InboxToCash — Privacy Policy

Effective date: July 18, 2026

Service: InboxToCash, available at inboxtocash.the-atlas-project.net

Provider: The Atlas Project (operating the "An Atlas Project" portfolio)

Contact: admin@the-atlas-project.net (privacy) · admin@the-atlas-project.net

This Privacy Policy explains how we handle personal information in connection with InboxToCash. It should be read with our Terms of Service, including the InboxToCash rider and mini-DPA. Because InboxToCash reads inbound email you connect, the "Email content and the Limited Use commitments" section (§P14) is important — please read it.


§P1 Who we are; scope

This Policy applies to the InboxToCash Service and its marketing site at inboxtocash.the-atlas-project.net. It does not cover Third-Party Services you connect (Gmail, Outlook, Stripe, your CRM), which have their own privacy policies.

Controller / processor roles.

- For your Account and billing data, we act as a controller.

- For the inbound email content the Service reads from your connected mailbox — including personal data about the people who contact you — you are the controller and we are your processor (or sub-processor). The mini-DPA in the Terms (§21) and §P13-DPA below govern that processing.

§P2 Categories of personal information we collect

CategoryExamplesSource
Account dataname, email, OAuth identity, workspace/inbox settingsyou, at signup (via Supabase auth)
Billing dataplan, billing email, partial card metadata, transaction historyyou and Stripe (we do not store full card numbers)
Usage & device datalog events, feature usage, IP address (hashed for rate-limiting), timestamps, error logsautomatically, to run and secure the Service
Support datamessages and correspondence you send usyou
Essential cookiesSupabase authentication-session cookieyour browser session
Connected inbox contentthe inbound inquiry emails in the labels/folders you designate, and the Deal Cards, duplicate flags, intent scores, and draft replies derived from them — which may contain the sender's name, email address, phone number, budget, dates, and message bodyyour connected Gmail/Outlook mailbox, on your instruction
Connection tokensOAuth tokens for your mailbox and CRM connections (encrypted at rest, AES-256-GCM)you, when you connect an account

We do not use analytics or advertising cookies/pixels, and we do not build advertising profiles. If this changes, we will update this Policy and, where required, obtain consent first.

§P3 How and why we use personal information (purposes)

  • Provide the Service — authenticate you; read the inbound emails in the labels/folders you designate; extract Deal Cards; de-duplicate inquiries against your ledger; score intent and prepare draft replies (on eligible tiers); and push deals to your connected CRM.
  • Billing — process subscriptions via Stripe.
  • Communicate — send transactional and service messages (receipts, security notices, product and ingestion-health notices) via Resend. We send marketing email only where permitted and with an unsubscribe option.
  • Secure and maintain — rate-limit the free scan (using a hashed IP), detect abuse, debug, and protect the Service and users.
  • Comply — meet legal obligations and enforce our Terms.
  • Improve — understand feature usage in aggregate. We do not use the inbound email content you connect to train generalized AI models, and the AI providers that perform extraction do not train their general models on your content under their API/enterprise terms.

§P4 Legal bases (GDPR / UK GDPR)

Where GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, maintain, and improve the Service, and for limited service communications), balanced against your rights; consent (where required, e.g., any future non-essential cookies or optional marketing); and legal obligation (e.g., tax/records). For the inbound-email content we process on your behalf, your instructions and the mini-DPA govern; you are responsible for the legal basis and any notice/consent owed to the individuals who email you, as the controller.

§P5 Subprocessors and third-party recipients

We use the following subprocessors and service providers for InboxToCash. Not every user triggers every one — the CRM and AI providers apply only if you connect them or if extraction keys are configured.

SubprocessorFunctionWhen it applies
VercelApplication hosting / edge deliveryalways
SupabaseDatabase and authenticationalways
StripePayment processing; subscription billingpaid plans
ResendTransactional and service emailalways
Google APIs (Gmail)Read the labels you designate (gmail.readonly); save draft replies (gmail.compose) — no sendingif you connect a Gmail inbox
Microsoft Graph (Outlook)Read the folders you designate and save drafts (Mail.Read, Mail.ReadWrite, offline_access)if you connect an Outlook inbox
AnthropicAI extraction of Deal Cards (Haiku, with Sonnet escalation)if an Anthropic key is configured (live extraction)
OpenAIAI extraction of Deal Cards (fallback provider)if an OpenAI key is configured (live extraction)
PipedriveReceives Deal Cards / contacts you pushif you connect Pipedrive
HubSpotReceives Deal Cards / contacts you pushif you connect HubSpot
Google SheetsReceives Deal Cards you push (via a service account)if you connect Sheets
Upstash (Redis)Durable rate-limiting / quota / circuit-breaker keyed on hashed IPwhen configured (otherwise in-memory)
SentryError monitoringwhen configured
BetterStackUptime/heartbeat monitoring (to detect if ingestion silently stops)when configured

We enter data-processing terms with subprocessors where required and require appropriate safeguards. We will update this list and, where required, give notice before adding a subprocessor that materially changes processing of your data. We do not sell personal information and do not share it for cross-context behavioral advertising.

When live AI extraction is not enabled, the Service runs a deterministic, on-server heuristic extractor with bundled sample inquiries ("demo mode"), and no email content is sent to an AI provider.

§P6 Cookies and similar technologies

We use essential cookies only — specifically, the Supabase authentication-session cookie needed to keep you signed in. We do not use analytics, advertising, or tracking cookies or pixels. Because we use only strictly-necessary cookies, we do not show a consent banner for non-essential cookies. If we ever introduce non-essential cookies, we will update this Policy and obtain consent where required.

§P7 Retention

  • Account and billing data — kept while your Account is active and as needed for legitimate business and legal purposes (e.g., tax records) after closure.
  • Connected inbox content and Deal Cards — retained according to your tier and settings. On the Solo plan the dedupe ledger is windowed to 90 days; on the Pro plan it is persistent until you delete it or close your Account. A scheduled retention job enforces the applicable window.
  • Connection tokens — kept (encrypted) until you disconnect the account or close your Account.
  • On request or on termination, Customer Personal Data is deleted or de-identified, subject to residual backups purged on our ordinary cycle and records we must keep by law.

§P8 Security

We use reasonable technical and organizational measures appropriate to the risk, including encryption in transit, AES-256-GCM encryption at rest for mailbox and CRM OAuth tokens, access controls, least-privilege, row-level security on stored data, and reliance on reputable infrastructure providers (Vercel, Supabase, Stripe). No system is perfectly secure; we cannot guarantee absolute security. We will notify affected users and regulators of a personal-data breach where required by law.

§P9 Your privacy rights

§P9.1 GDPR / UK GDPR (EEA/UK residents). Subject to conditions, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent where processing is based on consent. You may lodge a complaint with your supervisory authority. Where we act as processor for your inbound-email content, we will route or assist with requests as directed by you, the controller.

§P9.2 CCPA / CPRA (California residents). You have rights to know/access, delete, correct, and to opt out of "sale" or "sharing" and limit use of sensitive personal information. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for purposes requiring a right-to-limit. We will not discriminate against you for exercising rights. Authorized agents may submit requests with proof of authorization.

§P9.3 The people who email you (data subjects of connected content). The inbound emails you connect contain personal data about third parties who contacted you. For that data, you are the controller and requests from those individuals are typically directed to you; we assist you as your processor. We do not have a direct relationship with those individuals and generally cannot verify their identity independently of you.

§P9.4 How to exercise rights. Email admin@the-atlas-project.net (or admin@the-atlas-project.net) from your Account address, describing your request. We will verify your identity and respond within the time required by law. For content held on your behalf (processor role), we direct end users to you as the controller.

§P10 International data transfers

We are based in the United States, and our subprocessors may process data in the US and elsewhere. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum, or another lawful mechanism. By using the Service, you understand your information may be processed in the US.

§P11 Children

The Service is not directed to individuals under 18, and we do not knowingly collect their personal information (see Terms §16).

§P12 Changes to this Policy

We may update this Policy. We will post the new version with a revised "Last updated" date and, for material changes, provide additional notice (email or in-product). Continued use after the effective date constitutes acceptance where permitted by law.

§P13 Contact

Questions or requests: admin@the-atlas-project.net (privacy) or admin@the-atlas-project.net. Postal address: The Atlas Project, [MAILING_ADDRESS — to be added once the entity is formed].


§P13-DPA — Mini-Data Processing Addendum (inbound email content)

This summary mirrors the mini-DPA in the Terms (§21), which is the operative version.

  1. Roles. For the inbound email content and derived personal data the Service processes on your instruction ("Customer Personal Data"), you are the controller and we are the processor (or sub-processor).
  2. Instructions. We process Customer Personal Data only to provide and secure the Service, per your documented instructions (your designated labels/folders and connected scopes), and as required by law.
  3. Purpose limitation. We will not sell Customer Personal Data, use it for advertising, or use it to train generalized AI models. AI providers used for extraction act under contract and do not train their general models on your data.
  4. Confidentiality. Personnel with access are bound by confidentiality; human access occurs only as needed for security or support, and with your consent.
  5. Sub-processors. You authorize the subprocessors in §P5; we remain responsible for them and will give notice of material changes with a chance to object.
  6. Security. We maintain the measures in §P8 appropriate to the risk.
  7. Assistance. We reasonably assist you with data-subject requests, security, breach notification, and DPIAs, and notify you without undue delay of a breach affecting Customer Personal Data.
  8. Deletion/return. On termination or request, we delete or return Customer Personal Data, subject to residual backups and legal-retention requirements.
  9. International transfers. The SCCs/UK Addendum in §P10 apply where relevant.
  10. Audit. We make available information reasonably necessary to demonstrate compliance and allow reasonable, confidential audits on notice.

§P14 — Email content and the Limited Use commitments

InboxToCash reads inbound email you connect. We take the sensitivity of that access seriously and hold ourselves to the Limited Use standard set by Google and Microsoft.

Scope. The Service reads only the mailbox labels or folders you designate. It does not read your whole mailbox by default. On Gmail it uses read-only access to those labels plus the ability to save (not send) draft replies; on Outlook it reads the folders you designate and can save drafts. The Service does not send email on your behalf — a draft becomes a sent message only if you send it yourself.

Use. We use that content solely to provide the features you request: extracting Deal Cards, de-duplicating inquiries, scoring intent, preparing draft replies, and pushing deals to your connected CRM. We never use it for advertising, we never sell it, and we do not use it to train generalized AI models. Human access to your mailbox content occurs only as needed for security or support, and with your consent.

Google API Services User Data Policy (verbatim):

InboxToCash's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft Graph (mirror commitment):

InboxToCash's use and transfer of information received from Microsoft Graph adheres to Microsoft's Graph and platform terms, and we apply the same Limited Use commitments: we access only the mailbox labels/folders you designate; we use that content solely to provide the extraction and de-duplication features you request; we never use it for advertising; we never sell it; we do not use it to train generalized AI models; and human access occurs only for security or support, with your consent.


Last updated: July 18, 2026 · The Atlas Project · admin@the-atlas-project.net · admin@the-atlas-project.net

This document was prepared with automated assistance and has not been reviewed by an attorney. It is not legal advice.