This notice explains how InboxStackGPT handles your data. InboxStackGPT is a free service operated by EMAILTRUST Technologies Private Limited (“InboxStack”, “we”) that lets you read your Google Postmaster Tools data from AI assistants such as Claude and ChatGPT and from the InboxStackGPT browser extension. It supplements the InboxStack Privacy Policy, which applies to everything not covered here.
What we access from your Google account
When you connect InboxStackGPT, Google asks you to grant these permissions:
- Your email address and Google account ID (
openid,email), to identify your InboxStackGPT account. - Your Postmaster Tools domains (
postmaster.domain), to list the domains registered to your account, their verification state and your permission level. - Your Postmaster Tools traffic and compliance data (
postmaster.traffic.readonly), read-only, to read spam rate, authentication rates, encryption, delivery errors, feedback-loop data and Google’s sender compliance status for those domains.
InboxStackGPT does not request access to your Gmail messages, contacts, files or any other Google data. If you do not grant all of the Postmaster permissions, InboxStackGPT will not create an account.
How we use it
We use this data only to provide the features you ask for: answering your questions in Claude or ChatGPT, showing your domains in the browser extension, and alerting you in the extension when a domain’s status gets worse.
We do not sell your data, use it for advertising, or use it to train AI or machine-learning models.
Google API Services Limited Use
InboxStackGPT’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide and improve the user-facing features described above.
- We transfer it to others only as needed to provide those features (see “Who receives your data”), to comply with applicable law, or as part of a merger or acquisition with notice to you.
- No human at InboxStack reads your Google user data, except with your explicit consent for a specific support request, where needed for security (such as investigating abuse), to comply with law, or when the data has been aggregated and anonymized for internal operations.
What we store
| Data | Why | How |
|---|---|---|
| Google email address and account ID | Identify your account | Stored in our database |
| Google OAuth access and refresh tokens | Fetch Postmaster data when you ask, and once a day to record compliance status | Encrypted at rest (AES-256-GCM); never sent to Claude, ChatGPT or the extension |
| InboxStackGPT access and refresh tokens issued to Claude, ChatGPT or the extension | Authenticate those apps | Only a one-way hash is stored; access tokens expire after one hour |
| Postmaster responses | Fast repeat answers | Cached for up to 30 minutes, keyed to your account only |
| Daily compliance status for each of your domains: Google’s overall verdict and whether each sender requirement passed | Show how compliance changed over time, since Google only reports today’s status | Stored in our database, keyed to your account only; deleted after 13 months. Contains no traffic numbers or message content |
| Request log: which feature was used, which domain, whether it succeeded, and how long it took | Security, abuse prevention and reliability | Stored in our database; contains no Postmaster metrics |
The browser extension keeps your InboxStackGPT tokens, your settings and the last domain summary in your browser’s local extension storage.
Who receives your data
- The AI assistant you connect (for example Anthropic’s Claude or OpenAI’s ChatGPT) receives the answers to the questions you ask it. Their handling of that data is governed by their own privacy policies.
- Infrastructure providers that host InboxStackGPT’s servers and databases, under contract and only to run the service.
We do not share Google user data with anyone else.
Retention and deletion
- Disconnecting the connector in Claude or ChatGPT, or choosing Disconnect in the extension, revokes that app’s InboxStackGPT tokens.
- Revoking Google access at myaccount.google.com/permissions stops InboxStackGPT from reading any further Postmaster data immediately, including the daily compliance check.
- Deleting your account: email help@inboxstack.com from the Google address you connected. We delete your InboxStackGPT account, stored Google tokens, issued tokens, compliance history and request log within 30 days.
Cached Postmaster responses expire on their own within 30 minutes.
Security
All traffic uses HTTPS. Google tokens are encrypted at rest, and the tokens we issue are stored only as hashes. Every request is checked against the domains your own Google account can see before any Postmaster data is read.
Contact
Questions about this notice: help@inboxstack.com.
