Privacy Policy
Effective September 23, 2026
Embox is an email client that shows the mail you already have, from providers like Gmail, iCloud, Fastmail and Yahoo, in one calm, keyboard-first inbox. Embox is operated by Vogel (“we”, “us”). This policy explains what we collect, why, and the choices you have.
What we collect
- Your Embox account. Your name, email address and a salted hash of your password, or, if you sign in with Google, your name, email address and Google account identifier.
- Connected mail accounts. The access tokens (for Gmail) or app passwords and API keys (for other providers) you give us so Embox can reach your mailbox. These are encrypted before they are stored.
- Your mail. Messages and their metadata (senders, recipients, subjects, dates, read and archive state, attachments you open) that Embox syncs from your connected accounts so it can show and organize them.
- Settings. Preferences such as theme, density and which beacons you want, stored in your browser.
- Operational data. Your IP address and basic request information, used for security and rate limiting, and error codes that never contain the content of your mail.
How we use it
We use your information only to provide and improve the features you use in Embox: showing, searching and organizing your mail, surfacing actionable items (such as a sign-in code or a meeting link) as “beacons”, keeping read and archive state in sync, and sending mail when you ask us to. We do not use your mail for advertising, and we do not sell your information.
Google user data
If you connect a Gmail account, Embox requests access to read, modify (for example, marking messages read or archiving them) and send email on your behalf. We use this access only to provide Embox’s user-facing email features.
Embox’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We do not use Gmail data for advertising, and we do not sell it or transfer it to data brokers or information resellers.
- We do not use Gmail data to train generalized artificial intelligence or machine learning models.
- People do not read your Gmail data unless you give us explicit permission for specific messages (for example, to help with a support request), it is necessary for security purposes such as investigating abuse, or it is required to comply with the law.
- We only transfer Gmail data to others when it is necessary to provide Embox’s features (for example, to our hosting provider), to comply with the law, or as part of a merger or acquisition with notice to you.
Sharing
We share information only with service providers that run Embox for us, such as our hosting provider, under agreements that restrict their use of it; when required by law or to protect the rights and safety of our users; or as part of a business transfer, with notice to you. We never sell your information.
Storage and security
Your data is stored on servers operated by our hosting provider. Mail provider credentials are encrypted with AES-256-GCM, all connections to Embox and to mail providers use TLS with certificate verification, and access to production systems is restricted. No system is perfectly secure, but we work to protect your information and will notify you of a breach as required by law.
Retention and deletion
- When you remove a mail account in Embox, we immediately delete its stored credentials and stop syncing it.
- To delete all mail Embox has stored for you, or your Embox account entirely, email ryan@vogel.dev. We will delete it within 30 days, except where we must keep something to comply with the law.
- You can revoke Embox’s access to your Google account at any time from your Google Account permissions.
Children
Embox is not directed to children under 13, and we do not knowingly collect information from them.
Changes
If we change this policy, we will update the date above, and for significant changes we will let you know in Embox or by email before they take effect.
Contact
Questions or requests about your privacy: ryan@vogel.dev.