Privacy Policy
Operated by Inbox Triage (open source). Contact: inbox-triage-support@googlegroups.com.
What Inbox Triage does
Inbox Triage adds labels to incoming Gmail messages (“Triage/Needs You”, “Triage/Updates”, “Triage/For You”, “Triage/Later”, “Topics/Shopping”, plus “Triage/Junk” if you mark anything as junk) on a schedule you choose. It never sends, deletes, archives, forwards, or marks email as read, and never moves email to Spam.
Google user data we access
- Permission:
https://www.googleapis.com/auth/gmail.modify, the narrowest Gmail permission that allows adding labels. It's used only to read received messages, create the labels above, and add or remove those labels. - What is read: headers (sender, subject, date, authentication results), message text, and the IDs of messages you sent (to recognise people you correspond with).
How it's used and shared
- For each received email, a short cleaned excerpt (up to 1,000 characters), the subject, the sender's domain and coarse flags are sent to Jev by TypeSafe (typesafe.ai), directly or through OpenRouter (openrouter.ai), which passes the request to TypeSafe. This uses your own Jev key or, when the operator sponsors free access, the operator's key. Jev answers yes/no questions; local rules decide the label. Message IDs, email addresses and attachments are not sent.
- Only if you click “Turn notes into rules”, your typed notes and the sender/subject of the emails shown on screen are sent once to an AI model via OpenRouter to propose rules for you to review.
- We do not sell Google user data, use it for advertising, or use it to train AI models. Human access is limited to what's needed for security or legal obligations, or with your consent.
- Inbox Triage's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- The Inbox Triage extension's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Chrome and Brave extension
The optional extension adds a dashboard to Gmail. Its content script reads the Gmail tab title to identify the open account and detect unread-count changes; it does not read message bodies from Gmail's page. Its service worker sends the account address and a revocable server access token to your selected Inbox Triage server to fetch label summaries and request a sync. The dashboard displays recent senders and subjects returned by the server. The extension stores the selected server address, per-account server tokens, and dashboard preferences in browser storage, but no Google OAuth token, AI key, message body or subject. Its Gmail page permission is needed to place the dashboard; labeling is performed by the server through the separately approved Google permission. A self-hosted server may use loopback HTTP rather than HTTPS.
What is stored
- Your Google OAuth token, your Jev key, your settings, rules and notes summary, run history, the IDs of labeled messages with the labels applied, and hashed (non-reversible) relationship facts.
- Message bodies and subjects are not stored on disk; the dashboard fetches subjects live from Gmail and the server may cache recent sender/subject details briefly in memory.
- Data is stored on the operator's server with access restricted to the service.
Deleting your data
Click Disconnect account in the app to remove that account's OAuth token, Jev key, settings, rules, notes summary, run history, message IDs and relationship facts from the active server, and invalidate its extension access. The app also asks Google to revoke the grant; if that request fails, remove access at myaccount.google.com/permissions. Revoking access at Google alone does not delete data from this server: use Disconnect or contact inbox-triage-support@googlegroups.com for deletion. On the hosted triage.shimoverse.com service, automated encrypted disk snapshots can retain a deleted account's data for up to seven days while the source disk remains active; other self-hosted operators may use different backup policies. Labels already added stay in Gmail; you can delete them there.
Changes
We'll update this page if data practices change. Last updated: 2026-10-02.