Legal
Privacy Policy
View Terms of Use →Last updated: June 5, 2026
This Privacy Policy explains what information InboxJury collects, how we use it, and the choices you have. InboxJury is an application published by AI Canadian Solutions (“AICS”, “we”, “us”), its parent company. Because InboxJury works by connecting your email and using AI to read it, we’ve tried to be specific and plain about exactly what that involves.
On this page
1.Who we are
InboxJury is an email-triage application that connects one or more of your email accounts and uses artificial intelligence to read each thread and return a verdict, summary, and suggested actions. InboxJury is published and operated by AI Canadian Solutions, a Canadian company that is the data controller for the information described in this policy.
2.What we collect
Account information
Your email address, authentication details (for example, a password hash or magic-link token), plan and billing status, device registration tokens for notifications, and your in-app preferences and settings.
Connected-email content and metadata
Once you connect an inbox, we sync and store messages from that mailbox so InboxJury can analyze and organize them. This includes message content (subject lines and body text), metadata (sender, recipients, dates, thread and message identifiers, labels and folders), and information derived from it — such as the verdicts, summaries, tags, detected subscriptions, and any feedback or corrections you provide.
Connection credentials
For Google and Microsoft inboxes we store the OAuth access and refresh tokens issued by the provider; for IMAP inboxes we store the mailbox password you supply. These secrets are encrypted at rest and are used only to access the mailbox you connected. We never receive your Google or Microsoft password.
Usage information
Basic logs and usage data needed to operate and secure the service — such as AI usage and cost counters, sync timestamps, error logs, and standard request metadata (IP address, browser or app version).
3.How we access your email
InboxJury can connect to your email in the following ways, and only with your authorization:
- Gmail / Google Workspace — via Google OAuth using the
gmail.modifyscope, which lets InboxJury read your messages and, where you choose, take actions such as archiving or moving them. - Outlook / Microsoft 365 / Hotmail — via Microsoft OAuth using the
Mail.ReadWritepermission through the Microsoft Graph API. - IMAP mailboxes — via standard IMAP using credentials you provide, for custom-domain mailboxes.
The Chrome extension
The optional InboxJury Chrome extension displays verdicts, tags, and draft replies in a side
panel while you read email in Gmail or Outlook on the web. It requests only the permissions it
needs — local storage, the side panel, activeTab, and access to
the mail.google.com, outlook.live.com, outlook.office.com, and InboxJury sites — so it can
detect which message you’re viewing and show the matching verdict. The extension
authenticates with a personal access token that you explicitly approve while signed in; it does
not read your mailbox directly through InboxJury and it never receives your password.
4.How AI processes your email
To produce a verdict, InboxJury sends the relevant portions of an email thread — typically the subject, sender, and the text of the most recent messages — to a third-party AI model provider (currently OpenAI). The model returns a structured assessment (a keep/cancel-style verdict, a summary, key facts, suggested action items, and optionally a draft reply). We also generate numeric embeddings of message text to find related verdicts and improve relevance.
5.Third-party processors
We share data with a limited set of service providers only to operate InboxJury:
- Email providers you connect (Google, Microsoft, and IMAP hosts) — to sync your mail and take the actions you request.
- AI processing providers (currently OpenAI) — to generate verdicts, summaries, and draft replies from your email content.
- Hosting, email-delivery, and notification providers — our cloud infrastructure, transactional-email delivery for sign-in and digests, and push-notification delivery (Google Firebase Cloud Messaging).
- Payment processing (Stripe) — for paid plans; payment card details are handled by the processor, not stored by us.
Our access to and use of data from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide and improve InboxJury’s features for you, is not sold, is not used for advertising, and is not transferred to others except as needed to provide the service, for security, or to comply with law.
6.How we share data
We do not sell your personal information or the contents of your email. We share data only with the processors above, when you direct us to, or where required by law or to protect the rights, safety, and security of InboxJury, our users, or the public.
7.Data retention
We retain your account information and synced email data for as long as your account is active and the relevant inbox is connected, so InboxJury can keep working for you. When you disconnect an inbox we stop syncing it and remove its stored credentials. When you delete your account, or request deletion, we delete your personal data and synced email content from our active systems, except for limited records we must keep for legal, security, or accounting reasons; residual copies in backups are purged on our normal backup-rotation cycle.
8.Security
We protect your data with industry-standard safeguards: encryption in transit (TLS), encryption at rest for sensitive secrets such as OAuth tokens and IMAP passwords, scoped access tokens, and access controls so that each user can only reach their own data. No system is perfectly secure, but we work to protect your information and to respond promptly to any incident.
9.Your rights & controls
You are in control of your data in InboxJury. You can, at any time:
- Disconnect an inbox from your settings, which stops further syncing and removes its stored credentials. You can also revoke access in your Google or Microsoft account’s security settings.
- Revoke the Chrome extension’s token from your settings or by uninstalling the extension.
- Export your data using the in-app data-export option.
- Delete your account and data using the in-app account-deletion option.
Depending on where you live, you may also have rights to access, correct, delete, or restrict the processing of your personal information, and to object or lodge a complaint with a regulator. To exercise these rights, contact us using the details below.
10.Children’s privacy
InboxJury is not intended for children. We do not knowingly collect personal information from anyone under 16 (or the age of digital consent in your jurisdiction). If you believe a child has provided us information, please contact us and we will delete it.
11.International users
InboxJury is operated from Canada, and our service providers (including AI and infrastructure providers) may process data in Canada, the United States, and other countries. By using the service, you understand your information may be transferred to and processed in jurisdictions whose data-protection laws may differ from those where you live. We rely on appropriate safeguards for such transfers where required.
12.Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, take reasonable steps to notify you. Your continued use of InboxJury after the changes take effect constitutes acceptance of the updated policy.
13.Contact
For privacy questions or to exercise your rights, contact the InboxJury team at inboxjury@aicanadiansolutions.ca. You can also reach our parent company, AI Canadian Solutions, at support@aicanadiansolutions.ca (or aicanadiansolutions@gmail.com).
InboxJury is an application published by AI Canadian Solutions.