Privacy Policy

Last updated: February 7, 2025

Overview

Inbox Ninja is an AI-powered email assistant that runs on Rush, the macOS agent platform. We take your privacy seriously. Your email data is processed locally and on-demand only when you explicitly request it.

How Gmail Access Works

Inbox Ninja connects to your Gmail through OAuth 2.0 authentication:

  • We never see or store your Gmail password
  • You grant specific permissions through Google's secure OAuth flow
  • You can revoke access at any time from your Google Account settings
  • OAuth tokens are stored securely in your macOS Keychain

What We Access

Inbox Ninja only fetches email data when you explicitly ask it to perform a task:

  • Triaging your inbox to surface important emails
  • Summarizing email threads
  • Drafting replies that match your writing style
  • Checking your calendar for scheduling context

No background syncing. We do not continuously monitor or index your inbox. Data is fetched on-demand per your request.

Data Storage

  • No email content on our servers. Email data is processed in-session and not persisted beyond fulfilling your request.
  • Session history (your conversation with the agent) is stored locally on your Mac in ~/.rush/sessions/.
  • OAuth tokens are stored in your macOS Keychain, not in plain text files.

Third-Party Services

Inbox Ninja uses the following services to process your requests:

  • Anthropic Claude - AI processing for understanding emails, generating summaries, and drafting replies. Email content sent to Claude is subject to Anthropic's privacy policy. Anthropic does not use API inputs for training.
  • Google APIs - Gmail and Calendar access through secure OAuth 2.0.

What We Don't Do

  • We do not train AI models on your email content
  • We do not sell or share your data with third parties
  • We do not store copies of your emails on our servers
  • We do not run background processes that continuously access your inbox

Your Control

You have full control over your data:

  • Revoke Gmail access anytime from Google Account permissions
  • Delete session history from the Rush app or by removing files from ~/.rush/sessions/
  • Request deletion of any data by contacting us

Security

All data transmission is encrypted using industry-standard TLS. OAuth tokens are stored in your macOS Keychain, which provides hardware-level encryption on supported devices.

Changes

We may update this privacy policy. Changes will be posted here with an updated date.

Contact

Questions about this policy? contact@trp.so