Privacy Policy
Privacy Policy for Apex Inbox — how we collect, use, and protect your data.
Last updated: August 12, 2026
Apex Inbox ("we," "us," or "our") is operated by Apex Digital. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Information We Collect
Account information. When you sign in with Google, we receive your name, email address, and profile photo from Google's OAuth service. We do not receive your Google password.
Gmail access. With your explicit permission, Apex Inbox reads your Gmail messages to categorize them, generate summaries, and surface action items. We access only the inbox data necessary to provide the service. We do not sell, share, or use your email content to train AI models or for any purpose beyond delivering the features described on this page.
Usage data. We collect standard server logs (request timestamps, IP addresses, browser type) and in-app usage signals (which features you use, error events) to maintain and improve the service.
Follow-ups and notes. Any follow-up reminders or notes you create within Apex Inbox are stored in our database and associated with your account.
How We Use Your Information
- To authenticate you and maintain your session
- To read and classify your Gmail messages using Claude AI (Anthropic)
- To generate draft replies and email summaries on your request
- To send follow-up reminders you schedule
- To diagnose errors and improve the product
- To communicate product updates and support responses
Third-Party Services
Apex Inbox uses the following sub-processors:
| Service | Purpose |
|---|---|
| Google (Gmail API, OAuth) | Email access and authentication |
| Anthropic (Claude API) | AI categorization, summaries, and draft generation |
| Neon (PostgreSQL) | Database storage |
| Vercel | Hosting and infrastructure |
We do not sell your personal information to any third party.
Data Retention
Your account data is retained for as long as your account is active. You can request deletion of your account and all associated data at any time from the Settings page. Upon deletion, your data is removed from our database within 30 days.
Gmail OAuth Scopes
Apex Inbox requests the https://www.googleapis.com/auth/gmail.modify scope, which allows us to read your messages and send replies on your behalf. We do not delete messages, access Google Drive, or request any scope beyond what is required to provide the features listed above.
Security
We use HTTPS for all data in transit. Database credentials and OAuth tokens are stored as environment secrets and are never exposed in client-side code. Access to production systems is restricted to authorized personnel.
Your Rights
You may request access to, correction of, or deletion of your personal information at any time by emailing support@apexdigi.org. If you are located in the EU or California, you have additional rights under GDPR and CCPA respectively; contact us to exercise them.
Children's Privacy
Apex Inbox is not intended for users under 13 years of age. We do not knowingly collect information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised "Last updated" date. Continued use of the service after changes constitutes acceptance of the updated policy.
Contact
Questions about this policy? Email us at support@apexdigi.org.