Privacy and data
Privacy Policy
This policy explains what Bugbrewery accesses, why it is needed, and the choices you have when using Bugbrewery Inbox Zero.
Last updated
August 14, 2026
1. Overview
Bugbrewery Inbox Zero is an email productivity service operated by Bugbrewery. It connects to services you authorize, including Gmail and optional Google Contacts, Google Calendar, and Google Drive features, to help you organize and act on your inbox. This policy applies to the Bugbrewery Inbox Zero service available through this website.
We process personal information only to provide, maintain, secure, and support the service and the features you choose to enable. We do not sell personal information or Google user data, and we do not use it for advertising.
2. Information we process
Account and profile information
When you sign in, we receive information such as your name, email address, profile image, account identifiers, and sign-in status. We also process the preferences, rules, writing-style guidance, support requests, and other settings you provide.
Gmail information
With your authorization, the service may access and process Gmail message content and metadata, including headers, senders, recipients, subjects, timestamps, message and thread identifiers, bodies, snippets, attachments, unsubscribe information, labels, drafts, sent-message state, read state, and relevant mailbox settings. The service may also create or modify labels and drafts, archive or delete messages, change read state, and send messages when you request or configure those actions.
Optional Contacts and Google Calendar information
If Contacts access is enabled and you grant it, we may process contact names, email addresses, and related contact details to recognize correspondents and support enabled email features. If you separately connect Google Calendar, we may process calendars, event details, attendees, time zones, and free/busy availability, and create or update events for scheduling features you choose to use.
Optional Google Drive information
If you connect Google Drive, the default limited permission lets the service access files it creates or files you open with the app. You can explicitly choose full Drive access if you want to use existing files and folders across your Drive. Depending on the access level and filing features you choose, we may process file and folder names, identifiers, paths, metadata, content, and permissions needed to list or read files and folders, download or upload files, create folders, and move files. We use this access to file email attachments and manage the Drive locations you select.
OAuth, device, and service information
We store OAuth access and refresh tokens, granted scopes, and token status so the service can remain connected until you disconnect it. We may also process session data, IP address, browser and device details, feature activity, and diagnostic or security logs needed to operate and protect the service.
3. How we use information
We use the information described above to:
- authenticate you and maintain connected accounts;
- analyze, categorize, organize, label, archive, delete, or update the read state of email according to your actions and configured rules;
- generate, save, and manage drafts, and send messages only when you request it or enable a feature or rule that does so;
- support filters, cold-email handling, bulk unsubscribe, and related inbox-cleanup features;
- provide optional calendar context, availability, and scheduling features;
- provide optional Google Drive filing by creating or using folders you select and uploading or moving email attachments;
- apply your instructions, preferences, and writing style to enabled AI-assisted features;
- troubleshoot errors, prevent abuse, secure the service, and respond to support requests; and
- understand service performance and improve user-facing features without using Google Workspace data to train generalized AI or machine-learning models.
4. AI providers, infrastructure, and disclosures
Some features use AI to classify messages, summarize context, or generate suggested drafts. When you enable or use those features, the information needed for the requested task may be processed by the AI provider configured for this deployment. AI providers receive data only to perform the enabled feature; they are not permitted by us to use Google Workspace data for advertising or to train generalized AI models.
We may also use infrastructure and service providers for hosting, databases, storage, security, diagnostics, analytics, and delivery of service communications. They may process information only as needed to operate, support, or protect the service on our behalf.
We otherwise disclose information only:
- when you direct us or give consent;
- when reasonably necessary to investigate abuse, protect the service or its users, or enforce our terms;
- when required by applicable law or valid legal process; or
- as part of a merger, acquisition, or sale of assets only with any notice and consent required by applicable law and Google API policies.
We do not sell or rent personal information, serve targeted ads, or share Google user data for advertising. Human access to private Gmail, Contacts, Calendar, or Drive data is restricted to cases where you give specific permission for support, access is needed for security or abuse investigation, or access is required by law.
5. Google API data and Limited Use
Our use of information received from Google APIs, and any transfer of that information, follows the Google API Services User Data Policy and its Limited Use requirements. You can read the current policy on the Google for Developers website.
In particular, Google user data is used only for the user-facing features described in this policy. It is not used for advertising, sold to data brokers, used to build marketing profiles, or used to train generalized AI or machine-learning models.
6. Retention and security
We retain account information, service settings, OAuth tokens, and feature data while your account is active and for only as long as reasonably needed to provide the service, satisfy the purpose for which it was collected, resolve disputes, protect the service, or meet legal obligations. Retention can vary by feature and the settings you choose. OAuth tokens are no longer used after the connected account is disconnected or access is revoked.
When an account or its data is deleted, copies may remain for a limited period in backups, security records, or records we must retain by law before being deleted or de-identified through our normal retention cycle.
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including access controls and protection of data in transit where applicable. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
7. Your choices and deletion
- Control features: you can change rules and disable optional features from your service settings.
- Revoke Google access: remove the service from your Google Account connections or disconnect the mailbox in Bugbrewery Inbox Zero. Revocation stops future API access but does not by itself delete information already stored by the service.
- Access, correction, and deletion: use the available account controls or email us at [email protected] to request access to, correction of, or deletion of your personal information. We may need to verify your identity.
Depending on where you live, you may have additional rights, including the right to object to or restrict processing, request portability, or complain to a data protection authority.
8. International processing and children
Bugbrewery and its service providers may process information in countries other than the one where you live. Where required, we use appropriate safeguards for international transfers and handle information according to this policy.
The service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided information to the service, contact us so we can investigate and delete it where appropriate.
9. Changes and contact
We may update this policy as the service or legal requirements change. We will post the revised policy here, update the date above, and provide additional notice when appropriate. Material changes to how Google user data is used will be disclosed before the new use begins and consent will be requested where required.
Bugbrewery is the operator responsible for this deployment. For privacy questions or requests, email [email protected].