Privacy Policy

Last updated: April 1, 2026

1. Introduction

Messybox, Inc. ("Messybox," "we," "us," or "our") operates the messybox.ai website and the Messybox email productivity platform (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not access or use the Service.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and authentication credentials (via OAuth — we never store your email password). If you subscribe to a paid plan, our payment processor collects your billing information; we do not store credit card numbers on our servers.

Email Data

To provide our sorting, drafting, and nudge features, our AI processes the content of your emails in real time. This processing is transient — email content is analyzed and immediately discarded. We do not permanently store the content of your emails. We retain only metadata necessary for the Service to function, such as sender addresses, timestamps, and category assignments.

Usage Data

We automatically collect information about how you interact with the Service, including pages visited, features used, click patterns, and session duration. This data is anonymized and used to improve the product.

Device and Browser Information

We collect standard technical information including your IP address, browser type, operating system, device identifiers, and referring URLs. This information is used for security, analytics, and troubleshooting.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process your emails for sorting, draft generation, and follow-up detection
  • Personalize your experience and learn your communication preferences
  • Process transactions and send related billing information
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and support requests
  • Monitor and analyze trends, usage, and activities to improve the Service
  • Detect, investigate, and prevent fraudulent or unauthorized activity

4. How We Share Your Information

We do not sell your personal information. We do not use your email content to train AI models. We may share your information only in the following circumstances:

  • Service providers: We share information with third-party vendors who perform services on our behalf, such as hosting, payment processing, and analytics. These providers are contractually obligated to protect your data.
  • Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
  • Business transfers: If Messybox is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
  • With your consent: We may share information for any other purpose with your explicit consent.

5. Data Security

We implement industry-standard security measures to protect your information. All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. We conduct regular security audits and penetration testing, and we maintain SOC 2 Type II certification.

While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly notifying you and relevant authorities of any breach in accordance with applicable law.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request that we correct inaccurate or incomplete data.
  • Deletion: Request that we delete your personal data.
  • Portability: Request a copy of your data in a machine-readable format.
  • Objection: Object to our processing of your personal data.
  • Restriction: Request that we restrict the processing of your data.

To exercise any of these rights, please contact us at privacy@messybox.ai. We will respond to your request within 30 days.

7. Cookies

We use cookies and similar tracking technologies to operate and improve the Service. Cookies are small data files stored on your device. We use the following types of cookies:

  • Essential cookies: Required for the Service to function properly (authentication, security).
  • Analytics cookies: Help us understand how users interact with the Service so we can improve it.
  • Preference cookies: Remember your settings and preferences for a better experience.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using certain features of the Service.

8. Data Retention

We retain your account information for as long as your account is active or as needed to provide the Service. Email content is processed transiently and not retained. Usage and analytics data is retained in anonymized form for up to 24 months. When you delete your account, we remove your personal data from our systems within 30 days.

9. International Data Transfers

Your information may be transferred to and processed in countries other than the country in which you reside. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, to protect your data during international transfers.

10. Children's Privacy

The Service is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@messybox.ai
  • Mail: Messybox, Inc., 548 Market St, Suite 36879, San Francisco, CA 94104