Last updated: September 10, 2026
This Privacy Policy describes what information InboxAPI collects and how it is used when you connect a Microsoft account and use InboxAPI to send email.
InboxAPI does not read, store, or have access to the contents of your inbox. Permissions requested during Microsoft sign-in are limited to your basic profile and sending mail.
Connected mailbox credentials are used solely to authenticate to Microsoft Graph and send email through your mailbox at your request. We do not sell or share your data with third parties.
Disconnecting a mailbox, or removing all accounts, deletes the associated data from InboxAPI's database immediately. This does not revoke InboxAPI's consent on Microsoft's side you can remove that separately at myaccount.microsoft.com.
Access to your account is protected by password authentication. Connected-mailbox tokens are stored server-side and are never exposed to other users.
Questions about this policy can be directed to the InboxAPI account owner.