Skip to content
inxo.ioPreview
ProductComparePricingDevelopersSecurity
Sign inStart free
ProductComparePricingDevelopersSecuritySign in

Privacy Policy

Effective 2026-09-10

inxo — Privacy Policy

Version 2026-09-10.


1. Two different relationships, and the difference matters

This policy covers two things that are easy to conflate:

Your customers’ email, which we process for you. When inxo reads, threads, classifies and drafts replies to mail in a mailbox you connected, we are acting on your instructions and for your purposes. You are the controller; we are the processor. We do not decide what to do with that mail. The terms governing it are in the Data Processing Addendum, which takes precedence over this policy for that data.

Your own account information, which we process for ourselves. Your name, your work email, your billing details and how you use the product — that we hold as controller, because it is our relationship with you. This policy covers it.

2. Your customers’ email (processor role)

Governed by the Data Processing Addendum. In summary:

  • What we hold: message content as a bounded copy (the full copy stays in your mailbox), email addresses, thread and delivery metadata, drafts, and audit records of who approved and sent what.
  • What we do with it: thread it, classify it, draft replies where the message calls for one, send what you approve, and keep the records that let you answer “who sent this, and when”.
  • Where it is: stored in a single United States region — Microsoft Azure’s Central US region. We operate one deployment and do not offer a choice of region; every backup and replica stays in that same region, with no cross-region replica. If you, or the people who write to you, are outside the United States, this by itself is an international transfer of the data we store — see §7 for the mechanism that covers it. One further carve-out, stated because it is the part people assume otherwise: the moment of drafting or classification sends the content to the model endpoint pinned for your workspace, which is a separate pin and may sit somewhere else entirely — depending on which model your workspace uses, that can mean a different region on the same cloud, or (for a Claude model, on one of its two hosting options) infrastructure outside Microsoft’s own cloud altogether — under the transfer terms in the Data Processing Addendum. Storage is pinned to the single region above; the model call is a separate pin and does not carry the same guarantee.
  • Who else touches it: the sub-processors listed in our register — Microsoft Azure for hosting, Azure AI Foundry for model inference, and, only if your workspace is pinned to a Claude model, Anthropic, PBC. Which applies depends on which model your workspace uses. On our Foundry-OpenAI path, Microsoft hosts the model itself and is the sole processor — the model’s original developer does not receive your data, and there is no further sub-processor. On our Foundry-Claude path, Claude is a third-party offering Anthropic — not Microsoft — sells and operates; Anthropic is an independent processor for the prompts and completions sent to it, and Microsoft separately shares your account’s contact, transaction and usage-volume information with Anthropic to operate that offering. Either way, no customer mail reaches a model today: the agreement each path requires, and its transfer assessment, have not been executed, and drafting and classification are structurally disabled until they are — see the sub-processor register for the current status.
  • How long, by kind, because they genuinely differ:
    • Message and thread content is kept for as long as the mailbox connection exists — it is the working record of an ongoing conversation, so there is no timer on it. It is deleted when you disconnect that mailbox, when your account ends, or on a valid erasure request, whichever comes first.
    • Drafts are pruned on their own schedule: 30 days after the conversation closes, adjustable per workspace between 30 and 90 days. 30 is a floor, not merely a default — you cannot set it shorter, and we would rather say so than let you discover it.
    • Audit and compliance records — who approved and sent what — are kept for at least a year, because their purpose is to answer questions later.
  • Your own mailbox is your system of record. When you ask us to erase, we erase what we hold; Microsoft 365 is yours to erase. The connect-time permission does include the ability to move a message to your Deleted Items — requested so offboarding can remove what the Service put there — and nothing in the Service uses it today.

3. Your account information (controller role)

What we collect

  • Account and identity: name, work email address, organization, and the role you hold in your account.
  • Authentication: credential identifiers and hashes. We never store a credential in recoverable form.
  • Billing: plan, subscription status and invoices. We do not receive or store your card details — payment is handled by Stripe on its own hosted pages, and card data does not enter inxo. Whether Stripe acts as a sub-processor for data we hold on your behalf, or as a vendor in our own billing relationship with you, is a determination we have recorded as open in our sub-processor register rather than asserted either way.
  • Product usage: which capabilities were called, when, by which credential, and whether they succeeded. This is operational telemetry — identifiers, counts and outcomes. It does not contain email bodies or the personal data of your correspondents, and that boundary is enforced in our logging rather than left to care.
  • Support correspondence you send us.
  • Signup verification. When someone signs up, we send a one-time code to the email address they give us, to prove they control it, using Azure Communication Services, a Microsoft service we use as our own vendor to send mail as inxo itself — not through a customer’s mailbox, and not the sub-processor register above, which covers mail we process for you, not mail we send as ourselves. We store only a salted, one-way digest of that address ourselves, but to deliver the code at all, the plaintext address necessarily passes to that vendor. It may belong to someone who never finishes signing up and never becomes a customer; we delete the record on a short, bounded window after the code expires. See the sub-processor register for the full entry.

Why

To provide and secure the Service, to bill you, to detect and prevent abuse, to meet legal obligations, and to tell you about material changes — including advance notice of a new sub-processor.

On what basis

Performance of our contract with you; our legitimate interests in securing the Service and preventing abuse; and legal obligation where one applies.

Sanctions and export-control screening

Before your account can send mail, and periodically afterward, we screen the identity you gave us — your organization’s name and, where Microsoft has linked your account to an Entra organization, that organization’s id — against government sanctions and export-control lists (principally the U.S. Treasury’s OFAC Specially Designated Nationals list). Where you signed up yourself, we additionally screen the account owner’s name and the billing contact’s name, and we separately check the jurisdiction on file against a list of comprehensively embargoed countries. We collect your billing address as account information but do not currently screen it against the sanctions list — an address cannot be reliably matched against a list of person and entity names without producing wrong holds on real customers, and we would rather tell you that than ship a check we don’t trust. We do not screen your correspondents — the people who write to the mailboxes you connect — under any part of this; it is about your organization’s own account, not the mail we process for you.

What happens on a match. An exact match suspends the account immediately, account-wide — you cannot draft or send while it stands. Most screens match nothing at all, and nothing happens.

There is a second tier that catches a close-but-not-exact resemblance — a likely transliteration or misspelling — and sends it to a human reviewer rather than suspending anything, because a resemblance is a question and not a decision. That tier is switched off by default and is not running today. While it is off, a name that resembles a listed party without matching it is recorded as no match and nothing is held. We would rather tell you that than describe a review step you might be relying on.

If you believe a match is wrong, contact us, and if your account has been suspended, use the appeal process described in the Terms of Service. A sanctions suspension is lifted only by a human review of the match — never automatically, including by a clean re-screen or a name change, because an automatic clearance is exactly what would let a real match remove itself.

Why we do this, and on what basis. This is not a discretionary interest we are weighing against yours: U.S. law prohibits us from providing services to a person or entity on these lists, so we process this data under legal obligation, not legitimate interest or consent, and we could not offer an opt-out even if we wanted to.

How long we keep it. A screening record that found no match is kept for five years from the date it was run, then deleted — long enough to show a regulator we were screening you throughout the relationship, and not so long that we hold an indefinite “we checked you against a sanctions list and you were fine” file on every customer. The deletion is done by a scheduled job, not by hand, and the five years are counted to the anniversary of the screening rather than approximated in days.

A record connected to an actual match, or to one still under human review, is not covered by that schedule: it is evidence for a decision about the account rather than a clean bill of health, so it is kept for as long as the account exists and is removed when the account’s data is erased.

Current status. As of this policy’s version, sanctions screening has not been switched on for any live account — there are no external customers yet. It will operate exactly as described above before any self-serve account can send mail, and before any customer mail is processed.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your content, or your correspondents’ mail, to train any model.

4. Who we share it with

  • Our sub-processors, listed and versioned in the sub-processor register, which gives advance notice of additions and a right to object.
  • Our payment processor, for billing.
  • Where the law requires it — and where we are permitted to tell you, we will.

We do not otherwise disclose your information to third parties.

5. Security

Data is encrypted in transit and at rest. Secrets are held in a managed key vault and resolved by workload identity — never stored in our database or configuration. Access to production is limited and audited. Records that exist to prove what happened are held in storage the application itself cannot modify or delete.

Each account’s data is isolated at the database layer such that a query which fails to state which account it is for returns nothing, rather than returning another account’s data. That is a structural property with a test that must pass on every change.

6. Your rights

Depending on where you are, you may have rights to access, correct, delete, port, or object to our processing of your personal information, and to withdraw consent where we rely on it. Contact us and we will respond within the period the applicable law requires.

If your request concerns email we process for one of our customers, we will refer you to that customer, who is the controller of that data and directs what happens to it. We will not act on such a request without their instruction, because acting on it would mean overriding their control of their own records.

Requests are scoped to the organization that directed the processing — in a managed-service arrangement, to that specific client, never to every client of the managing agency.

7. International transfers

Data we hold as processor is stored in a single United States region — we operate one deployment and do not offer a choice of region. If you, or your mailbox, are outside the United States, our storage of your data is itself an international transfer, separate from and in addition to the model-call transfer described in §2. Both are covered by the mechanism set out in the Data Processing Addendum — the European Commission’s 2021 Standard Contractual Clauses and the UK Addendum — with a transfer impact assessment for the storage location and a further one for each specific {provider, model, region} target the model call may use, rather than one assessment covering all of them. We do not rely on the EU-U.S. Data Privacy Framework as our own transfer mechanism.

Where we transfer your account, billing or usage data internationally as controller — to our payment processor, for example — we rely on Standard Contractual Clauses or another lawful mechanism under that vendor’s data processing terms.

8. Children

The Service is for organizations. It is not directed to children and we do not knowingly collect their personal information.

9. Changes

We will post a new version of this policy with a new version label and content hash, and will tell you in advance of material changes.

10. Contact

To be completed: the controller entity’s details and, where required, a representative and a data protection contact.

No Compromise AI, LLC

inxo.io

Product

ProductKnowledge basePortfolioComparePricing

Developers

Overview

Legal

TermsPrivacyData Processing AddendumSub-processorsAI disclosureAutomated sending
A No Compromise AI product · Built for Microsoft 365 · US and Canada