Privacy Policy
Last updated: 2026-07-26
Who we are
JoinedInbox is a trading name of Computer Repair Ltd (company no. 07013303), registered in England and Wales, registered office: 14 Belton Road, London, E7 9PF. Contact us at ernie@vaitex.co.uk.
Our two roles
JoinedInbox handles two quite different kinds of data, and our role differs between them.
- Your account data — we are the controller. Your sign-in identity, subscription and billing status, and our operational and security logs are processed by us, for our own purposes of running and securing the service.
- Your mail — we are a processor acting on your instructions. We fetch, store and display the contents of the mailboxes you connect solely so that you can use them through the service. You choose which mailboxes to connect, what to keep, and what to delete. We do not read your mail for our own purposes, and we do not mine, profile, analyse or sell its content, nor use it to train any model.
Mail from other people
Mail you receive contains information about the people who wrote to you. Those correspondents are not our customers and never interacted with us directly.
We hold their information only because it arrived in a mailbox you chose to connect, and we process it only on your instructions — storing it, indexing it so you can search it, and displaying it to you and to any team members you have granted access. We do not contact your correspondents, build profiles of them, or use their data for any purpose of our own. As the person who decides which mailboxes are connected and who can see them, you are responsible for that decision under data protection law; we support it.
What we store
- Your sign-in identity — the account email address (for the owner) or username (for members), a display name, and a salted hash of the password (argon2id). We never store passwords themselves.
- Connected mailbox credentials — the IMAP and SMTP login details for each mailbox you connect, encrypted at rest with AES-256-GCM. The encryption key lives only in the server's environment and is never stored with the data or included in backups.
- Your mail — the messages and attachments fetched from your connected accounts, and anything you compose, send or save as a draft through the service.
- Things you add to your mail — labels, stars, and task information including due dates, assignments and free-text notes (up to 500 characters each).
- Signatures — the signature content you configure per account, including any image you upload for it.
- Subscription data — your plan, billing interval, renewal status and storage usage. Card details are handled entirely by Stripe and never reach our servers.
- Operational logs — an append-only record of events such as sign-ins, account changes, billing events and support requests, with the event type, a timestamp and, where relevant, the IP address the request came from.
We do not use tracking scripts, advertising cookies, or analytics of any kind. The only cookie the service sets is the one that keeps you signed in.
Why we process it
- To provide the service: fetching, storing, searching, displaying and sending your mail, and keeping connected credentials usable for that purpose.
- To secure your account: authentication, rate-limiting sign-in attempts, and alerting a mailbox owner when their mailbox is newly connected to the service.
- To take payment and manage your subscription, through Stripe.
- To answer support requests you send us.
- To meet our legal and accounting obligations.
Where your data is held
The service runs on hardware owned and controlled by us, physically located in Lithuania. Our company is registered in the United Kingdom. Some of the third parties listed below process limited data elsewhere, under their own safeguards.
Who else is involved
- Stripe — payment processing and subscription billing. Receives your billing identity and payment details directly; we never see card data.
- Hostinger — sends our own transactional email (verification, billing and lifecycle notices) and provides our domain and DNS. Receives the recipient address and content of those service emails. It does not carry your own mail, which travels directly between the service and your providers.
- Browser push services — if, and only if, you enable browser notifications, your browser gives us a delivery address at its own vendor's push service (Google, Mozilla or Apple, depending on your browser). We send new-mail notifications through it. The notification content is encrypted so that only your browser can read it, but the push service necessarily sees the delivery address and the timing.
- Uptime and job monitoring — external monitors check that the service is responding and that scheduled jobs have run. They receive status information only, not personal data.
- Your own mail providers — by design, the service connects to whichever IMAP and SMTP servers you configure.
We do not sell your data or share it with anyone for marketing.
How long we keep things
- Mail stays until you delete it or your account ends. You are in control: there is no automatic expiry of mail we have fetched.
- Deleted mail stays in the trash for 30 days, then is permanently purged.
- Optionally, you can tell the service not to fetch mail older than a chosen age from a given mailbox. This is a fetch filter — it stops old mail being copied in, and never deletes anything already stored, nor anything at your provider.
- After your account ends — whether you delete it, cancel, or it lapses through non-payment — the retention windows in the Terms of Service apply, and we email you the exact deletion date beforehand.
- Backups are encrypted and held in rolling generations of 7 daily, 4 weekly and 6 monthly copies. After data is erased from the live service, residual copies can persist in those generations for up to approximately 6 months before ageing out. We do not surgically remove an individual account from existing backups. Because the credential encryption key is never included in a backup, backed-up mailbox credentials are not usable on their own.
Your rights
Depending on where you live, you have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing.
Two of these are built into the product and are the fastest route:
- Export — builds a zip containing one mbox file per connected mailbox plus every attachment. Because we do not keep the original raw message, exported messages are reconstructed and may differ in minor technical ways not visible when reading them. We email you when it is ready; the link works for 48 hours and you can start a new export once every 24 hours.
- Delete — a two-step process: confirm in the application with your password, then open a one-time link emailed to the account address, valid for one hour. Nothing is deleted until that link is opened, and the request can be cancelled before then. Deletion also cancels any active subscription.
For anything else, or to complain about how we have handled your data, contact us using the details above. You also have the right to complain to your data protection authority; in the UK this is the Information Commissioner's Office.
If you are a correspondent rather than a customer — that is, your data reached us because someone you emailed uses JoinedInbox — the customer whose mailbox it is decides how that mail is handled. Contact us and we will help route your request to them.
What survives deletion
After an account is erased we keep only a minimal audit record: the account's internal id, a one-way SHA-256 hash of the email address rather than the address itself, the reason for deletion, and the timestamp. Everything else — mail, attachments, credentials, settings, signatures, tasks, and the free-text detail in the operational log — is removed at the same time. This record never prevents the same email address from signing up again.
Security
- Mailbox credentials are encrypted at rest with AES-256-GCM, with the key held only in the server environment and excluded from all backups.
- Passwords are hashed with argon2id and never stored or logged in readable form.
- All traffic to the service is encrypted with TLS, and the session cookie is marked secure and HTTP-only.
- Sign-in and other sensitive endpoints are rate-limited against automated abuse.
- Each member sees only the mailboxes they have been granted, enforced on the server rather than merely hidden in the interface.
- When a mailbox is newly connected, we email that mailbox itself, so its real owner is alerted if the connection was not authorized.
No system is perfectly secure. A compromise of the running server would expose the credential encryption key held in its environment; the encryption protects database copies, backups and anything taken off the server.
Changes to this policy
We may update this policy as the service develops. The current version and its effective date are shown at the top of this page.