InboxDutyLegal

Privacy notice

How InboxDuty handles personal data on this website and in the service. It covers the two roles we hold, the data we process, how long we keep it, who else is involved, and your rights.

Last updated 25 September 2026. Operated by SortX Software Ltd, company number 17132612, registered office 9 Lowood House, Bewley Street, London E1 0BT, trading as InboxDuty.

Who we are, and our two roles

InboxDuty is operated by SortX Software Ltd, company number 17132612, registered office 9 Lowood House, Bewley Street, London E1 0BT, trading as InboxDuty ("we", "us"). For the website and the relationship with the account holder, we are the controller. For the correspondence we process on a customer organisation's shared mailboxes, that organisation is the controller and we are its processor: we act only on its documented instructions.

Contact us at [email protected]. Report a security issue to [email protected].

Data we control on the website and account

When you visit the public site or sign in with your work identity, we process:

  • Your name and work email address, taken from the Google Workspace or Microsoft 365 work identity you sign in with.
  • Your organisation, your membership of it and your role.
  • Security data: the IP address and browser user agent of a request, used for rate limiting and abuse protection, and the sign-in attempt and session cookies described in the cookie statement.
  • Billing data: the opaque Stripe customer and subscription references, the plan quantity and Stripe's own status words. Card details and invoices live only on Stripe's hosted pages.

We use this to run and secure the service you have asked for (the contract), to meet our legal obligations (for example, tax), and for our legitimate interest in keeping the service safe and available. We do not send marketing, and we do not sell personal data.

Data we process for a customer organisation

When an organisation connects a shared mailbox, we process the following on its instructions. None of it is the content of a message.

  • The mailbox connection: the provider mailbox identifier, the scopes granted, the consent type and the polling cursor. The mailbox tokens themselves are held by self-hosted Nango, not by InboxDuty's database.
  • For each message judged: a keyed identifier derived from the provider's message id, the decision, the full weight distribution behind it, the confidence, the classifier and model version, counts of the categories of personal data that were removed, the statutory flags detected, and the times of receipt and processing.
  • Human corrections: the previous and new decision, the shape version and who made the change.
  • An audit trail of who changed access, statutory policy, shapes, mailbox connections, processing or billing, and when.

What we never store

  • Email bodies and attachments.
  • Message subjects and sender addresses.
  • The original text sent for judgement: personal data is replaced with typed placeholders before anything external sees it, and the message body is dropped after the decision is recorded.
  • Mailbox OAuth refresh tokens, which are held by self-hosted Nango rather than InboxDuty's database.

InboxDuty never stores email content. This is the product's central promise and is covered by tests. A message is read transiently, personal data is stripped before anything external judges it, and the durable record is a decision against a keyed identifier rather than the message.

How long we keep it

  • Decisions, weight distributions, corrections and the audit trail: kept while the organisation subscribes and for twelve months after it lapses. Access ends after that.
  • Organisation configuration (the organisation, its members, mailbox settings, classification shapes and rules): kept while the organisation exists. A lapse deletes nothing; the configuration is removed on offboarding, which is a separate decision (#59).
  • Onboarding interview transcripts: cleared as soon as the interview has produced a draft shape, and deleted with the draft when it is approved or discarded. A draft nobody has touched is purged after seven days.
  • Deletion on request: a record is deleted within 30 days of a written request to [email protected], once the customer organisation (as controller) has instructed it.
  • Billing records: kept for six years to meet tax and accounting obligations.
  • Server and application logs: kept for 30 days.
  • Encrypted backups: kept for 35 days, after which a deleted record is gone from every copy.
  • Website session data: held for the life of the sign-in session, then discarded when you sign out or it expires.

The automated job that enforces the twelve-month deletion (#59) is still being built. Until it ships, access ends at twelve months and deletion happens on request and on offboarding. The full schedule is in our retention policy.

Who else processes data

We use the following providers. Each receives only what its role requires.

  • Hostinger (shared zzapp VPS): Hosts the web and worker containers and the InboxDuty database, and a separate operator host holds encrypted backups.
  • Cloudflare: Terminates public TLS at its edge and provides DNS, caching and security controls. It sees request metadata, never message content.
  • Stripe: Payment processing, invoicing and subscription management. Card details and invoices are handled on Stripe's own hosted pages and never reach InboxDuty.
  • TypeSafe AI (api.typesafe.ai): The runtime classifier. It receives only the stripped text, never the original message, and returns typed weights.
  • OpenAI (GPT): Used only in the set-up conversation that helps a team describe its classification rules. It sees the team's own typed descriptions and examples, never mailbox correspondence.
  • Self-hosted Nango at nango.zzapp.uk: The operator's own infrastructure, not a third-party service. It performs the OAuth exchange and holds the mailbox refresh tokens.
  • Google Workspace and Microsoft 365: The customer's own mail providers. InboxDuty reads a shared mailbox through the provider's change feed and writes its decision back as the provider's own labels.

Signed data processing agreements with these providers, and the transfer safeguards described below, are not all in place yet. This notice will state them once they are. We will give customers notice before adding a new subprocessor.

International transfers

Several of the providers above are established in the United States, so using the service can involve a transfer of personal data outside the UK. Where a transfer needs a safeguard, for example the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, we will put it in place before live customer mail is processed. Those safeguards are not all in place yet, so this notice will name them once they are.

Your rights

Under the UK GDPR you have the right to be informed, to access your personal data, to have it rectified or erased, to restrict or object to its processing, and to data portability. Where we process data as a processor, we pass a request to the customer organisation that controls it and help them answer it.

To exercise a right, write to [email protected]. You also have the right to complain to the Information Commissioner's Office (ico.org.uk). We would rather hear from you first.

Cookies

We set only the cookies the service needs to sign you in. They are listed, with their purposes and lifetimes, in the cookie statement.

Changes

This notice reflects the service as built on 25 September 2026, and is dated any time it changes.