Privacy policy
What Nickbox collects, what it does not store, how Gmail data is used, who processes it, and how to exercise your rights.
Draft for the public beta. Pending legal review.
Nickbox is a hosted, read-only connector that lets your AI assistant search and read your Gmail inboxes. This policy explains what we handle and why. The service is operated by ALDAN INGENIERÍA SAPI de CV (TODO(owner): exact legal name and address).
Google API Services User Data Policy
Nickbox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Limited Use commitments
Information we receive from Gmail through the gmail.readonly permission is handled under these rules:
- We use it only to provide the user-facing features you asked for: searching and reading your messages through your assistant.
- We do not transfer it to others, except as needed to provide the service, for security purposes, or to comply with the law.
- We do not use it for advertising of any kind.
- Nobody at Nickbox reads your messages, except with your explicit consent, for security purposes such as investigating abuse, or when the law requires it.
- We do not use it to develop, improve or train AI or machine learning models.
What we collect
- Account data. Your Google ID, email address, plan and billing status.
- Inbox metadata. For each connected inbox: the nickname you chose, the address, and the connection status.
- Credentials. One encrypted refresh token per inbox, held in Google Cloud Secret Manager. OAuth grants for your assistant are stored hashed.
- Interest-list data. If you leave your email on the interest list: your email and the assistant you use. Where applicable these are stored as a hash. We use them only to tell you when places open.
- Usage counts. How many times each tool is called, so we can run and protect the service.
- Payment data. Handled by Stripe. We receive a customer reference and your subscription status, not your card number.
What we do not store
Message bodies, subjects, attachments and search results pass through our server in memory so your assistant can receive them. They are discarded after the response. We do not write message contents to our database or logs.
Your assistant (for example Claude or ChatGPT) receives what it asks for and handles it under its own provider's terms. Nickbox does not control that.
Permissions
Nickbox requests https://www.googleapis.com/auth/gmail.readonly for each inbox, plus openid and email to sign you in. We cannot send, delete, label or modify messages.
Where data lives and who processes it
- Google Cloud (region us-central1): Cloud Run, Firestore and Secret Manager.
- Stripe: payment processing and invoices.
- PostHog (optional; TODO(owner): remove those not enabled): privacy-friendly product analytics and page speed measurements, without cookies and without personal profiles.
- Sentry (optional; TODO(owner): remove those not enabled): error reports from the website, with email addresses, tokens and URL query strings removed before sending.
- Better Stack (optional; TODO(owner): remove those not enabled): uptime monitoring and the public status page. It checks public pages and receives no user data.
Gmail data never reaches analytics or error tools. Those tools receive event names, page names and technical error details only, never message content, subjects, addresses of your correspondents or your inbox nicknames.
No other processor receives your mail content. Because our infrastructure is in the United States, your information is transferred there.
Retention
- Disconnecting an inbox deletes its connection data and revokes the token with Google.
- Deleting your account removes all data we hold about you, except invoices, which Stripe keeps as required by law.
- Operational logs contain no message content and are kept only for a limited period (TODO(owner): confirm log retention period).
Your rights
You can ask us to access, correct or delete your data, to limit how we use it, or to receive a copy. If you are in Mexico, you have the ARCO rights (access, rectification, cancellation and opposition) under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP). If you are in the European Economic Area or the United Kingdom, you can make equivalent requests under the GDPR.
Most of this you can do yourself: disconnect inboxes or delete your account in the dashboard, or remove Nickbox at myaccount.google.com/permissions. For anything else, write to us and we will reply within a reasonable time.
Children
Nickbox is not for anyone under 18. We do not knowingly collect data from minors.
Security
Tokens are encrypted, access is scoped to your account, and message content is not persisted. No system is perfectly safe, and we cannot promise otherwise. To report a security issue, write to the contact below.
Changes
If we change this policy in a material way, we will update the date above and tell account holders by email before the change applies.
Contact
soporte@nickbox.io. Postal address: TODO(owner): legal address.
