1. Overview
This Privacy Policy applies to the Tame Inbox website (tameinbox.com), web app (app.tameinbox.com), mobile apps, and related services (together, the “Service”). The Service is operated by Evigasoft Canada Inc. (“Tame Inbox,” “we,” “us”), a Canadian corporation with its registered office in Alberta, Canada. Your use of the Service is also governed by our Terms of Service.
Tame Inbox helps you manage your own email: it connects to the mailboxes you choose, shows and organizes your messages, and — when you ask it to — uses AI to sort mail, summarize it, translate it, draft replies, and unsubscribe you from senders you no longer want to hear from. We collect only what these features need, and every feature that touches your mail runs at your direction.
2. Information we collect
Account information
You sign in with Google, Apple, Microsoft, or Yahoo. From your chosen provider we receive your name, email address, and account identifier. We never see your provider password. Tame Inbox does not use its own passwords.
Connected mailboxes
When you connect a mailbox (Gmail, Outlook, or Yahoo Mail), we store the OAuth access and refresh tokens the provider issues — encrypted at rest — so the Service can access that mailbox on your behalf. For Yahoo accounts connected with an app password instead of OAuth, the app password is stored encrypted at rest. Disconnecting a mailbox deletes its stored credentials.
Email data
When you use the app, we fetch messages from your connected mailbox on demand — headers, sender and recipient details, subjects, and message bodies — and process them transiently to display and organize your inbox. We do not maintain a server-side copy of your mailbox, and we do not scan or index your mail in the background. The only mail-derived data we store is the minimum needed for actions you queue (see Section 7) and preferences you save (for example, how a sender should be categorized).
Shared tasks
If you use shared task groups, we store the tasks you create and share, group membership, and invite codes so members of your group can see the tasks you choose to share with them.
Billing information
If you buy AI credits, we store your credit balance and purchase ledger, plus the transaction identifiers reported by Google Play, the Apple App Store, or Stripe. Payment-card numbers are handled entirely by those providers and never reach our servers.
Technical information
Like most online services, our infrastructure processes basic technical data — such as IP address, device type, and request timestamps — to deliver the Service, prevent abuse, and diagnose failures. We record AI usage metrics (token counts and costs, not message content) to meter credits. Tame Inbox does not use advertising trackers or third-party behavioural analytics.
3. How we use information
We use personal information to:
- sign you in and operate your account;
- display, organize, search, and send email in the mailboxes you connect, at your direction;
- provide the AI features you invoke — sorting, summaries, translation, and reply drafts;
- carry out cleanup actions you queue, such as unsubscribing from senders;
- operate shared task groups you join;
- meter, process, and administer AI-credit purchases;
- protect the Service, prevent abuse, and keep it reliable; and
- comply with applicable law and respond to valid legal requests.
We do not sell personal information, we do not use your email data for advertising of any kind, and we do not use it to determine creditworthiness or for lending purposes.
4. Google user data
If you connect a Gmail mailbox, Tame Inbox accesses Gmail data through Google’s APIs with the scopes you approve on Google’s consent screen. Specifically:
- Access: we read message headers, subjects, and bodies, and message flags/labels, on demand when you use the app;
- Use: Gmail data is used only to provide user-facing features you see in the app — your inbox view, AI sorting, summaries, translation, reply drafts, search, and the cleanup actions you queue. We do not use Gmail data for advertising, and no human reads it except with your explicit consent, for security purposes, or to comply with law;
- Storage: we do not persistently store Gmail message content. We store only your encrypted OAuth tokens, saved preferences, and the minimal metadata of actions you queue (Section 7);
- Sharing: when you invoke an AI feature, the relevant message subject and body are sent to Anthropic (our AI provider) to generate the result, as described in Section 6. We share Gmail data with no other third party.
Tame Inbox’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Microsoft and Yahoo data
The same practices apply to Outlook and Yahoo mailboxes: message data is fetched on demand, processed transiently to provide the features described above, and not persistently stored. For Yahoo mailboxes, we do not retain Yahoo user data beyond transient processing — well within the 24-hour retention limit in Yahoo’s developer terms — other than your encrypted credentials and the minimal action metadata described in Section 7. Email content from any provider is sent to a third party only as described in Section 6, and only when you use the feature that requires it.
6. AI-powered features
Tame Inbox uses Anthropic’s Claude models for the AI features in the app: sorting and prioritizing messages, summaries, translation, and reply drafts. These features run when you use them (or when you have turned on AI sorting for your inbox), and each sends Anthropic only the content it needs — typically the subject and body text of the messages being processed, and your saved preferences (such as your preferred language).
We use Anthropic’s commercial API, under which Anthropic acts as a data processor: Anthropic does not train its models on this content, and automatically deletes API inputs and outputs from its systems within 30 days, except where longer retention is required for trust and safety or by law. We ask for your permission before enabling AI features, and you can stop using them at any time. AI output can be incomplete or wrong — review it before relying on it or sending anything.
7. Automated cleanup and unsubscribe
When you ask Tame Inbox to unsubscribe you from a sender, we act on your instruction: we contact the sender’s advertised unsubscribe endpoint (using the one-click standard where the sender supports it, or the sender’s unsubscribe link), or — where the sender only offers an email address — send an unsubscribe request from your own mailbox on your behalf. To run these actions, we store the minimal details needed until they complete — the sender, its domain, and the unsubscribe link from the message you selected — plus a history of completed actions so you can see what was done.
Whether an unsubscribe request is honored depends on the sender, not on us; Section 4 of the Terms of Service explains this in more detail.
9. Storage and retention
Account records, encrypted mailbox credentials, preferences, cleanup history, shared tasks, and the credit ledger are stored in our database, hosted on our own infrastructure. Mailbox content is not stored server-side; some messages you have viewed may be cached on your own device so the app works smoothly.
We retain your information while your account is active. Disconnecting a mailbox deletes its credentials immediately. When you delete your account (see our account deletion page), your account records, credentials, preferences, cleanup history, and shared content are permanently deleted from our database; purchase records held by Stripe, Google, or Apple are retained by those providers as required for financial and tax purposes, and residual copies may persist briefly in encrypted backups before they cycle out.
10. Your choices and privacy rights
You can disconnect mailboxes, edit preferences, leave shared groups, and delete your entire account directly in the app. You may also contact us to:
- ask what personal information we hold about you and how it has been used or disclosed;
- access, correct, or receive a portable copy of your personal information;
- delete your account and associated information, subject to legal exceptions;
- withdraw consent for optional processing, including the AI features; or
- raise a privacy question, concern, or complaint.
We respond to requests at [email protected] and may need to verify your identity first. Depending on where you live, these rights are backed by law — including PIPEDA and provincial privacy laws in Canada (including Quebec’s Law 25), the GDPR in Europe and the UK GDPR (where our legal bases are performance of our contract with you, your consent for optional features such as AI processing, and our legitimate interests in securing and improving the Service), and state privacy laws in the United States such as the CCPA/CPRA. We do not sell or “share” personal information as those terms are defined in the CCPA, and we do not process it for targeted advertising. You may also complain to your local privacy regulator, such as the Office of the Privacy Commissioner of Canada or your EU data-protection authority.
Signing out does not delete server-side account data, and uninstalling the app only removes local data from that device. To close your account entirely, use “Delete account” in Settings or see the account deletion page.
11. International transfers
We are a Canadian company and our servers are located in Canada. Some of our service providers — including Anthropic, Google, Apple, Microsoft, Yahoo, Stripe, and Cloudflare — process data in the United States and other countries. Personal information processed outside your province, state, or country may be subject to local law and lawful access by courts and authorities in those jurisdictions. Where required, we rely on appropriate safeguards for these transfers, such as contractual data-protection commitments.
12. Children
The Service is not directed at children, and we do not knowingly collect personal information from children under 13. If you believe a child has created an account, contact [email protected] and we will delete it.
13. Security and incident response
We protect personal information with administrative, technical, and organizational measures, including encrypted network transport (TLS), encryption at rest for mailbox credentials, authenticated access with short-lived sessions, and access controls that keep each account’s records separate. No storage or transmission method is completely secure, so keep your devices and provider accounts safe and contact us promptly if you believe your account has been compromised.
If a privacy incident creates a real risk of significant harm, we will investigate and provide notices or reports as required by applicable law.
14. Changes and contact
We may update this policy as the Service or legal requirements change. We will post the revised version here, update the date above, and provide additional notice when a change is material.
Questions, requests, or complaints may be sent to our Privacy Officer at [email protected], or by mail to Evigasoft Canada Inc., Alberta, Canada.