Privacy Policy
Effective Date: January 24, 2025
Welcome to Index Inbox ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our newsletter service at indexinbox.com (the "Service").
Please read this privacy policy carefully. By accessing or using our Service, you agree to this privacy policy. If you disagree with any part of this privacy policy, please do not access the Service.
Information We Collect
Information You Provide to Us
When you sign in with Google, we collect:
- Google Account Information: We access your basic profile (name, email address, and profile picture) through Google OAuth 2.0. We use the minimum required Google API scopes and do not access your Gmail, Drive, Calendar, or other Google services.
- Account Preferences: Newsletter preferences and subscription settings you configure.
- Payment Information: When you subscribe to our premium service, payment details are processed securely by Stripe. We do not store your credit card information.
Information Automatically Collected
When you access our Service, we automatically collect:
- Log Data: IP address, browser type and version, pages visited, time and date of visit, time spent on pages, and other diagnostic data.
- Device Information: Information about your device including device type, operating system, and browser information.
- Cookies: We use essential cookies for authentication and to maintain your session. You can control cookies through your browser settings.
How We Use Your Information
We use the information we collect to:
- Create and manage your account using Google authentication
- Provide, operate, and maintain our newsletter service
- Send you our weekly newsletter with curated content
- Process your subscription payments through Stripe
- Respond to your comments, questions, and customer service requests
- Send you technical notices, updates, security alerts, and support messages
- Understand and analyze how you use our Service to improve our offerings
- Detect, prevent, and address technical issues
- Comply with legal obligations
Important Note on Google Data: Information obtained from Google APIs will be used in compliance with the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not sell, rent, or share it with third parties for their marketing purposes.
Information Sharing and Disclosure
Sharing of Google User Data
We maintain strict controls over Google user data and only share it in limited circumstances:
- With Your Consent: When you explicitly authorize us to share your information
- Legal Compliance: When required by law, legal process, or government request
- Security and Fraud Prevention: To protect against fraud, abuse, or security threats
Service Providers
We work with trusted service providers who help us operate our Service. These partners are contractually obligated to protect your information:
- Supabase: Database hosting and user authentication
- Stripe: Secure payment processing (we never store your credit card details)
- ConvertKit: Email newsletter delivery (email addresses only)
- Vercel: Website hosting and content delivery
We only share the minimum information necessary for these providers to perform their services.
We Do Not Sell Your Information
We never sell, rent, or trade your personal information to third parties for marketing or commercial purposes.
Data Security
We implement industry-standard security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction.
Security Measures
- Encryption: All data is encrypted in transit and at rest using industry-standard protocols
- Access Controls: Strict access controls limit data access to authorized personnel only
- Monitoring: Continuous monitoring and logging of all system access and activities
- Security Audits: Regular security assessments and third-party audits
- Secure Infrastructure: Enterprise-grade hosting with advanced security features
Data Breach Response
In the unlikely event of a data breach affecting your personal information, we will notify you and relevant authorities within 72 hours as required by applicable law, and take immediate steps to secure our systems and protect your data.
Data Retention and Deletion
We retain your personal information only as long as necessary to provide our Service and fulfill the purposes described in this policy.
Retention Periods
- Active Accounts: Information is retained while your account is active
- Inactive Accounts: Accounts are automatically deleted after 2 years of inactivity
- Account Deletion: All personal data is deleted within 30 days of account deletion
- Legal Requirements: Some information may be retained longer when required by law
Deleting Your Data
You can request deletion of your personal data at any time:
- Use the "Delete Account" option in your profile settings
- Email us at admin@indexinbox.com
- We will process deletion requests within 48 hours
Cookies and Similar Technologies
We use cookies and similar technologies to provide and improve our Service. These technologies help us authenticate users, remember preferences, and analyze site usage. You can control cookie settings through your browser, though some features may not work properly if cookies are disabled.
Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information:
- Access: Request a copy of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Export your data in a portable format
- Opt-out: Unsubscribe from marketing communications
To exercise these rights, please contact us at admin@indexinbox.com.
Children's Privacy
Our Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes by email or through our Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Google API Services Compliance
Our use of Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements:
- Google user data is only used to provide or improve user-facing features
- We request only the minimum necessary permissions
- You can revoke our access to your Google account at any time
- We maintain transparency about how we use your Google data
- All Google data is protected with appropriate security measures
Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Email: admin@indexinbox.com
Service: Index Inbox
Website: https://indexinbox.com
We will respond to your inquiry within 48 hours.