Privacy policy
Last updated October 2, 2026inbox MCP lets your AI apps use your LinkedIn, Instagram, Telegram and WhatsApp accounts safely. This policy explains what personal data we handle to do that, why, and the choices you have. In short: we keep as little as we can, we never store your passwords or inboxes, and we never sell your data.
1. What we collect
We collect only what we need to run inbox MCP:
- Account details: your email address and name, and the sessions you sign in with (including the IP address and browser of each session).
- Workspace details: workspace name and icon, members, roles and the email addresses you invite.
- Connected accounts: for each LinkedIn, Instagram, Telegram or WhatsApp account you connect, which app it is, its identifier, its name, its public profile handle or phone number when the app provides one, whether a LinkedIn account has Premium, and its connection status.
- Connected apps and keys: the AI apps you authorize, the permissions you grant them, and API keys (stored only as a one-way hash).
- Usage: daily counts of actions per connected account (for example, messages sent, profile views or invitations sent), used to enforce limits and shown in your dashboard.
- Billing: if you subscribe, your Stripe customer and subscription status. Card details go directly to Stripe; we never see or store them.
- Technical logs: request logs (IP address, time, path, errors) kept by our hosting provider to keep the service secure and working.
- Approximate city on our homepage: our hosting provider estimates your city from your IP address, and the homepage uses it to personalise its examples. It is used only while the page loads; we don't store it or link it to you.
2. Your LinkedIn, Instagram, Telegram and WhatsApp data
You can connect accounts from LinkedIn (Microsoft), Instagram and WhatsApp (Meta) and Telegram. You sign in on our connect page: with your password and any verification code for LinkedIn and Instagram, or by scanning a QR code or entering a pairing code with your phone for WhatsApp and Telegram. These are sent over an encrypted connection to our provider Unipile, which holds the connection and accesses the account on your behalf. We do not store your passwords.
Messages and conversations, and on LinkedIn also profiles, posts, invitations and search results, are fetched through Unipile from the app when you or your AI app ask for them, and returned to the app that asked. We do not keep a copy of your inboxes or of the profiles you view. Messages you schedule for later are held only until they are sent or cancelled, together with the result of each send.
When you disconnect an account, we stop using it and ask Unipile to remove the connection. We do not sell data from your connected accounts, and we do not use it to train AI models.
3. How we use it
- To sign you in, run your workspace and carry out the actions you or your authorized apps request.
- To pace those actions and keep each connected account within safe daily limits.
- To send service emails: sign-in links, invitations, trial and billing notices. We don't send marketing emails without your consent.
- To bill you, prevent abuse (for example, repeated free trials) and keep the service secure.
- To comply with legal obligations.
4. Legal bases
If you are in the European Economic Area or the United Kingdom, we process your data to perform our contract with you (running the service you signed up for), for our legitimate interests (security, abuse prevention, improving reliability), to meet legal obligations (tax and accounting records), and, where we ask for it, with your consent, which you can withdraw at any time. Our processing is subject to the GDPR and the French Data Protection Act (Law No. 78-17 of 6 January 1978, as amended).
6. AI apps you connect
When you connect an AI app (such as Claude, ChatGPT or Cursor), the data it requests from your connected accounts (for example messages or profiles) is sent to that app. How that app stores and uses the data is governed by its own terms and privacy policy, not this one. You choose what each app may do and can revoke its access at any time from the Connected apps page.
7. How long we keep it
- Account and workspace data: for as long as your account exists.
- Unfinished account connections: deleted after 24 hours.
- Daily usage counts: about 13 months.
- Webhook delivery records: 30 days.
- Connected accounts on an ended trial or subscription: released after 12 hours without payment.
- Invoices and accounting records: 10 years from the end of the financial year, as French law requires.
9. Security
All traffic is encrypted in transit. API keys are stored as hashes, access tokens are short-lived and scoped to the permissions you grant, and sending actions are off until you allow them. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires.
10. Your rights
You can access, correct, export or delete your personal data, object to or restrict its processing, and withdraw consent. Many of these you can do yourself in the dashboard: disconnect accounts, revoke apps, delete API keys or delete a workspace. For anything else, email support@inbox-mcp.com and we will answer within one month (extendable by two months for complex requests, in which case we'll tell you why).
If you are in the EEA or UK, you can also complain to your data protection authority (in France, the CNIL). California residents have similar rights to know, delete and correct their data; we do not sell or share personal information for cross-context behavioral advertising.
11. International transfers
Some of our providers process data outside your country, including in the United States. Where data leaves the EEA or UK, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses.
12. Children
inbox MCP is for professionals and is not intended for anyone under 18. We do not knowingly collect data from children.
13. Changes
We may update this policy as the service changes. We will post the new version here with a new date, and tell you by email before any significant change takes effect.
14. Contact
inbox MCP is operated by Logike SAS, SIRET 90230339500021, 128 rue de la Boétie, 75008 Paris, France. Logike SAS is the controller of your personal data. Questions or requests: support@inbox-mcp.com.