itself creates in your Google Drive (drive.file), to read and write those spreadsheets (spreadsheets), and to create and deploy the Apps Script that sends your campaigns (script.projects, script.deployments). We use these solely to provision, per campaign, the spreadsheet and sender script that run in your own account so mail sends from your own Gmail on your own quota.
Gmail sending itself is authorized separately by you, to your own script, under your own account. Our servers never read your inbox beyond detecting replies to your campaigns, and never send mail themselves. OAuth tokens are stored encrypted (AES-256-GCM) at rest and used only for the operations above.
inboxrow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except with your explicit consent, for security purposes, or where required by law.
Your contacts' data
The contact lists you upload belong to you. You decide who is on them; we process that data only on your instructions, to run your campaigns.
We don't use your contacts for our own marketing, don't share them with other customers, and don't sell them to anyone. When you delete a list or close your account, we delete it.
You're responsible for having a lawful basis to email the people on your lists — see our Terms of Service for what that means.
What we never do
- Sell or rent your data. To anyone, ever.
- Read your mailbox beyond what's needed to send campaigns and detect replies.
- Use your lists, copy, or results to benefit other customers.
Who we share data with
Only the service providers we need to run inboxrow — such as hosting, form delivery, and your own email provider (which necessarily processes the mail you send through it). They may only use your data to provide their service to us.
Beyond that, we'd only disclose data if the law genuinely requires it.
How long we keep it
Access requests: as long as needed to respond and set you up. Customer data: for as long as you have an account. When you close your account — or just ask — we delete your data within 30 days, except the minimum we must keep for legal or accounting reasons.
Security
We keep the surface area small on purpose: few systems, few providers, credentials stored encrypted, and access limited to the people who run the service. No system is perfectly secure, but less infrastructure means less to go wrong — that's the whole idea behind inboxrow.
Your rights
You can ask us at any time to show you the data we hold about you, correct it, export it, or delete it. Email us and we'll sort it out — no forms, no runaround. Depending on where you live (for example the EU/UK under GDPR, or California under CCPA), these rights are also guaranteed by law.
Changes to this policy
If we change this policy in a way that matters, we'll update the date at the top and let active customers know by email.
Contact
Questions about your data? Email us at pranav.kumar@inboxrow.com. A real person reads it.
© 2026 inboxrow · Terms of Service