InboxAPI

Privacy Policy

Last updated: September 10, 2026

This Privacy Policy describes what information InboxAPI collects and how it is used when you connect a Microsoft account and use InboxAPI to send email.

Information we collect

InboxAPI does not read, store, or have access to the contents of your inbox. Permissions requested during Microsoft sign-in are limited to your basic profile and sending mail.

How we use your information

Connected mailbox credentials are used solely to authenticate to Microsoft Graph and send email through your mailbox at your request. We do not sell or share your data with third parties.

Data retention and deletion

Disconnecting a mailbox, or removing all accounts, deletes the associated data from InboxAPI's database immediately. This does not revoke InboxAPI's consent on Microsoft's side you can remove that separately at myaccount.microsoft.com.

Security

Access to your account is protected by password authentication. Connected-mailbox tokens are stored server-side and are never exposed to other users.

Contact

Questions about this policy can be directed to the InboxAPI account owner.