Privacy Policy
Privacy Policy for Apex Inbox — how we collect, use, and protect your data.
Last updated: August 12, 2026
Apex Inbox ("we," "us," or "our") is operated by Apex Digital. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Information We Collect
Account information. When you sign in with Google, we receive your name, email address, and profile photo from Google's OAuth service. We do not receive your Google password.
Mailbox access. With your explicit permission, Apex Inbox reads connected mailbox messages to categorize them, generate summaries, and surface action items. Gmail connections may also use message-label actions and approved reply sending; Outlook connections may use read/write and send permissions for the same workflows. We access only the data necessary to provide the service. We do not sell, share, or use your email content to train AI models or for any purpose beyond delivering the features described on this page.
Usage data. We collect standard server logs (request timestamps, IP addresses, browser type) and in-app usage signals (which features you use, error events) to maintain and improve the service.
Follow-ups and notes. Any follow-up reminders or notes you create within Apex Inbox are stored in our database and associated with your account.
How We Use Your Information
- To authenticate you and maintain your session
- To read and classify connected mailbox messages using Claude AI (Anthropic)
- To generate draft replies and email summaries on your request
- To send follow-up reminders you schedule
- To diagnose errors and improve the product
- To communicate product updates and support responses
Third-Party Services
Apex Inbox uses the following sub-processors:
| Service | Purpose |
|---|---|
| Google (Gmail API, OAuth) | Email access and authentication |
| Anthropic (Claude API) | AI categorization, summaries, and draft generation |
| Neon (PostgreSQL) | Database storage |
| Vercel | Hosting and infrastructure |
We do not sell your personal information to any third party.
Data Retention
Your account data is retained for as long as your account is active. You can request deletion of your account and all associated data at any time from the Settings page. Upon deletion, your data is removed from our database within 30 days.
Gmail OAuth Scopes
Apex Inbox requests the https://www.googleapis.com/auth/gmail.modify scope, which allows us to read your messages and send replies on your behalf. We do not delete messages, access Google Drive, or request any scope beyond what is required to provide the features listed above.
Security
We use HTTPS for all data in transit. Database credentials are stored as environment secrets. Your OAuth access tokens are stored encrypted in our database and are never exposed in client-side code. Access to production systems is restricted to authorized personnel.
Your Rights
You may request access to, correction of, or deletion of your personal information at any time by emailing support@apexdigi.org. If you are located in the EU or California, you have additional rights under GDPR and CCPA respectively; contact us to exercise them.
Children's Privacy
Apex Inbox is intended for users who are at least 18 years of age, consistent with our Terms of Service. We do not knowingly collect information from anyone under 18.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised "Last updated" date. Continued use of the service after changes constitutes acceptance of the updated policy.
Contact
Questions about this policy? Email us at support@apexdigi.org.