Legal

Privacy policy

Last updated 12 August 2026·Version 1.0·hello@inbxer.com

This policy covers the planned Inbxer cloud service and this website. If you self-host Inbxer, none of your customer data reaches me — you are the controller and this policy does not apply to that deployment.

1. Who's behind this

Inbxer is an open-source project built and operated by one person — Abdelmjid. For the cloud service I act as a processor of your customer data and a controller of your own account data. Reach me at hello@inbxer.com.

2. What I collect

Two categories, and I treat them differently.

Account data — the name, work email and workspace details you give me when signing up, plus billing information held by my payment processor.
Customer data — the conversations, contacts and attachments your team stores in Inbxer. I process this only to run the service for you.
Product telemetry — errors, page timings and feature usage, tied to a workspace rather than a named individual.
Website analytics — a privacy-preserving, cookieless counter of page views and referrers.

3. How I use it

Account data runs your subscription and lets me reach you about incidents, security notices and releases. Customer data is used only to deliver the features you enable — routing, search, automation and reporting.

I don't sell data, I don't share it with advertisers, and I don't use your customer data to train shared machine-learning models. Where you enable AI drafting, the request goes to the model provider you select and isn't retained for training.

5. Sub-processors

The list stays short, and it's public. Material changes get announced 30 days before they take effect, and you can object.

Cloud hosting — AWS, in the region you choose at workspace creation (EU, US or AU).
Email delivery — Postmark, for transactional mail only.
Payments — Stripe, which holds card data; I never see it.
Error monitoring — Sentry, self-hosted in the same region as your workspace.

6. Retention

Customer data lives as long as your workspace does. Delete a conversation and it leaves primary storage immediately, backups within 35 days. Close your account and everything's erased within 60 days, unless a law requires me to keep invoices longer.

Self-hosted deployments set their own retention. Nothing in them reaches me.

7. Your rights

You can access, correct, export or erase your data, restrict or object to processing, and lodge a complaint with a supervisory authority. Export and deletion run through the same public API the product itself uses, so you don't have to email me to get your data out.

If you're an end customer of a company that uses Inbxer, contact that company first — they control the data, and I act on their instructions.

8. International transfers

Choose an EU workspace and customer data stays in the EU at rest and in processing. Where a transfer is unavoidable — for example me assisting on a ticket you open from outside the EU — it's covered by the standard contractual clauses in the DPA and limited to what the request requires.

9. Data processing agreement

The DPA incorporates the EU standard contractual clauses and the UK addendum, lists sub-processors, and sets a 24-hour breach notification window. It's available on request, and standard cloud plans don't need to negotiate it.

10. Changes

This policy is versioned, with previous editions kept in the repository so you can diff them. Material changes get emailed to workspace admins at least 30 days ahead.