- We never see your email. The app talks to Gmail from your Mac, through a Google app you own. Nothing passes through a server of ours, because there is none.
- Mail goes to one place you chose: the AI provider on your own key. Run a local model and it goes nowhere.
- We hold almost nothing about you. A license key, the name of the Mac it was activated on, and whatever you email us. Purchases are handled by Kelviq checkout.
- Everything the app learns lives on your disk and is yours to delete.
Who we are
InboxMinder Pro is made by Kelviq, Inc., 2261 Market Street STE 46163, San Francisco, CA 94114, United States ("Kelviq", "we"). We are the data controller for the small amount of information described under Buying a license and This website. For everything the app itself processes, you are in control: it runs on your hardware, under your Google account, with your API keys.
Write to hi@kelviq.com with any question about this policy.
The app on your Mac
InboxMinder Pro is a menu-bar app and a background agent installed on your Mac. The agent watches the Gmail mailbox you connected, labels incoming mail, and writes an unsent reply draft into threads that need one. To write those drafts it reads the thread, looks things up in a private index built from material you added (your docs, a repository, a folder, Notion, Linear or Slack), and studies your own sent mail to match your voice.
All of this happens on your Mac. The app has no account system, no sync, no telemetry and no crash reporting. It cannot send mail, and it never marks anything as spam. The only things it writes to Gmail are labels and unsent drafts, and it deletes a draft only if it created that draft itself and Gmail confirms it was never sent.
Every network call the app makes
This is the complete list. If a future version adds a destination, this page and the app's release notes will say so.
| Destination | What is sent | When |
|---|---|---|
| Gmail API | Requests to read threads, add or remove labels and create drafts, authorised by the Google OAuth app you created in your own Google Cloud project. | Continuously while the agent runs. |
| The AI provider you chose | The email being classified or answered, the passages retrieved from your index, samples of your sent mail for voice, and your standing instructions. Your docs and sent mail are also sent once, to be embedded for the index. | Each time a message is classified, drafted or polished, and when the index is built or refreshed. |
| Connectors you configured | Read-only requests to Notion, Linear, Slack, GitHub, a docs site or an MCP server, using tokens you supplied. Linear is also written to when you hand a thread off with a label. | On indexing, on lookups during drafting, and on Linear hand-offs. |
| api.kelviq.com | Your license key, the name of your Mac (its hostname), the app name and version. Later checks send the key and an instance id. No mail, no account name, no usage data. | On activation, periodically to confirm the license, and when you deactivate. |
| inboxminder.com | A request for the update feed. It carries the app version and macOS version in its user agent, and nothing else. | Once a day, and when you choose Check for Updates. Updates are downloaded from GitHub and ask before installing. |
Our servers: none exist. Kelviq does not operate any server that receives, relays, stores or reads your email, your documents, your index, your drafts or your keys.
Gmail and Google user data
You connect InboxMinder Pro to Gmail with a Google OAuth app that you create in your own Google Cloud project during setup. The permission you grant belongs to your Google account and your project; no third party, including Kelviq, holds a credential to your inbox. You can revoke it at any time from your Google account permissions.
The app requests the gmail.modify scope, which it needs to read threads, apply labels and create drafts. It does not request the scope that sends mail. The sign-in flow returns to 127.0.0.1 on your own machine, not to any server of ours.
Google user data obtained through the Gmail API is used only to provide the features described on this site: classifying and labelling mail, writing reply drafts in your voice, following up, and showing you what the app did. It is stored only on your Mac, transferred only to the AI provider you configured, and never sold, used for advertising, or used to train models by us. InboxMinder Pro's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI providers
The app generates text through a provider you pick and pay directly: Anthropic, OpenAI, Google, any OpenAI-compatible service, or a model running on your own Mac through Ollama or LM Studio. What the provider receives is described in the table above. How they handle it is governed by their terms and privacy policy, not ours; most commercial providers do not train on API traffic, and a local model sends nothing off the machine.
Your API keys are stored in the macOS Keychain. They never touch a config file, a log, the status file the menu bar reads, or a notification.
What stays on your Mac
- Keychain
- Google tokens, AI provider keys, connector tokens and your license key. Service name
inboxminder. - ~/.inboxminder/
- A SQLite state file (which threads were seen, drafted, followed up or resolved), the local vector index of your docs and sent mail, the status file, and logs.
- ~/.config/inboxminder/
- Your settings, as a plain TOML file. It contains no secrets.
- Logs
- Record subjects, senders, labels and timings so you can see what the app did. They never contain message bodies, retrieved passages or provider responses.
To remove everything: quit the app, run inboxminder agent uninstall from the bundled command line (or delete the launch agent from the app's Preferences), delete the app, the two folders above and the inboxminder Keychain items, then revoke the Google permission. Nothing remains anywhere else, because nothing was ever sent anywhere else.
Buying a license
Purchases go through Kelviq checkout, where Kelviq, Inc. is the merchant of record and card processing is done by Stripe. At checkout we receive your name, email address and billing country or postal code, which we keep to issue your license key, send receipts, answer support requests and meet tax and accounting obligations. We do not see or store full card numbers. The Kelviq privacy policy covers checkout in detail.
When you activate, the app registers the license key against the hostname of your Mac so the key can be moved to another machine later. We keep license records for as long as the license is valid and for the period required by tax law afterwards.
When you email us, we keep the correspondence so we can help you and recognise you if you write again. We answer support mail from Gmail, with InboxMinder Pro's help.
This website
inboxminder.com is a static site. It uses Google Analytics to count visits and see which pages are read; that sets cookies and sends your IP address and browser details to Google, which may use them as described in Google's privacy policy. You can block it with a content blocker, with Google's opt-out add-on, or by refusing cookies from googletagmanager.com; the site works identically without it. We do not use advertising pixels or session recording. Fonts are served from this domain, not from a font network.
Downloads are hosted on GitHub, and the Buy button leads to Kelviq checkout. Each is governed by that service's own policy once you are there.
Your choices and rights
- Access, correction, deletion. Email hi@kelviq.com and we will show you, fix or delete what we hold about you, which is your purchase record, license record and correspondence. Tax records are kept for the period the law requires.
- Everything on your Mac is yours to inspect and delete without asking us; see What stays on your Mac.
- Google permissions can be revoked from your Google account at any time. The app then stops reading mail until you sign in again.
- Residents of the EEA, UK, Switzerland and California have the rights those laws give them, including to object to processing, to portability, and to complain to a supervisory authority. Our basis for keeping purchase and license data is performance of the contract with you and our legal obligations. We do not sell personal information and do not share it for cross-context advertising.
- International transfers. Kelviq is in the United States, so purchase records are held there. The app itself transfers your data only to the AI provider and connectors you chose, in the regions they operate.
Children
InboxMinder Pro is a business tool and is not directed at children under 16. We do not knowingly collect information from them. If you believe a child has bought a license, write to us and we will delete the record and refund the purchase.
Changes and contact
When this policy changes, the date at the top changes with it, and material changes are noted in the app's release notes. Continuing to use the app after a change means you accept the new version.
Kelviq, Inc. · 2261 Market Street STE 46163, San Francisco, CA 94114, United States · hi@kelviq.com