Last updated: April 18, 2026
The data controller responsible for processing your personal data in accordance with the EU General Data Protection Regulation (GDPR) and equivalent data-protection laws worldwide is:
Christian Louis IT Beratung
Alter Steinweg 3, 20459 Hamburg, Germany
Contact: christian@inboxconverge.com
For all data-protection enquiries (access, erasure, correction, objection or complaints) please use the email address above. We respond within 30 days (or the period required by applicable law).
This policy applies to the InboxConverge web application and all associated services. It covers all users worldwide, including those in the European Union (EU), European Economic Area (EEA), United Kingdom, Switzerland, and the United States.
A German-language version of this policy is available at /datenschutz.
When you create an account or sign in with Google we may receive your name, email address, and profile picture from Google OAuth 2.0. We use this data solely to authenticate you and identify your account within InboxConverge.
Legal basis (GDPR Art. 6): (b) contract performance.
To fetch email from your legacy POP3 / IMAP accounts you provide server details and credentials. These are stored encrypted at rest using AES-256 and are never transmitted to any third party.
Legal basis (GDPR Art. 6): (b) contract performance.
To inject email into your Gmail account, InboxConverge requests the following Google OAuth 2.0 scopes:
https://www.googleapis.com/auth/gmail.insert — inserts messages directly into your Gmail mailbox without sending them through SMTP.https://www.googleapis.com/auth/gmail.labels — creates and manages Gmail labels so imported messages can be tagged (e.g. “imported”).https://www.googleapis.com/auth/gmail.readonly — reads your Gmail profile (email address) to confirm the connection is working.The resulting access and refresh tokens are stored encrypted at rest. Tokens are refreshed automatically by the service when they expire and the refreshed token is persisted back to the database. You can revoke access at any time from your Google Account permissions page.
Legal basis (GDPR Art. 6): (b) contract performance.
Email bodies and attachments are read from your source accounts and written to your Gmail account. They are processed in memory only; no email content is written to persistent storage other than within your own Gmail account.
Legal basis (GDPR Art. 6): (b) contract performance.
We retain limited operational logs (message subject line, sender address, timestamp, success/failure flag) for up to 90 days. These are used to diagnose delivery problems and are accessible only to you and our operations team.
Legal basis (GDPR Art. 6): (f) legitimate interests.
Limited Use Policy Compliance
InboxConverge’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, InboxConverge commits to the following with respect to data obtained via Google APIs:
The service uses only strictly necessary session cookies to maintain your authenticated session. These cookies are essential for the service to function and are exempt from prior-consent requirements under the EU ePrivacy Directive (Art. 5(3)). We do not use analytics cookies, advertising cookies, or tracking pixels.
Google OAuth / Gmail API:Authentication and Gmail delivery are handled via Google’s APIs. Google processes your credentials according to its own Privacy Policy.
No sale or sharing for advertising: We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.
Where personal data is transferred outside the EEA we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) pursuant to EU Decision 2021/914/EU and European Commission adequacy decisions.
To exercise any of these rights, contact us at christian@inboxconverge.com. Complaints may be directed to the relevant supervisory authority (in Germany: BfDI).
If you are a California resident or resident of another US state with applicable privacy legislation, you have the right to know, delete, correct, and opt out of the sale of personal information. We do not sell or share personal information. Contact: christian@inboxconverge.com.
If you are in Canada, you have the right to access, correct, and withdraw consent under PIPEDA and provincial privacy laws. Contact: christian@inboxconverge.com.
Users in Brazil (LGPD), Japan (APPI), Australia (Privacy Act 1988), South Korea (PIPA), Singapore (PDPA), and other markets may exercise equivalent data-protection rights under applicable national law. Contact: christian@inboxconverge.com.
We may update this policy from time to time. The “Last updated” date at the top of this page indicates when it was last revised. For material changes we will notify users via an in-app notice or email.
For questions or concerns about this policy or your data, please contact: christian@inboxconverge.com
Christian Louis IT Beratung
Alter Steinweg 3, 20459 Hamburg, Germany