Legal
Privacy Policy
Last updated: 26 April 2026
1. Who we are
Locryn Thomas (trading as InboxAI) is the data controller for personal data processed through this website and dashboard. Our address: Locryn Thomas trading as InboxAI · 69 St Johns Street, Hayle, Cornwall TR27 4LN. You can contact us at support@inboxai.direct.
2. Data we collect
Account data
When you sign up we collect your name, email address, and business details via Clerk (our authentication provider). We also store your subscription status and billing history via Stripe.
Chat conversation data
Conversations that visitors have with your widget are stored in our database (Supabase, hosted in the EU). This includes message content, timestamps, and session identifiers. Visitors are not asked for their name or email unless your Knowledge Base instructs the AI to request it.
Usage data
We collect aggregated usage metrics (conversation counts, AI usage) to operate rate limiting and analytics features. We use Sentry for error monitoring, which may capture limited technical diagnostics.
3. How we use your data
- To provide and improve the InboxAI service
- To process payments and manage your subscription
- To send transactional emails (receipts, escalation alerts)
- To detect and prevent fraud or abuse
- To comply with legal obligations
Our lawful basis under UK GDPR is contract performance (to deliver the service you signed up for) and legitimate interests (security, product improvement). Where we rely on legitimate interests, we have balanced these against your rights.
4. Data sharing
We share data only with:
- Clerk — authentication and user management (US, with UK GDPR adequacy measures)
- Supabase — database hosting (EU region)
- Stripe — payment processing (EU region where possible)
- Anthropic — AI inference for widget responses and the Knowledge Base editor (US, processed transiently; not used for training)
- Resend — transactional email delivery (US, with UK GDPR adequacy measures)
- Sentry — error monitoring (US, with UK GDPR adequacy measures)
We do not sell your data to third parties.
5. Data retention
We retain your account data for as long as your account is active and for up to 12 months after closure for audit purposes. Conversation data is retained for 24 months by default. You may request earlier deletion at any time (see section 7).
Billing records held by our payment processor (Stripe) are retained according to their data retention policy, which complies with UK tax requirements (typically 6+ years).
6. Cookies
We use strictly necessary cookies for authentication and session management. For full details see our Cookie Policy.
7. Your rights
Under UK GDPR you have the right to:
- Access — request a copy of your data (use the export feature in Settings)
- Rectification — correct inaccurate data
- Erasure — request deletion of your account and data
- Portability — receive your data in a machine-readable format
- Object — to processing based on legitimate interests
- Restriction — request we limit processing while a dispute is resolved
To exercise these rights email support@inboxai.direct or use the account controls in your dashboard. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) — the UK supervisory authority for data protection — at ico.org.uk or 0303 123 1113.
8. Visitor data
When visitors interact with an InboxAI widget on a customer's website, we process their messages on the customer's behalf. The customer is the data controller for visitor data; InboxAI is the data processor.
Visitor messages and conversation history are:
- Sent to Anthropic (United States) for AI processing — subject to Standard Contractual Clauses
- Stored in our database (Supabase, EU region) for the customer to review in their dashboard
- Retained for 90 days unless the customer extends or deletes earlier
Customers using InboxAI must:
- Disclose AI-assisted chat processing in their own privacy policy
- Have a lawful basis under UK GDPR for processing visitor data (typically legitimate interest or consent)
- Provide visitors with the means to exercise their data rights
InboxAI provides a Data Processing Addendum (DPA) on request for customers who require one for their compliance. Contact support@inboxai.direct.
9. Security
We use industry-standard security measures including TLS encryption in transit, encrypted storage at rest, and role-level database access controls. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
10. Changes to this policy
We will notify you by email of any material changes at least 14 days before they take effect. The "last updated" date at the top of this page reflects the most recent revision.