This policy covers the planned Inbxer cloud service and this website. If you self-host Inbxer, none of your customer data reaches me — you are the controller and this policy does not apply to that deployment.
Inbxer is an open-source project built and operated by one person — Abdelmjid. For the cloud service I act as a processor of your customer data and a controller of your own account data. Reach me at hello@inbxer.com.
Two categories, and I treat them differently.
Account data runs your subscription and lets me reach you about incidents, security notices and releases. Customer data is used only to deliver the features you enable — routing, search, automation and reporting.
I don't sell data, I don't share it with advertisers, and I don't use your customer data to train shared machine-learning models. Where you enable AI drafting, the request goes to the model provider you select and isn't retained for training.
For account data, the contract between us is the basis. For telemetry and analytics, it's a legitimate interest in keeping the service reliable, balanced against a design that avoids identifying individuals. Where consent is required, I ask for it, and you can withdraw it any time.
The list stays short, and it's public. Material changes get announced 30 days before they take effect, and you can object.
Customer data lives as long as your workspace does. Delete a conversation and it leaves primary storage immediately, backups within 35 days. Close your account and everything's erased within 60 days, unless a law requires me to keep invoices longer.
Self-hosted deployments set their own retention. Nothing in them reaches me.
You can access, correct, export or erase your data, restrict or object to processing, and lodge a complaint with a supervisory authority. Export and deletion run through the same public API the product itself uses, so you don't have to email me to get your data out.
If you're an end customer of a company that uses Inbxer, contact that company first — they control the data, and I act on their instructions.
Choose an EU workspace and customer data stays in the EU at rest and in processing. Where a transfer is unavoidable — for example me assisting on a ticket you open from outside the EU — it's covered by the standard contractual clauses in the DPA and limited to what the request requires.
The DPA incorporates the EU standard contractual clauses and the UK addendum, lists sub-processors, and sets a 24-hour breach notification window. It's available on request, and standard cloud plans don't need to negotiate it.
This policy is versioned, with previous editions kept in the repository so you can diff them. Material changes get emailed to workspace admins at least 30 days ahead.