Privacy Policy
Effective 18 July 2026
This policy explains how Supry Inc. handles personal data in connection with InboxAgents. It covers both the people who hold an InboxAgents account and the people whose messages arrive in an InboxAgents inbox — two groups with very different relationships to us, and we treat them differently. If you only read one section, read Mail sent to our customers by third parties.
1. Who we are
InboxAgents is operated by Supry Inc., a Delaware C corporation with a registered address at 2035 Sunset Lake Road, Suite B-2, Newark, DE 19702, United States. In this policy, “we”, “us” and “our” mean Supry Inc.
InboxAgents is email infrastructure for software. It gives AI agents and applications their own programmatic email inboxes, reachable over an API. The current version of the service is receive-only: customers can receive and read mail through InboxAgents, but cannot send mail through it. The only message we send is the one-time code used to verify an email address at signup.
For privacy questions, requests, or complaints, write to legal-inbox-agents@supry.com.
2. Our two roles: controller and processor
Under the GDPR and UK GDPR, the obligations that apply to us depend on whether we decide why and how data is processed.
We are a controller for the data we hold about our own customers and prospective customers: account records, billing information, support correspondence, and analytics about how the product and website are used.
We are a processor for the contents of the mail that arrives in a customer’s inbox. The customer decides what inboxes exist, who is told about them, what is done with the messages, and how long they are kept. We store and serve that mail on the customer’s instructions and for no other purpose.
3. What we collect
Account data
When you create an account through the web dashboard we collect your email address, your first and last name, and a password. Passwords are handled by our authentication provider and are never stored by us in any form. When an account is created programmatically through the API, we collect an email address and an optional username.
We also record the IP address of the client that requested the signup, which we use to rate-limit account creation and prevent abuse. We should be honest about the retention of this specific record: it currently sits in a rate-limiting table and is not deleted on a schedule. It is overwritten when the same IP address is seen again, and otherwise remains until we delete it manually or on request.
Email content
We store the mail that our customers receive, and we store it in full. Nothing is redacted, stripped, or minimised. For each message this includes:
- the sender address and every recipient address, including To, Cc, Bcc and Reply-To;
- the subject line;
- the plain-text body, the HTML body, extracted text and HTML, and a short preview;
- the complete set of MIME headers, message identifiers, labels, message size and timestamps;
- the complete raw MIME source of the message and the decoded bytes of every attachment, held in object storage in the United States.
Any personal data a sender chooses to put in a message or an attachment is therefore stored by us, because storing the message intact is the service.
Billing data
Paid plans are billed through Stripe. Stripe receives your account email address and collects payment details directly from you. Card numbers and equivalent payment credentials never pass through or rest on our systems.
Technical logs and analytics
Our hosting provider records request metadata — HTTP method, path, response status, user agent, and serving region — together with error diagnostics. These runtime logs do not contain email bodies, and are retained for approximately one day. We also use product and web analytics, described in section 9.
4. How we use personal data
- To provide the service: creating inboxes, receiving and parsing inbound mail, storing it, and returning it to the customer over the API, webhooks, WebSocket streams, and our MCP server.
- To authenticate you and keep accounts separate from one another.
- To bill for usage and maintain the financial records we are required to keep.
- To protect the service against abuse, including rate-limiting signups by IP address.
- To respond to support requests and to send operational notices about the service.
- To understand, in aggregate, how the product and website are used, so we can improve them.
5. We do not use your email for AI training — and we never send it to a model
This is worth stating plainly, because it is unusual for a product in this category and because it is easy to assume otherwise.
We do not send email content to any AI or machine-learning provider. Our systems contain no integration with any large language model or AI service. We do not use customer email — bodies, subjects, headers, attachments or metadata — to train, fine-tune, or evaluate any model, to generate embeddings, or to perform automated classification or summarisation. No model of ours or anyone else’s reads your mail.
One clarification, so that this is not read as a contradiction: InboxAgents exists to be used by AI agents, and customers routinely connect their own agents to their own inboxes through our API or our MCP server. When that happens, the customer’s own software authenticates with the customer’s own API key and reads the customer’s own mail. That is the customer choosing to send their data to a model provider of their choosing, under their own agreement with that provider. It is not us forwarding data to a model, and we have no involvement in or visibility over what the customer’s agent then does with what it read. The commitment above is about our conduct; what a customer’s own agent does is governed by that customer’s own privacy policy.
6. Mail sent to our customers by third parties
Most of the personal data flowing through InboxAgents does not come from our customers. It comes from people who wrote to one of our customers’ inboxes. Those people have no relationship with Supry Inc., never agreed to our terms, and were never asked for anything by us. We store their email address, the full content of what they wrote, and any files they attached — and we keep it for as long as our customer keeps it. We think that deserves a section of its own rather than a line buried elsewhere.
Roles. For mail received into an inbox, the InboxAgents customer who owns that inbox is the data controller. They decided to operate the inbox, they determine the purposes for which the mail is used, and they decide how long it is kept. Supry Inc. is the data processor. We process that mail solely to deliver, store and serve it to that customer, on that customer’s instructions, and for no independent purpose of our own. We do not read it, mine it, profile senders, build cross-customer datasets from it, sell it, or use it to train anything.
If you are a sender and you want something done about your data. Write to legal-inbox-agents@supry.com. Because we act as a processor, we generally cannot decide on your request ourselves: the controller is the customer whose inbox you wrote to. What we will do is acknowledge you, identify the relevant customer, and route your request to them, then assist them in acting on it — including by deleting or exporting the relevant messages when they instruct us to. Where we are legally permitted to tell you which customer holds the data, we will, so you can approach them directly. We aim to respond within 30 days.
For customers. Our Data Processing Agreement covers our processing of inbound mail, including the standard Article 28 processor obligations and our sub-processor list. It applies automatically to every customer as part of our Terms of Service; a countersigned copy is available on request from legal-inbox-agents@supry.com. If you operate InboxAgents inboxes that receive mail from people in the EU or UK, you are the controller of that mail and the obligations that come with that role — telling senders what you do with their messages, having a lawful basis, honouring their rights — are yours.
7. Legal bases (GDPR and UK GDPR)
Where we act as a controller, we rely on the following bases under Article 6(1):
- Performance of a contract (Art. 6(1)(b)) — creating and running your account, provisioning inboxes, delivering the service, and billing you for it.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure and available, preventing abusive or automated signups, diagnosing faults, and understanding product usage in aggregate. We balance these against your interests and use the least intrusive means we can.
- Legal obligation (Art. 6(1)(c)) — retaining tax, accounting and transaction records.
- Consent (Art. 6(1)(a)) — where we ask for and receive your consent for a specific purpose. You can withdraw consent at any time, without affecting processing already carried out.
Where we act as a processor for inbound mail, the lawful basis is determined by our customer as the controller, not by us.
8. Who we share data with
We do not sell personal data and we do not share it for cross-context behavioural advertising. We disclose it only to the sub-processors listed below, who process it on our behalf under contract; to professional advisers where necessary; and where we are compelled to by law or valid legal process. If the business is ever acquired or merged, data may transfer as part of that transaction, and we will say so before it takes effect.
| Sub-processor | Purpose | Data received | Region |
|---|---|---|---|
| Supabase | Database and authentication | All account data and all stored email content | United States (us-east-1) |
| Amazon Web Services (SES, S3, SNS) | Email receipt, object storage, delivery notifications | All inbound email, raw MIME, attachments | United States (us-east-1) |
| Vercel | Application and API hosting | All data transits Vercel as the application host; retained runtime logs contain request metadata only | United States (iad1 / us-east-1) |
| Fly.io | Real-time WebSocket event delivery | Full message content transits this relay in real time | United States (iad, US East) |
| Stripe | Payments and subscription billing | Account email address. Card details are submitted directly to Stripe and never reach our systems | United States |
| Svix | Delivery of webhooks to customer endpoints | Full message payloads, including bodies, headers and sender addresses | United States |
| PostHog | Product analytics | Event metadata and account identifiers. No email bodies and no sender addresses | United States (US cloud) |
| Google Analytics 4 | Website and application analytics | Usage events and an application user identifier | United States |
Two entries deserve emphasis. Webhook delivery through Svix carries the full message payload, including bodies, headers and sender addresses, to the endpoint a customer configures. Real-time streaming through Fly.io means full message content transits that relay. Both are features customers switch on; both are unavoidable consequences of doing so.
10. How long we keep data
We want to be direct here rather than reassuring. InboxAgents does not currently delete data automatically. There is no time-to-live on stored messages, no expiry on stored attachments, and no storage lifecycle rule that ages content out. Email content, including raw MIME and attachments, is retained until the customer deletes the inbox or asks us to delete it. If an account is terminated, data is retained for 60 days — so that an accidental cancellation can be reversed and any outstanding export completed — and is then deleted.
There is also, at present, no self-serve account deletion in the dashboard. Deletion of an account and its data is handled manually by us. Write to legal-inbox-agents@supry.com and we will action it and confirm back to you within 30 days. Runtime logs are the exception to all of this: they are retained for roughly one day. Billing records are kept for as long as tax and accounting law requires.
11. Security
We describe our security measures precisely, and we do not claim measures we have not implemented.
- All traffic to and from the service is encrypted in transit using TLS.
- At rest, data is protected by the default encryption our infrastructure providers apply — server-side encryption on object storage and disk encryption on the database. We do not currently apply any additional application-level encryption: message bodies and headers are stored as ordinary database columns, readable by anyone with authorised access to the database.
- API keys are stored only as SHA-256 hashes. We never hold the plaintext key, and cannot recover one for you if it is lost.
- One-time signup codes are stored hashed and expire after ten minutes.
- Customer data is isolated at the database level using row-level security, so a query executed for one account cannot reach another account’s rows.
- Attachment downloads are served through pre-signed links that expire after fifteen minutes.
No system is perfectly secure. If you believe you have found a vulnerability, please tell us at legal-inbox-agents@supry.com rather than disclosing it publicly.
12. International transfers and data location
All InboxAgents data is stored and processed in the United States. We do not currently offer EU or UK data residency, and there is no configuration that keeps your data inside the EEA or the UK.
If you are in the EEA, the UK, or Switzerland, using InboxAgents necessarily involves transferring personal data to the United States. Where a transfer mechanism is required, we rely on the European Commission’s Standard Contractual Clauses, together with the UK Addendum for UK transfers, and we engage our sub-processors on terms providing equivalent safeguards. You can request a copy of the relevant clauses from legal-inbox-agents@supry.com.
13. Your rights in the EEA and UK
If the GDPR or UK GDPR applies to you, you have the right to request access to the personal data we hold about you, to have inaccurate data corrected, to have data erased, to receive data you provided in a portable format, to object to processing we carry out on the basis of legitimate interests, to ask us to restrict processing while a dispute is resolved, and to withdraw any consent you have given.
Exercise any of these by writing to legal-inbox-agents@supry.com. We will respond within 30 days. We may need to verify your identity first, and we may not be able to act on a request that concerns data we hold as a processor — in that case we will route it to the relevant controller, as described in section 6.
You also have the right to complain to your data protection supervisory authority. In the EEA this is the authority in the country where you live or work; in the UK it is the Information Commissioner’s Office. We would appreciate the chance to address your concern first, but you do not have to come to us before going to them.
14. Your rights in California (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we have collected about you and how we use and disclose it, to request its deletion, to request correction of inaccurate information, and to be free from discrimination for exercising any of these rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. There is consequently nothing for you to opt out of on that front.
The categories of personal information we collect are set out in section 3, the purposes in section 4, and the parties we disclose to in section 8. Disclosures to those parties are made for business purposes under service contracts that prohibit them from using the information for their own purposes.
To make a request, write to legal-inbox-agents@supry.com. You may use an authorised agent, in which case we will ask for proof of their authority.
15. Children
InboxAgents is a developer product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact legal-inbox-agents@supry.com and we will delete it.
16. Changes to this policy
We will update this policy when our practices change — and because several statements here describe things we have not yet built (automatic deletion, self-serve account deletion, regional data residency), we expect it to change as we build them. The effective date at the top always reflects the current version. For material changes we will notify account holders by email or in the product before the change takes effect.
17. Contact us
Supry Inc.
2035 Sunset Lake Road, Suite B-2
Newark, DE 19702
United States
Privacy and legal: legal-inbox-agents@supry.com