Last updated: 2026-09-27
In short
- We collect only what we need to run your inbox: your account details, the tools you connect, and what we need to bill you and keep the service secure.
- Data from your connected tools is used only to show it back to you and to act on it when you ask. We never sell your data and we never use it for advertising.
- Everything is hosted in the European Union. A few providers are based outside it (for example our tracing and avatar providers); they are listed below.
- You can delete your account yourself at any time from your Profile page. To see or export your data, email privacy@universal-inbox.com.
This summary is here to help you read the policy. The full text below is what applies.
In short: Universal Inbox is run by one person, David Rousselie, in France.
Universal Inbox is operated by David Rousselie, entrepreneur individuel (sole trader) registered in France. Full details are in our Legal Notice. In this policy, "we", "us" and "our" refer to him as the operator of Universal Inbox.
We are the data controller for the personal data described in this policy, under the EU General Data Protection Regulation (GDPR) and the French loi Informatique et Libertés.
This policy covers:
Universal Inbox is also open-source software that anyone can host. This policy does not cover instances hosted by someone else: the person or organization running that instance is responsible for your data there.
Contact for anything related to your data: privacy@universal-inbox.com.
In short: your account, the content of the tools you connect, billing status, support messages and technical logs.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | First and last name, email address, password (stored only as a secure Argon2 hash), passkeys, identity from a sign-in provider (e.g. Google) | You, or the sign-in provider you choose |
| Connected tools | Access tokens for the tools you connect (encrypted with AES-256-GCM), and copies of the items we sync: notifications, emails, messages, issues, pull requests, calendar events, document comments, tasks. These items can contain personal data about other people (e.g. the sender of an email). | The tools you connect (see section 4) |
| Billing | Stripe customer and subscription identifiers, plan, subscription status and billing period. We never see or store your card number. | Stripe |
| Support | Messages you send us through the in-app chat or by email, with your name, email and user ID | You |
| API and AI access | API keys you create, and the AI assistants you authorize to access your account (MCP) | You |
| Technical | IP address, browser type, request logs and performance traces, login attempts. Traces identify you only by an internal user ID: email addresses, IP addresses and one-time links are removed before traces leave our servers. | Your device, when you use the Service |
| Website statistics | Anonymous page-view statistics, with no cookies and no personal profile | Your browser, when you visit the website |
We do not collect sensitive data on purpose. If one of your connected tools contains sensitive information, we only process it as part of the item it belongs to, to show it to you.
In short: mostly to provide the service you signed up for, plus security and legal obligations.
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Create and manage your account, sign you in | Performance of our contract with you |
| Sync your connected tools, show your notifications and tasks, perform the actions you ask for | Performance of our contract with you |
| Manage your subscription and payments | Performance of our contract with you |
| Keep invoices and accounting records | Legal obligation |
| Answer your support requests | Performance of our contract, or our legitimate interest in helping you |
| Send service emails: email verification, password reset, account lockout alert, sign-up attempt on an existing account | Performance of our contract, and our legitimate interest in securing your account |
| Protect the Service: rate limiting, lockout after failed logins, abuse prevention | Legitimate interest (security) |
| Detect and fix bugs and performance problems using logs and traces | Legitimate interest (keeping the Service working) |
| Measure website audience anonymously | Legitimate interest (improving the website) |
| Show your avatar (Gravatar) and product news (Headway) in the app | Legitimate interest (a more usable interface) |
We do not send marketing emails. If we ever want to, we will ask for your consent first.
We do not make automated decisions that have legal or similarly significant effects on you.
In short: we read what we need to fill your inbox, and we only change something in a tool when you ask us to.
When you connect a tool, you authorize Universal Inbox through that tool's own sign-in page. You can see and change the permissions there. Here is what each integration does:
| Tool | What we read | What we can do on your behalf |
|---|---|---|
| GitHub | Your notifications and the issues, pull requests, discussions and alerts they point to | Mark notifications as read, unsubscribe from threads |
| Linear | Your notifications and issues | Mark notifications as read or delete them, unsubscribe, complete or delete issues |
| Gmail | Email threads with the label you choose, your labels and profile | Add or remove labels (mark as read, archive) |
| Google Calendar | Event invitations | Answer invitations (accept, decline, maybe) |
| Google Drive | File comments and file metadata | Nothing: access is read-only |
| Slack | Messages, threads, channels, users, user groups, emoji and reactions related to the items you save | Add or remove reactions |
| Todoist | Your tasks and projects | Create, update, complete and delete tasks |
| TickTick | Your tasks and projects | Create, update, complete and delete tasks |
We act on a tool only when you trigger an action, or when a rule you set up asks us to.
Browser extension. The extension can send a web page to your inbox. Its "Slack bridge" feature uses your existing Slack session inside your own browser to talk to Slack; your Slack session token stays in your browser, and only your Slack workspace ID and user ID are sent to our servers.
Disconnecting a tool. When you disconnect a tool, we delete the access tokens we stored for it and ask the tool to revoke Universal Inbox's access. If that request fails (for example because the tool is unavailable), you can still revoke access yourself in the tool's settings, such as your Google account or GitHub settings. Items already imported stay in your account: notifications are hidden, and tasks are kept. They are deleted when you delete your account, or sooner if you ask us.
In short: data from Google is used only to provide the features you see, and never for ads or AI training.
Universal Inbox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, for data from Gmail, Google Calendar and Google Drive:
In short: if you connect an AI assistant, it sees what you ask it to see, under your own agreement with its provider.
You can let an AI assistant (such as Claude, ChatGPT, Gemini or Mistral) access your Universal Inbox through our MCP server, or create API keys for tools like the Raycast extension. When you do, the data that the assistant or tool requests is sent to it. What its provider does with that data is governed by your own agreement with that provider, not by this policy.
You can revoke an AI assistant or an API key at any time in your settings.
In short: only with the providers that help us run the Service, and never for advertising.
We use the following providers (called "processors"). They may only use your data to provide their service to us, under a data processing agreement.
| Provider | Purpose | Location |
|---|---|---|
| Koyeb (Mistral AI SAS) | Hosting of the application | European Union (Frankfurt, Germany) |
| Neon, Inc. | Database hosting | European Union region; US company |
| Scaleway SAS | Sending service emails | European Union (France) |
| Stripe Payments Europe, Ltd. | Payments and subscription management | Ireland; Stripe group worldwide |
| Crisp IM SAS | In-app support chat | European Union (France) |
| Hound Technology, Inc. (Honeycomb) | Performance traces for debugging (identified by an internal user ID only, with no email or IP address) | United States |
| Cloudflare, Inc. | Website hosting and delivery | Worldwide network; US company |
| Automattic, Inc. (Gravatar) | Showing your profile picture, based on a hash of your email address | United States |
| Headway | "What's new" widget in the app (receives your IP address when it loads) | Outside the EU |
Stripe also acts as an independent controller for the payment data it collects directly from you. See Stripe's privacy policy.
The tools you connect (section 4) receive the actions you ask us to perform. They are chosen by you and process data under their own terms.
We may also disclose data if the law requires it, for example to answer a valid request from a court or public authority. If Universal Inbox is ever sold or transferred, your data would move to the new operator, who would be bound by this policy; we would tell you beforehand.
We do not sell your personal data, and we do not share it with advertisers or data brokers.
In short: when a provider is outside the EU, we use the legal safeguards the GDPR requires.
Some providers listed above are based in, or can access data from, countries outside the European Economic Area, mainly the United States. In those cases, the transfer is covered by the provider's certification under the EU-U.S. Data Privacy Framework and/or by the European Commission's Standard Contractual Clauses. You can ask us for more information about these safeguards.
In short: as long as you have an account, then we delete it.
| Data | How long |
|---|---|
| Account and connected-tool data | As long as your account exists. Deleted as soon as you delete your account (or within 30 days if you ask us by email). |
| Payment event notifications from Stripe | 30 days |
| Backups | Deleted data disappears from backups within 30 days |
| Invoices and accounting records | 10 years, as required by French law (Code de commerce, art. L123-22). They stay with Stripe, unlinked from your deleted account. |
| Logs and traces | 60 days |
| Support conversations | 3 years after your last message |
In short: encryption, careful access, and we tell you if something goes wrong.
No system is perfectly secure. If a data breach is likely to put your rights at risk, we will notify the French data protection authority (CNIL) within 72 hours and inform you without undue delay, as the GDPR requires.
In short: we only use what the Service needs to work. No advertising or tracking cookies.
| Name / type | Set by | Purpose | Duration |
|---|---|---|---|
id cookie | Universal Inbox (app) | Keeps you signed in (strictly necessary) | 30 days |
| Local storage | Universal Inbox (app) | Remembers your settings, and completes sign-in with an external provider (strictly necessary) | Until you clear it |
| Chat cookies | Crisp (app) | Keeps your support conversation open across pages. Crisp loads only when you click Support in the app, never before and never on the sign-in or sign-up pages. | Set by Crisp |
When the app loads your avatar from Gravatar or the "What's new" widget from Headway, these providers receive your IP address and may set their own cookies.
The website www.universal-inbox.com uses a self-hosted, privacy-friendly analytics tool (Umami). It uses no cookies and does not build a profile of you.
Because we only use cookies that are needed for the Service to work, we do not show a consent banner. You can block or delete cookies in your browser settings, but you will not be able to stay signed in.
In short: it's your data. Ask and we'll help.
Under the GDPR you have the right to:
You can update your name and email in your account settings.
You can delete your account yourself from your Profile page ("Delete my account"). You confirm by typing your email address. We then cancel any paid subscription immediately, ask each connected tool to revoke our access, and delete your account and all its data. Invoices are kept for the legal retention period (section 9).
For anything else, including a copy or export of your data, email privacy@universal-inbox.com. We may ask you to confirm your identity. We answer within one month.
If you think we have not respected your rights, you can complain to the CNIL, the French data protection authority, or to the authority of the EU country where you live.
The Service is not intended for anyone under 15. We do not knowingly collect data from children under 15. If you believe a child has created an account, contact us and we will delete it.
If we make significant changes to this policy, we will tell you by email or in the app before they take effect. The date at the top of this page shows when it was last updated.