Privacy Policy

Engineer Unchain Inbox Unchained · operated by SITE REKON LLC · Last updated 28 August 2026

The short version. We connect to your Gmail account to sort your incoming mail, record receipts in your built-in expense ledger, and pass genuine sales enquiries to your CRM. We never delete, trash, or send email from your mailbox. We do not store the contents of your emails - only the sender, subject, a short preview, and what we decided about each one. (For IMAP mailboxes we hold a message's text briefly while it is analysed, and delete it within 72 hours at most - section 5.)

1. Who we are

Inbox Unchained is operated by SITE REKON LLC, trading as Engineer Unchain. For any privacy question, including a request to access or delete your data, contact [email protected].

2. What we access, and what we keep

These are different things, and the difference matters.

What we access

With your permission, we use the Gmail API to read messages in your inbox, and to archive them (remove the INBOX label), mark them as read, or apply a label. We request the gmail.modify scope because organising your inbox is the product; it is the narrowest Google scope that allows it.

What we store

We storeWe do not store
Sender address, subject line, a short preview (up to 300 characters), the message and thread identifiers, and the dateThe body of your emails. It is read from your mailbox when a message is analysed and is not kept. The one exception is IMAP mailboxes: IMAP cannot re-read a message once it has been archived, so we hold the text while the message is analysed and delete it as soon as that finishes, and never keep it longer than 72 hours
What our system concluded about a message - its category, a one-line summary, an urgency rating, and any expense or lead details it identified - including an expense record in your ledger (vendor, amount, date) when a receipt is confirmed General attachments. They are read only to analyse a message or when you view them, and are not stored
Receipt documents (invoices, bills) attached to emails routed to your accounting ledger are encrypted at rest (Fernet: AES-128 in CBC mode, authenticated with HMAC-SHA256) and stored so your financial records remain accessible even if Gmail access is later disconnected. You can view and delete stored receipts from the Expenses page at any time Attachments on emails that are NOT routed to your expense ledger
Your account details, settings, and a log of actions taken Your Google password. We never see it

3. Automated analysis, and who else sees your mail

To sort your inbox we send the content of an email to an AI provider for classification. That content includes readable text we extract from attachments (for example the text of a PDF receipt) and, where enabled, the image of an attached receipt sent to the provider's vision model to read the amount. Today the provider is Anthropic (primary) and OpenAI (used only if the first call fails). They process the content to return a classification and do not use it to train their models. We do not store attachment contents; they are fetched, sent for analysis, and discarded. The current list is published at Subprocessors and we will update that page before adding another.

Analysis is automated. It does not produce legal or similarly significant decisions about you: it decides where an email should go, and by default every action it proposes - recording an expense, passing a lead to your CRM - waits for your approval first.

4. What we do with your mailbox

The only changes we ever make to your Gmail account are: archive (remove from the inbox), mark as read, and apply a label. We never delete a message, never move one to Trash or Spam, and never send mail as you. The single exception is forwarding: when you have set up a forwarding rule, a matching email is forwarded to the address you chose - and only there.

5. How long we keep it

6. Security

Your Gmail authorisation token is encrypted at rest with a dedicated key. All traffic is over HTTPS. Access to the production database is restricted to the operator.

7. Your choices

You can also revoke our access directly at myaccount.google.com/permissions at any time, without telling us.

8. Google API Services User Data Policy

Inbox Unchained's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, we do not sell it, and we do not allow humans to read it except where you explicitly ask us to for support, where it is required by law, or where it is necessary for security.

9. Changes

If we change this policy in a way that materially affects how your data is handled, we will notify you at your account email address before it takes effect.