Privacy Policy

Effective August 14, 2026 · Last updated September 11, 2026

Autobox is an email assistant that works inside your mailbox. It reads each message as it arrives, files it under a label, and leaves a draft reply where one is needed. It never sends mail on your behalf.

This policy explains what Google user data Autobox accesses, why, how long we keep it, and who else can see it. It is written to be read, so we have kept it short and specific. Where Autobox is connected to an Outlook or Zoho Mail mailbox instead of Gmail, the same rules apply to that mailbox's data; the sections that name Google describe the Google-specific commitments.

Who we are

Autobox is operated by SJ Enterprise. For any privacy question, or to exercise any right described below, write to admin@sjenterpriseusa.com and we will respond within 30 days.

What we access, and why

Google asks you to approve permissions twice: once when you sign in, and once more when you connect a Gmail mailbox. Each is a separate consent, and we request the narrowest scopes that let the product work:

When Google OAuth scope What it lets Autobox do Why we need it
Signing in openid email profile See your email address and name Identifies your Autobox account; nothing in your mailbox is reachable with these
Connecting Gmail https://www.googleapis.com/auth/gmail.modify Read your messages, apply and remove labels, and create drafts Reading a message is what lets us categorize it; the label is the output; the reply is written into your mailbox as an unsent draft

That is the whole list. We do not request the Calendar, Contacts, or Drive scopes, and we do not request gmail.send. Autobox never calls Gmail's send API: every reply it writes is created as a draft, and it sits in your drafts until you send it yourself.

How your email is processed

When a message arrives, its content — sender, subject, body, and the thread it belongs to — is passed to a large language model that decides which label fits and, where appropriate, writes a draft reply. This is automated. The label and the draft are written back to your mailbox.

Two model providers are involved. Anthropic (Claude) categorizes each message. OpenAI writes the draft reply. Under our agreements with both, your content is not used to train their models, they retain it only as long as needed to return a response and to detect abuse, and they act as our processors — they may not use your data for their own purposes.

Whether people can read your mail

No employee, contractor, or other human reads your messages. The only exceptions are the ones Google's policy permits: with your explicit consent (for example, if you send us a message to debug a specific problem), where necessary for security purposes such as investigating abuse, or where we are legally required to. If any of these happens, access is limited to the individual messages concerned.

Limited Use

Autobox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

"Google user data" here means everything Autobox receives from Google about you: your email address and name from sign-in, and — once a Gmail mailbox is connected — message headers, subjects, bodies, labels, thread identifiers, and the drafts we create. Specifically, we do not and will not:

What we store

How long we keep it

We do not keep logs of message content. Application logs carry message identifiers and the label assigned, never the text. Error reports are configured so that request bodies and personal details are not captured.

Who else sees it

We do not sell your data and we do not share it for advertising. We use a small number of service providers who process data on our behalf, under contract, and only to run the product:

Provider What they do for us What reaches them
Anthropic Categorizes each message (Claude) Message content, to return a label
OpenAI Writes the draft reply Message content and thread history, to return a draft
Supabase Hosts our database Everything listed under "What we store", encrypted at rest
Amazon Web Services Hosts the application and this website Message content in transit while it is being processed; not retained
Sentry Error reporting Stack traces and identifiers; personal details and request bodies are switched off
Better Stack Application logs Message identifiers and labels; never message text
Resend Sends account emails: sign-up verification, password reset, and a notice if a connected mailbox stops working Your name and email address, and the address of the connected mailbox; never message content

Google, Microsoft, and Zoho are not on this list because they are not our processors: they are the mailbox providers you chose, and Autobox reads from and writes to the mailbox you connected under the permissions you granted there.

Disconnecting and deletion

You can disconnect a mailbox from Autobox's settings page at any time. Disconnecting stops processing, revokes our access at the provider where the provider allows it (Google and Zoho do; Microsoft does not offer a way, so an Outlook grant is removed under your Microsoft account), and deletes the messages, drafts, and agent session we hold for that mailbox. You can also revoke Autobox's access from your Google Account permissions page; that stops all processing immediately, and the stored data is removed when you disconnect or delete your account.

To delete your Autobox account and everything we hold, use Delete account on the settings page. It takes effect immediately: every connected mailbox is disconnected as above, every record we hold for you is deleted, and you are signed out everywhere. If you would rather not use the app, write to admin@sjenterpriseusa.com and we will do the same within 30 days.

Our database provider keeps encrypted backups for 7 days, so a copy of deleted data may exist in a backup for up to 7 days after deletion, after which it is gone. Labels and drafts already in your mailbox belong to you and stay there; deleting your Autobox account does not remove them.

Your rights

Depending on where you live, you may have the right to access the data we hold about you, correct it, delete it, export it, or object to how we process it. Write to admin@sjenterpriseusa.com and we will action it within 30 days at no charge.

Changes to this policy

If we change how we handle your data in a way that matters, we will email every connected account before the change takes effect, and update the date at the top of this page. Continuing to use Autobox after that date means the new policy applies.

Contact

SJ Enterprise
admin@sjenterpriseusa.com