← Quietbox

Privacy Policy

Last updated 27 July 2026

Draft.The bracketed placeholders below must be filled in, and this document should be reviewed by a qualified adviser, before Quietbox is offered to anyone outside the operator’s own organisation.

Who we are

Quietbox (“we”, “the service”) is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For questions about this policy or about your data, contact [PRIVACY CONTACT EMAIL].

What Quietbox does

Quietbox connects to your Microsoft Outlook mailbox with your permission, reads newly arrived messages, classifies them using an AI model, and files them into folders — either folders it creates for you, or folders you already have and select. It can also create tasks from messages and send you a periodic email digest.

What we access and store

When you connect a mailbox, Quietbox requests permission to read and modify your mail, send mail on your behalf, and read and write your mailbox settings. It uses these to file messages, apply categories, and send digests.

We store, per processed message:

  • Subject, sender name and address, and recipient addresses
  • A preview of the message body, and an AI-generated summary of it
  • The date received, whether it had attachments, and a link that opens the message in Outlook
  • The tag assigned, the confidence score, the folder chosen, and how that folder was chosen

We also store:

  • Your email address and the OAuth tokens for your mailbox, encrypted at rest
  • The names and structure of your mail folders, and any labels you add to help the AI route into them
  • Your settings, rules, tags and any tasks created

Quietbox does not download or store attachments, and does not store complete message bodies — only the preview and summary described above.

Who your data is shared with

We do not sell your data and we do not use it for advertising. It is shared only with the providers needed to run the service:

  • OpenAI— classifies each message and chooses a folder for it. To do that it receives the subject, the sender’s name and address, the To and CC addresses, a short preview of the body (up to the first 255 characters, which is the length Microsoft provides), and your own name and email address so it can tell when you are merely copied in. Choosing a folder additionally sends the generated summary, the names of your candidate folders and any labels you gave them, your exclusion rules, and your past folder corrections. Under OpenAI’s API terms this data is not used to train their models.
  • Microsoft — the source of your mail, accessed via the Microsoft Graph API under the permission you grant.
  • Supabase — hosts the database in which the above is stored.
  • Resend — delivers digest and notification emails to you. Digest emails contain summaries of your messages.
  • Vercel and DigitalOcean — host the application itself.

Where your data is held

Data is stored and processed on infrastructure operated by the providers listed above, which may be located outside [JURISDICTION]. Where required, transfers rely on the safeguards those providers offer in their own terms.

How long we keep it

Your processed-message records are retained until you delete your account or ask us to remove them. We are not currently applying an automatic retention limit; if that changes, this policy will be updated first.

Your choices

  • Disconnect at any time. Disconnecting the mailbox in the app stops all processing and deletes the stored access tokens. The permission you granted continues to exist on Microsoft’s side until you revoke it there, from your Microsoft account’s app permissions — we cannot do that for you.
  • Exclude folders and senders. You control which folders Quietbox may file into, and can set rules that exclude messages from processing entirely.
  • Access, correct or delete. Email [PRIVACY CONTACT EMAIL] to request a copy of your data, correct it, or have it deleted. Deleting your account removes your stored messages, folders, rules, tasks and tokens.

Depending on where you live you may have additional rights over your personal data, including the right to complain to a supervisory authority.

Security

Mailbox access tokens are encrypted before being stored. Access to the production database is restricted to the service itself, and all traffic between your browser, the service and its providers is encrypted in transit. No system is perfectly secure, and we cannot guarantee absolute security.

Children

Quietbox is not intended for use by anyone under 16, and we do not knowingly collect their data.

Changes to this policy

If we change how we handle your data we will update this page and revise the date above. Material changes will be communicated to connected users by email.

Questions about this policy: [PRIVACY CONTACT EMAIL]