SuperMailbox · Updated October 3, 2026

Privacy Policy

How SuperMailbox plans to handle account information, connected mailbox credentials, email requests, billing, and AI app authorizations.

Draft for launch review. These service disclosures still need final company, retention, infrastructure, and contact details before publication.

1. Who operates SuperMailbox

SuperMailbox is operated by [legal company name and address to be added before launch] (“SuperMailbox,” “we,” or “us”). Contact details for privacy requests will be published here before the service opens to the public.

2. Information used by the service

SuperMailbox needs limited information to provide an account and connect the email accounts you choose. The launch service is designed to use:

  • Account details such as your verified email address and sign-in/session records.
  • Mailbox details such as the email address, provider, connection health, and the credentials or tokens needed to connect.
  • Billing records supplied by Stripe, including subscription state and the identifiers needed to manage a subscription.
  • AI app authorization details, including the client, approved scopes, and whether you later revoked access.
  • Minimal diagnostic and security records such as timestamps, operation type, result, and request identifiers.

3. Mail content and attachments

When you ask an authorized AI app to search or open email, SuperMailbox accesses the selected provider account to complete that request. The product is designed not to keep message bodies or attachments by default. Request and security logs should not contain message bodies, attachment contents, mailbox passwords, access tokens, or unnecessary personal email details.

Before launch, SuperMailbox will publish the final technical retention periods, temporary-file behavior, and any exceptions needed to operate the service.

4. Mailbox credentials

For iCloud Mail, provide an Apple app-specific password only. Never enter your primary Apple Account password. SuperMailbox’s design calls for credentials to be encrypted before storage and decrypted only when needed to perform an authorized mail operation. The implementation and key-management details must be verified before launch.

Disconnecting a mailbox is intended to remove its stored credentials and stop future access. Deleting your account is intended to remove your account, mailbox connections, and AI authorizations, subject to records that must be retained for billing, security, or legal obligations.

5. How information is used

Information is used to authenticate you, connect and operate the mailboxes you select, provide AI app authorization, manage billing, protect the service, respond to requests, and meet legal requirements. SuperMailbox does not sell mailbox contents.

6. Service providers and sharing

SuperMailbox plans to use infrastructure, billing, transactional email, and network connectivity providers to run the service. The final list and their locations will be maintained on the Subprocessors page. Your email provider receives requests needed to access your own account. An AI app receives information you choose to request through its SuperMailbox tools, subject to that app’s own terms and privacy practices.

7. Billing

Stripe processes subscription payments. The offer is a seven-day trial followed by $4.99 per month, with a payment method required to start the trial. Payment card details are handled by Stripe. Billing cancellation and paid-through dates are reflected in the account dashboard.

8. Retention and deletion

Account, billing, authorization, and minimal security records are retained only as long as needed to operate the service, resolve disputes, meet legal obligations, and protect users. Exact retention periods will be added before launch. You can disconnect mailboxes, revoke AI app access, or request account deletion from your dashboard.

9. Security

SuperMailbox plans access controls, encrypted credential storage, secure sessions, and redacted operational logs. No internet service can promise perfect security. See the Security page for current controls and the reporting process; both will be completed before launch.

10. Your choices and rights

You can review active AI connections, revoke an authorization, disconnect a mailbox, manage billing, and request account deletion. Depending on where you live, you may have additional privacy rights. A privacy contact and request process will be supplied before public launch.

11. Children and changes

SuperMailbox is intended for adults managing their own email accounts and is not designed for children. We will update this notice when the service or applicable requirements change and show the effective date above.

12. Contact

[Privacy contact and postal address to be added before launch.]