Privacy Policy

Last updated: June 15, 2026

1. Data Controller

InBoxIA(hereinafter, “we”, “the Platform”) is an AI-powered automated customer service SaaS platform, operated from Spain.

2. Data We Collect

2.1 Registration data

When creating an account on InBoxIA, we collect:

  • Full name, email address and password (encrypted with bcrypt)
  • Phone number (optional)
  • Preferred timezone
  • Profile picture (optional)

2.2 Business data

To configure your AI agents, we collect information that you voluntarily provide:

  • Business name, address, description and type of activity
  • Service and/or product catalog (names, prices, descriptions)
  • Opening hours and calendar configuration
  • Business logo and images

2.3 Knowledge base

To train your AI agents, you can voluntarily upload:

  • PDF documents, Excel files
  • Web page URLs for content extraction
  • Manually written frequently asked questions (FAQs)

This data is processed and stored in a vectorized format to allow real-time semantic search. Only your AI agent has access to your knowledge base.

2.4 Conversation data

InBoxIA acts as a data processor on behalf of the client, who is the data controller for the data of their end users.

When connecting your communication channels (WhatsApp, Instagram, Messenger), InBoxIA processes:

  • Sent and received text messages
  • Media files (photos, videos, audios, documents) shared in the conversations
  • Contact details of the customers who write to you (name, platform number/ID)
  • Conversation metadata (dates, statuses, tags)

2.5 Payment data

Payments are fully processed through Stripe. InBoxIA does not store credit card data or sensitive financial information. We only store the Stripe customer equivalent and subscription status.

2.6 Third-party connection data

When connecting external services, we store:

  • WhatsApp: Access token, phone number ID and WhatsApp Business account ID (Meta's WhatsApp Business Platform / Cloud API)
  • Instagram: Long-lived access token, username, account ID
  • Messenger: Page access token, page ID, page name
  • Google Calendar: OAuth access token for calendar synchronization

2.7 Social media data (Social Hub module)

When connecting social networks through the Social Hub module for content management and publishing, we store the following data depending on the platform:

  • YouTube: OAuth access and refresh tokens, channel ID, channel name, custom channel URL and profile thumbnail
  • TikTok: OAuth access tokens, user ID, profile name and basic account data required for publishing
  • Facebook (pages): Page access token, page ID, page name
  • LinkedIn: OAuth access tokens, profile or company page ID
  • X (Twitter): OAuth access tokens, account ID, username
  • Pinterest: OAuth access tokens, account ID
  • Reddit: OAuth access tokens, username
  • Threads: OAuth access tokens, user ID
  • Other platforms (Bluesky, Discord, Slack, Telegram, Mastodon, Twitch, Medium, Dev.to, Hashnode, WordPress, Dribbble, Lemmy, VK, Kick, Google My Business, Farcaster, Nostr, etc.): Access tokens or authentication credentials, account identifiers and profile names required for the connection

This data is used exclusively to authenticate your account on the corresponding platform and manage content publishing on your behalf. We do not access private messages, contacts or personal data of your followers through these Social Hub connections.

3. Purpose of Processing

We use your data to:

  • Provide the service: Manage your AI agents, process conversations, schedule appointments and offer platform functionalities
  • AI Processing: Your data is sent to OpenAI (GPT-4, Whisper, Vision) to generate intelligent responses, transcribe audios and analyze images, always within the context of your conversations
  • Service improvement: Analyze platform usage to improve features
  • Communications: Send you account-related emails (verification, plan changes, security alerts)
  • Billing: Manage your subscription and process payments through Stripe

4. Legal Basis for Processing

  • Performance of a contract: Processing is necessary to provide the service you have requested (Art. 6.1.b GDPR)
  • Consent: For the use of non-essential cookies and commercial communications (Art. 6.1.a GDPR)
  • Legitimate interest: For fraud prevention and platform security (Art. 6.1.f GDPR)

5. Data Sharing with Third Parties

InBoxIA shares data with the following service providers, exclusively to operate the platform and provide the features you request:

  • OpenAI (USA) — Natural language processing, image analysis and audio transcription. Data is sent under OpenAI's enterprise-grade API policy, which does not use the data to train their models. Google user data is never sent to OpenAI.
  • Groq (USA) — AI processing for the platform's internal support assistant. It does not use the data to train its models.
  • Stripe (USA) — Payment processing and subscription management
  • Meta Platforms (USA) — For integration with WhatsApp (WhatsApp Business Platform / Cloud API), Instagram, Messenger, Facebook Pages and Threads (official APIs)
  • Google (USA) — For Google Calendar synchronization and YouTube integration (YouTube API Services) and Google My Business, only with users who have explicitly granted the corresponding OAuth permissions
  • TikTok (ByteDance) (varies by region) — For content publishing on TikTok through the Social Hub module (official TikTok API)
  • LinkedIn (Microsoft) (USA) — For content publishing on LinkedIn through the Social Hub module (official API)
  • X Corp. (USA) — For content publishing on X (Twitter) through the Social Hub module (official API)
  • Pinterest (USA) — For pin publishing through the Social Hub module (official API)
  • Reddit (USA) — For content publishing through the Social Hub module (official API)
  • Other social media platforms — Discord, Telegram, Mastodon, Bluesky, Twitch, Medium, Dev.to, Hashnode, WordPress, Dribbble, Lemmy, VK, Kick, Slack, Farcaster, Nostr and others, based on the connections you voluntarily activate
  • PostHog (EU) — Product analytics to understand usage and improve the platform (instance hosted in the European Union).
  • Hetzner Online GmbH (Germany, EU) — Server hosting and infrastructure. The database is hosted on our own servers in encrypted form; we do not use a third-party managed database service.

International data transfers are carried out under the European Commission's Standard Contractual Clauses and/or the EU-US Data Privacy Framework.

We do not transfer or disclose your information to third parties for purposes other than the ones described in this policy. In particular, we do not sell, rent or otherwise share your data for advertising, marketing profiling, data brokerage, resale to information brokers, credit-worthiness evaluation, lending purposes, or targeted/personalized/retargeted advertising.

6. Google User Data

When you connect your Google account to use the Google Calendar integration, InBoxIA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6.1 What Google user data we access

  • Your Google account email address and profile name (to identify the connected account in our dashboard)
  • Google Calendar events, calendars and availability for the calendars you explicitly select (read/write access to create, update, delete and query appointments booked by your AI agent)
  • OAuth access and refresh tokens, stored encrypted at rest

6.2 How we use Google user data

Google user data is used solely to provide and improve the user-facing Calendar features you have activated: reading availability so the AI agent can offer time slots, and creating, modifying or cancelling events on your behalf during conversations with your customers.

6.3 Who we share Google user data with

InBoxIA does not share, transfer or disclose your Google user data to any third party, except:

  • With you and your end users — event details are shown in the InBoxIA dashboard and communicated to the customers you are chatting with, as part of the service you have configured.
  • Google itself — to perform the Calendar API calls you have authorized.
  • Infrastructure providers acting as data processors under strict confidentiality — Hetzner (EU, server hosting where we host our own encrypted database). This provider cannot access Google user data in a usable form and cannot use it for its own purposes.
  • When legally required — to comply with applicable law, regulation, legal process or enforceable governmental request.
  • With your explicit consent — for any other transfer, we will request your affirmative consent in advance.

6.4 Prohibited uses

In accordance with the Google API Services User Data Policy, InBoxIA explicitly does NOT:

  • Transfer Google user data to third parties for serving advertisements, including retargeted, personalized or interest-based advertising
  • Sell Google user data or share it with data brokers or information resellers
  • Use Google user data to determine credit-worthiness or for lending purposes
  • Use Google user data to train, fine-tune or evaluate generalized AI/ML models; the AI agent only reads the specific event information needed to respond to each customer conversation in real time, and this data is not retained for model training
  • Allow humans to read Google user data, unless we have obtained your affirmative consent for specific data, it is necessary for security purposes (e.g., investigating abuse), to comply with applicable law, or the data has been aggregated and anonymized and is used for internal operations

6.5 Revoking access and deletion

You can revoke InBoxIA's access to your Google account at any time from the integrations section of your dashboard or from your Google Account permissions page. Upon revocation, OAuth tokens are deleted from our systems within 7 days. You can also request deletion of all Google-derived data we hold by contacting agent@inbox-ia.com.

7. Social Media Data (Social Hub Module)

7.1 YouTube

When you connect your YouTube channel, InBoxIA uses the YouTube API Services. By doing so, you agree to be bound by the YouTube Terms of Service and the Google Privacy Policy.

We access: basic channel information (name, ID, thumbnail), the ability to upload and manage videos, and publication metadata. This data is used exclusively to manage content publishing on your behalf. We do not access your YouTube Analytics data, comments, subscribers or private channel information beyond what is necessary for publishing.

You can revoke access at any time from your Google Security Settings. Upon revocation, OAuth tokens are deleted within 7 days.

7.2 TikTok

When you connect your TikTok account, InBoxIA accesses your basic profile information and the ability to publish videos on your behalf. Data is obtained through the official TikTok API and is used exclusively for publishing functionality. InBoxIA does not access your TikTok private messages, follower lists or detailed analytics data. InBoxIA does not share your TikTok data with any third parties other than TikTok itself and the infrastructure providers listed in this policy. You can revoke access at any time from your TikTok account settings.

7.3 LinkedIn, X, Pinterest, Reddit, Threads and others

For each social network you connect to the Social Hub module, InBoxIA only accesses the basic profile data and publishing permissions necessary to manage content on your behalf. We apply the principle of least privilege: we only request the permissions strictly necessary for publishing functionality. We do not access private messages, contacts, follower lists or detailed analytics data from these platforms unless explicitly necessary for a feature that you activate.

For all connected platforms:

  • Access tokens are stored encrypted on our servers
  • Data is only shared with the corresponding platform and our infrastructure providers
  • You can disconnect any platform at any time from your Social Hub dashboard
  • Upon disconnection, tokens are deleted within 7 days
  • We do not use your social media data to train AI models, for advertising or for profiling

8. Data Retention

  • Account data: As long as you keep your account active and during the subsequent legal period
  • Conversations: As long as you keep your account active. Multimedia files are automatically deleted after 30 days
  • Payment data: According to applicable tax obligations (minimum 5 years)
  • Knowledge base: Until you manually delete it or cancel your account
  • Social media tokens (Social Hub): As long as you keep the connection active. Deleted within 7 days of disconnection or account cancellation
  • Scheduled content (Social Hub): Until publication or manual deletion. Drafts are retained while the account is active

9. Your Rights (GDPR)

As a user, you have the right to:

  • Access: Request a copy of the data we have about you
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request the deletion of your data (“right to be forgotten”)
  • Portability: Receive your data in a structured format
  • Object: Object to the processing of your data
  • Restriction: Request the restriction of processing

To exercise any of these rights, contact us at agent@inbox-ia.com. We will respond within a maximum of 30 days.

You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).

10. Security

We implement technical and organizational security measures to protect your data:

  • Passwords encrypted with bcrypt
  • Communications encrypted with HTTPS/TLS
  • Authentication via JWT tokens
  • Third-party tokens securely stored and automatically renewed
  • Fraud prevention system to detect misuse

11. Minors

InBoxIA is not directed to children under 16. We do not knowingly collect data from minors. If we discover that a minor has registered, we will delete their account and associated data.

12. Changes to this Policy

We reserve the right to update this privacy policy. We will notify you of any significant changes via the platform or by email. Continued use of the service after the changes implies acceptance of the updated policy.

13. Contact

For any inquiries regarding privacy or data protection, you can contact us at: