Zero-knowledge architecture

We never store your emails.

Inbox Revenue AI reads your inbox only while a scan is running. Message content lives in memory for a few seconds, gets reduced to structured opportunities, and is then discarded. This page is maintained by the Inbox Revenue AI team to explain how the product handles your data — it is not an independent certification.

How a scan works

  1. 1. You authorize read-only Gmail access. You can revoke it at any time.
  2. 2. Recent messages are fetched into server memory for a single request.
  3. 3. A modular analysis engine — cloud, local, or hybrid — extracts structured signals such as merchant, value and expiry.
  4. 4. Only that structured result is saved. The raw text is dropped.

What we store

  • Account ID and email address

    Needed to sign you in and bill your plan.

  • Gmail OAuth token

    Encrypted at rest with AES-256-GCM and readable only by our server.

  • Detected opportunities

    Merchant, opportunity type, estimated value, expiry date and a confidence score.

  • Scan metadata

    Counts and timing of scans, used for limits and reliability.

What we never store

  • Email bodies or HTML
  • Subjects or thread history
  • Attachments
  • Contact lists
  • Anything sent to another person

Access and control

  • We never permanently store your emails.
  • Your inbox is analyzed only to find savings.
  • Administrators cannot read your inbox.
  • Email content is discarded after processing.
  • You may revoke Gmail access at any time.

Every opportunity record is scoped to your account with row-level security. Administrators of Inbox Revenue AI see aggregate counts only. You can delete all detected opportunities, or disconnect Gmail entirely, from inside the app.

Roadmap: local-only analysis

Our analysis engine is modular by design. A fully on-device mode is in development so that message text never leaves your machine at all.

Questions about privacy or a security report? Reach us through the in-app support link in Settings.