Privacy Policy

Last updated: 2026-09-27

In short

  • We collect only what we need to run your inbox: your account details, the tools you connect, and what we need to bill you and keep the service secure.
  • Data from your connected tools is used only to show it back to you and to act on it when you ask. We never sell your data and we never use it for advertising.
  • Everything is hosted in the European Union. A few providers are based outside it (for example our tracing and avatar providers); they are listed below.
  • You can delete your account yourself at any time from your Profile page. To see or export your data, email privacy@universal-inbox.com.

This summary is here to help you read the policy. The full text below is what applies.

1. Who we are

In short: Universal Inbox is run by one person, David Rousselie, in France.

Universal Inbox is operated by David Rousselie, entrepreneur individuel (sole trader) registered in France. Full details are in our Legal Notice. In this policy, "we", "us" and "our" refer to him as the operator of Universal Inbox.

We are the data controller for the personal data described in this policy, under the EU General Data Protection Regulation (GDPR) and the French loi Informatique et Libertés.

This policy covers:

Universal Inbox is also open-source software that anyone can host. This policy does not cover instances hosted by someone else: the person or organization running that instance is responsible for your data there.

Contact for anything related to your data: privacy@universal-inbox.com.

2. What data we collect

In short: your account, the content of the tools you connect, billing status, support messages and technical logs.

CategoryWhat it includesWhere it comes from
AccountFirst and last name, email address, password (stored only as a secure Argon2 hash), passkeys, identity from a sign-in provider (e.g. Google)You, or the sign-in provider you choose
Connected toolsAccess tokens for the tools you connect (encrypted with AES-256-GCM), and copies of the items we sync: notifications, emails, messages, issues, pull requests, calendar events, document comments, tasks. These items can contain personal data about other people (e.g. the sender of an email).The tools you connect (see section 4)
BillingStripe customer and subscription identifiers, plan, subscription status and billing period. We never see or store your card number.Stripe
SupportMessages you send us through the in-app chat or by email, with your name, email and user IDYou
API and AI accessAPI keys you create, and the AI assistants you authorize to access your account (MCP)You
TechnicalIP address, browser type, request logs and performance traces, login attempts. Traces identify you only by an internal user ID: email addresses, IP addresses and one-time links are removed before traces leave our servers.Your device, when you use the Service
Website statisticsAnonymous page-view statistics, with no cookies and no personal profileYour browser, when you visit the website

We do not collect sensitive data on purpose. If one of your connected tools contains sensitive information, we only process it as part of the item it belongs to, to show it to you.

In short: mostly to provide the service you signed up for, plus security and legal obligations.

PurposeLegal basis (GDPR art. 6)
Create and manage your account, sign you inPerformance of our contract with you
Sync your connected tools, show your notifications and tasks, perform the actions you ask forPerformance of our contract with you
Manage your subscription and paymentsPerformance of our contract with you
Keep invoices and accounting recordsLegal obligation
Answer your support requestsPerformance of our contract, or our legitimate interest in helping you
Send service emails: email verification, password reset, account lockout alert, sign-up attempt on an existing accountPerformance of our contract, and our legitimate interest in securing your account
Protect the Service: rate limiting, lockout after failed logins, abuse preventionLegitimate interest (security)
Detect and fix bugs and performance problems using logs and tracesLegitimate interest (keeping the Service working)
Measure website audience anonymouslyLegitimate interest (improving the website)
Show your avatar (Gravatar) and product news (Headway) in the appLegitimate interest (a more usable interface)

We do not send marketing emails. If we ever want to, we will ask for your consent first.

We do not make automated decisions that have legal or similarly significant effects on you.

4. The tools you connect

In short: we read what we need to fill your inbox, and we only change something in a tool when you ask us to.

When you connect a tool, you authorize Universal Inbox through that tool's own sign-in page. You can see and change the permissions there. Here is what each integration does:

ToolWhat we readWhat we can do on your behalf
GitHubYour notifications and the issues, pull requests, discussions and alerts they point toMark notifications as read, unsubscribe from threads
LinearYour notifications and issuesMark notifications as read or delete them, unsubscribe, complete or delete issues
GmailEmail threads with the label you choose, your labels and profileAdd or remove labels (mark as read, archive)
Google CalendarEvent invitationsAnswer invitations (accept, decline, maybe)
Google DriveFile comments and file metadataNothing: access is read-only
SlackMessages, threads, channels, users, user groups, emoji and reactions related to the items you saveAdd or remove reactions
TodoistYour tasks and projectsCreate, update, complete and delete tasks
TickTickYour tasks and projectsCreate, update, complete and delete tasks

We act on a tool only when you trigger an action, or when a rule you set up asks us to.

Browser extension. The extension can send a web page to your inbox. Its "Slack bridge" feature uses your existing Slack session inside your own browser to talk to Slack; your Slack session token stays in your browser, and only your Slack workspace ID and user ID are sent to our servers.

Disconnecting a tool. When you disconnect a tool, we delete the access tokens we stored for it and ask the tool to revoke Universal Inbox's access. If that request fails (for example because the tool is unavailable), you can still revoke access yourself in the tool's settings, such as your Google account or GitHub settings. Items already imported stay in your account: notifications are hidden, and tasks are kept. They are deleted when you delete your account, or sooner if you ask us.

5. Google user data

In short: data from Google is used only to provide the features you see, and never for ads or AI training.

Universal Inbox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, for data from Gmail, Google Calendar and Google Drive:

  • we use it only to provide and improve the user-facing features of Universal Inbox that you can see in the app;
  • we do not transfer it to others, except as needed to provide those features, to comply with the law, or as part of a merger or acquisition with your notice;
  • we do not use it for advertising, and we do not sell it;
  • no human reads it, unless you ask us to (for example for support), it is needed for security or to investigate abuse, or the law requires it;
  • we do not use it to develop, improve or train generalized AI or machine-learning models.

6. AI assistants and API keys

In short: if you connect an AI assistant, it sees what you ask it to see, under your own agreement with its provider.

You can let an AI assistant (such as Claude, ChatGPT, Gemini or Mistral) access your Universal Inbox through our MCP server, or create API keys for tools like the Raycast extension. When you do, the data that the assistant or tool requests is sent to it. What its provider does with that data is governed by your own agreement with that provider, not by this policy.

You can revoke an AI assistant or an API key at any time in your settings.

7. Who we share data with

In short: only with the providers that help us run the Service, and never for advertising.

We use the following providers (called "processors"). They may only use your data to provide their service to us, under a data processing agreement.

ProviderPurposeLocation
Koyeb (Mistral AI SAS)Hosting of the applicationEuropean Union (Frankfurt, Germany)
Neon, Inc.Database hostingEuropean Union region; US company
Scaleway SASSending service emailsEuropean Union (France)
Stripe Payments Europe, Ltd.Payments and subscription managementIreland; Stripe group worldwide
Crisp IM SASIn-app support chatEuropean Union (France)
Hound Technology, Inc. (Honeycomb)Performance traces for debugging (identified by an internal user ID only, with no email or IP address)United States
Cloudflare, Inc.Website hosting and deliveryWorldwide network; US company
Automattic, Inc. (Gravatar)Showing your profile picture, based on a hash of your email addressUnited States
Headway"What's new" widget in the app (receives your IP address when it loads)Outside the EU

Stripe also acts as an independent controller for the payment data it collects directly from you. See Stripe's privacy policy.

The tools you connect (section 4) receive the actions you ask us to perform. They are chosen by you and process data under their own terms.

We may also disclose data if the law requires it, for example to answer a valid request from a court or public authority. If Universal Inbox is ever sold or transferred, your data would move to the new operator, who would be bound by this policy; we would tell you beforehand.

We do not sell your personal data, and we do not share it with advertisers or data brokers.

8. Transfers outside the European Union

In short: when a provider is outside the EU, we use the legal safeguards the GDPR requires.

Some providers listed above are based in, or can access data from, countries outside the European Economic Area, mainly the United States. In those cases, the transfer is covered by the provider's certification under the EU-U.S. Data Privacy Framework and/or by the European Commission's Standard Contractual Clauses. You can ask us for more information about these safeguards.

9. How long we keep data

In short: as long as you have an account, then we delete it.

DataHow long
Account and connected-tool dataAs long as your account exists. Deleted as soon as you delete your account (or within 30 days if you ask us by email).
Payment event notifications from Stripe30 days
BackupsDeleted data disappears from backups within 30 days
Invoices and accounting records10 years, as required by French law (Code de commerce, art. L123-22). They stay with Stripe, unlinked from your deleted account.
Logs and traces60 days
Support conversations3 years after your last message

10. How we protect your data

In short: encryption, careful access, and we tell you if something goes wrong.

  • All traffic to the Service is encrypted in transit (HTTPS).
  • Access tokens for your connected tools are encrypted at rest (AES-256-GCM).
  • Passwords are never stored in clear, only as an Argon2 hash. API keys are stored only as a hash.
  • Repeated failed login attempts lock the account temporarily, and you get an email alert. Sign-in, sign-up and password-reset requests are rate-limited.
  • Password-reset links expire after 1 hour and email-verification links after 24 hours. Each works only once.
  • A new email address only replaces the old one once you have confirmed it.
  • Only the operator has administrative access to production systems.

No system is perfectly secure. If a data breach is likely to put your rights at risk, we will notify the French data protection authority (CNIL) within 72 hours and inform you without undue delay, as the GDPR requires.

11. Cookies and similar technologies

In short: we only use what the Service needs to work. No advertising or tracking cookies.

Name / typeSet byPurposeDuration
id cookieUniversal Inbox (app)Keeps you signed in (strictly necessary)30 days
Local storageUniversal Inbox (app)Remembers your settings, and completes sign-in with an external provider (strictly necessary)Until you clear it
Chat cookiesCrisp (app)Keeps your support conversation open across pages. Crisp loads only when you click Support in the app, never before and never on the sign-in or sign-up pages.Set by Crisp

When the app loads your avatar from Gravatar or the "What's new" widget from Headway, these providers receive your IP address and may set their own cookies.

The website www.universal-inbox.com uses a self-hosted, privacy-friendly analytics tool (Umami). It uses no cookies and does not build a profile of you.

Because we only use cookies that are needed for the Service to work, we do not show a consent banner. You can block or delete cookies in your browser settings, but you will not be able to stay signed in.

12. Your rights

In short: it's your data. Ask and we'll help.

Under the GDPR you have the right to:

  • access your data and get a copy of it;
  • correct inaccurate data;
  • delete your data ("right to be forgotten");
  • restrict how we use your data;
  • receive your data in a structured, machine-readable format (portability);
  • object to processing based on our legitimate interest;
  • set instructions for what happens to your data after your death (French loi Informatique et Libertés, art. 85).

You can update your name and email in your account settings.

You can delete your account yourself from your Profile page ("Delete my account"). You confirm by typing your email address. We then cancel any paid subscription immediately, ask each connected tool to revoke our access, and delete your account and all its data. Invoices are kept for the legal retention period (section 9).

For anything else, including a copy or export of your data, email privacy@universal-inbox.com. We may ask you to confirm your identity. We answer within one month.

If you think we have not respected your rights, you can complain to the CNIL, the French data protection authority, or to the authority of the EU country where you live.

13. Children

The Service is not intended for anyone under 15. We do not knowingly collect data from children under 15. If you believe a child has created an account, contact us and we will delete it.

14. Changes to this policy

If we make significant changes to this policy, we will tell you by email or in the app before they take effect. The date at the top of this page shows when it was last updated.

15. Contact