Launch pricing is live — $25/mo (reg. $45) · $199/yr (reg. $399).Launch pricing — $25/mo · $199/yr

Grab it
InboxJoy
FeaturesHow it worksPricingQuestionsLog in
Start free trial
← Back to home

Privacy Policy

Last updated October 8, 2026

This policy summarizes how the service works. It is not legal advice.

1. Who we are

InboxJoy is a service for creating and sending email sequences through mailboxes you connect. In this policy, “InboxJoy,” “we,” and “us” refer to InboxJoy.

Questions, privacy requests, and recipient suppression requests can be sent to hey@inboxjoy.online.

2. When we are controller and when we are processor

We are the controller of personal data we collect to create and administer your InboxJoy account, bill your workspace, secure the service, provide support, and operate our website.

You control the leads, contacts, message content, and campaign data that you or your team upload or send through InboxJoy. For that customer data, you are the controller and InboxJoy is your processor or service provider. You decide whom to contact, why you may contact them, what to say, and how long to keep their data.

If you use InboxJoy for another organization, that organization is the customer and controller. You must have authority to give us instructions on its behalf.

3. What we collect

Account and team data

We store your name, email address, verification state, optional profile image, password credential in protected form, acceptance date and version for the terms, and account and session timestamps. A workspace has a name, slug, status, time zone, sending limits, optional postal address, and an emergency sending switch. Team records include member roles and status, join dates, and pending invitation email addresses.

Connected mailbox data

For a Gmail, Google Workspace, or Outlook mailbox, we store the provider, mailbox address and display name, a Composio connected-account reference, connection status, time zone, sending schedule and limits, warm-up state, health data, and provider message or thread identifiers. InboxJoy does not store the Google or Microsoft OAuth token for these mailbox connections.

Customer-uploaded data and content

You can add contacts through CSV, the REST API, MCP, or the product interface. Contact fields can include email address, first and last name, company, title, website, phone, location, LinkedIn URL, source, a lawful-basis note, and custom fields. We also store lists, import records, campaigns, sequence descriptions, subjects, message bodies, personalization variables, schedules, and delivery records.

Engagement and delivery data

We record send attempts and events such as acceptance, opens, replies, automatic replies, bounces, complaints, and unsubscribes. Provider webhooks can contain sender and recipient details, message headers or content, and delivery diagnostics. We use these events to stop follow-ups, show campaign results, protect sender reputation, and add recipients to suppression lists.

Billing data

Dodo Payments handles checkout and card processing. We receive and store customer and subscription references, plan, subscription status, trial and billing dates, cancellation state, product reference, and payment webhook status. We do not receive or store full card numbers.

Technical and service data

We process session information, IP addresses and user agents used for authentication and security, API-key and OAuth grant activity, audit records, request and error logs, feature usage, and support communications. API keys, invitation tokens, and MCP tokens are stored as hashes.

Product analytics and session replay

We record product sessions inside the InboxJoy app for debugging and product improvement. Inputs and contact data are masked before they leave your browser. This recording does not apply to recipients of customer campaigns.

4. How we use data and our lawful bases

  • Contract. We use account, workspace, mailbox, contact, message, usage, and billing data to provide the service you request, authenticate users, send messages, detect replies, process subscriptions, and provide support. This is GDPR Article 6(1)(b) where it applies.
  • Legitimate interests. We use limited account, usage, delivery, and security data to prevent abuse, enforce sending limits, troubleshoot failures, maintain suppression controls, improve reliability, and protect InboxJoy, customers, mailbox providers, and recipients. This is GDPR Article 6(1)(f) where it applies.
  • Consent. We rely on consent where applicable law requires it, including for optional tracking or communications that cannot rely on another basis. You may withdraw consent without affecting earlier processing.
  • Legal obligations. We may retain or disclose records when needed to comply with tax, accounting, court, or regulatory requirements. This is GDPR Article 6(1)(c) where it applies.

When we process customer-controlled contact and campaign data as a processor, the customer determines the lawful basis. InboxJoy does not sell personal data or use customer contact lists for advertising.

5. Mailbox access

You connect Gmail or Outlook through Composio OAuth. The connection gives InboxJoy, through Composio, the provider access needed to identify the mailbox, send your campaign messages, subscribe to incoming-message events, search for replies, and inspect limited sent-message metadata when delivery is uncertain.

We use mailbox access to deliver campaigns, keep message threads together, confirm whether a send succeeded, and detect replies, bounces, complaints, and expired connections. We do not use mailbox data for advertising or sell it. We do not routinely copy or index your unrelated mailbox. Automated reply searches and inbound provider events can still access relevant message metadata or content, and the webhook payload received from the provider is stored as an operational record.

Composio holds the provider authorization. InboxJoy stores the connected-account reference. You can stop InboxJoy from sending through a mailbox by disconnecting it, and you can revoke the underlying authorization through Google, Microsoft, or Composio.

6. AI drafting

If you ask InboxJoy to draft a sequence, we send your campaign description, requested tone, and step count to Azure OpenAI. If you ask it to refine a step, we send that subject, body, action, and any custom instruction. Azure OpenAI returns generated content to InboxJoy. Do not place personal data or confidential information in an AI prompt unless you are authorized to have it processed for that purpose.

7. Open tracking and suppression

When open tracking is present, a small image request can record an open event. For each recorded open, InboxJoy stores the event time and message association, the first 300 characters of the user agent, a bot classification and reason where applicable, and a salted SHA-256 hash of the IP address. The raw IP is used transiently to make that hash and is not retained in raw form as part of the open event.

Mail privacy tools, proxies, and security scanners can trigger the image, so an open is not proof that a person read a message. We classify known proxies, scanners, missing user agents, and immediate prefetches as automated where our rules detect them.

Unsubscribe, permanent-bounce, complaint, block, and manual suppression records prevent later enrollment and sending. An unsubscribe record may include a user agent and hashed IP. We do not use tracking to build advertising profiles.

8. Service providers and subprocessors

We disclose only the data each provider needs for its role. Current providers are:

ProviderPurposeRegion
Microsoft AzureApplication hosting, PostgreSQL database, backups, monitoring, and Key Vault secretsNorth Central US for the primary production infrastructure
Azure Communication ServicesAccount, billing, service, and campaign test emailsEurope, based on the configured service endpoint
Azure OpenAIOptional sequence drafting and message refinement using content you submitThe region assigned to our configured Azure OpenAI resource
ComposioGmail and Outlook OAuth connections, sending, provider actions, and inbound event deliveryProvider-managed infrastructure; no fixed region is set in InboxJoy code
Dodo PaymentsCheckout, card processing, subscription management, and billing webhooksProvider-managed infrastructure; no fixed region is set in InboxJoy code
PostHogSession replay and error trackingThe configured PostHog cloud region
PiqoWebsite and product usage analytics: page views, clicks on public pages, and conversion eventsProvider-managed infrastructure; no fixed region is set in InboxJoy code
GhostPublic blog software on a separate, self-hosted Azure instance; it does not receive workspace dataNorth Central US

Google or Microsoft also process data under the mailbox account you choose to connect. They provide your email service rather than acting only on InboxJoy's instructions.

9. International transfers

Your data may be processed outside your state, province, or country. Our primary production infrastructure and separate Ghost blog instance are in North Central US. The configured Azure Communication Services endpoint is in Europe. Other provider locations are controlled by those providers and are not fixed in the application code.

Where transfer law applies, we use an available lawful transfer mechanism, such as an adequacy decision, contractual safeguards, or the provider's approved transfer terms. Contact us if you need information about the mechanism relevant to your data.

10. Retention

  • Account data. We keep it while your account is open and for up to 30 days after a closure request to finish support, security, and billing work, unless law requires longer retention.
  • Workspace and customer data. Contacts, messages, campaigns, imports, connected-mailbox references, provider webhook records, and engagement events are kept for the life of the workspace unless you delete them sooner. We do not currently apply a shorter fixed period to engagement events. Using the workspace deletion control removes live workspace-owned data.
  • Suppression data. We keep suppression entries for the life of the workspace and ordinarily indefinitely within it. Deleting an unsubscribe or complaint entry could allow the same person to be contacted again.
  • Short-lived credentials. Sessions, verification links, connection state, and OAuth codes expire according to their configured lifetime. Revoked key and grant records may remain as security records.
  • Backups. Deleted data may remain in protected database backups until the backup cycle expires. The current PostgreSQL point-in-time recovery window is 14 days.
  • Legal records. We may keep billing, fraud, dispute, and compliance records for the period required by law or needed to establish legal claims.

Canceling a subscription is not the same as deleting a workspace. Contact us or use the workspace deletion control when you want workspace data removed.

11. Security

InboxJoy uses HTTPS encryption in transit. Production database traffic stays on a private Azure network. Deployment secrets are kept in Azure Key Vault and read through managed identity. Provider tokens for connected Gmail and Outlook mailboxes remain with Composio. Application access is tied to authenticated users, workspace memberships, roles, and workspace-scoped database queries. API keys, invitation tokens, and MCP tokens are stored as hashes.

No system is perfectly secure. You must protect your password, connected accounts, API keys, and authorized MCP clients, and tell us promptly if you suspect unauthorized access.

12. Your privacy rights

Depending on where you live, you may ask to access, correct, erase, restrict, or receive a portable copy of your personal data. You may object to processing based on legitimate interests and withdraw consent where consent applies. You may also complain to your local data protection authority.

Email hey@inboxjoy.online to exercise a right. Tell us the account or email address involved. We may need to verify your identity. We will respond within 30 days, or within another period required by applicable law. We will tell you if a lawful extension or exception applies.

For customer-controlled contact or campaign data, we normally refer your request to the customer that uploaded it and help that customer respond as its processor.

13. If you received a customer's email

The InboxJoy customer that contacted you controls your contact data and message. Use the unsubscribe link in the email to stop future campaign messages from that customer. You can also contact the sender or email hey@inboxjoy.online and ask us to help place your address on that customer's suppression list.

A suppression request stops future InboxJoy campaign sends for that workspace. It does not control messages the sender sends outside InboxJoy.

14. Children

InboxJoy is a business service and is not directed to children under 18. Do not create an account for a child or upload children's personal data. If you believe a child's data was provided to us, contact us so we can review and remove it.

15. Changes to this policy

We may update this policy when the service, our providers, or the law changes. We will change the “Last updated” date and provide additional notice for a material change when appropriate. Your continued use after the effective date is subject to the updated policy.

© 2026 InboxJoyPrivacyTerms