Security and privacy

What we can do with your mail, what we keep, and how to take it all back.

The permission we ask for

Nickbox requests https://www.googleapis.com/auth/gmail.readonly for each inbox, plus openid and email to sign you in. With this permission we can search and read messages. We cannot send, delete, label or change anything.

What we store

For each inbox: the nickname, the address, the connection status and an encrypted refresh token in Google Cloud Secret Manager. For your account: your Google ID, email, plan and billing status. We keep counts of tool calls to run the service.

What we do not store

Message bodies, subjects, attachments and search results pass through our server in memory and are discarded after the response. They are never written to our database or logs.

Where it runs

On Google Cloud in us-central1 (Cloud Run, Firestore and Secret Manager). Payments run on Stripe. No other processor receives your mail content.

How to revoke access

Disconnect an inbox in the dashboard and we revoke its token with Google immediately. You can also remove Nickbox from your Google account permissions page. Deleting your account in the dashboard cancels your plan, revokes every inbox with Google and removes the records we hold, apart from invoices Stripe must keep.

AI models

Nickbox does not run AI models over your mail and does not use your data to train any model. Your assistant (for example Claude) receives what it asks for under its own terms.

Google API Services User Data Policy

Nickbox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Read the policy

Report a security issue

Write to our security contact. We reply within two business days. soporte@nickbox.io

Want every inbox in one assistant?

Try Nickbox for seven days. The beta is limited, so places are few.

Start your 7-day trial