InboxwellGitHub
Privacy

Privacy Policy

Inboxwell is a Windows desktop email client. This policy explains what the app accesses, where data is stored and the choices available to you.

Effective August 12, 2026

Who we are

Inboxwell is an open-source project maintained by its developer. Questions and privacy requests can be sent to support@gosho.app.

Data the desktop app processes

  • Account identity information, including your email address, display name and provider account identifier.
  • Email content and metadata needed to show, search, organize, compose, send and synchronize messages, threads, labels and folders.
  • Attachments and contact details you choose to open, download or use when composing mail.
  • App preferences, signatures, sync state and a local search index.
  • OAuth access and refresh tokens required to keep an authorized account connected.

How we use the data

Inboxwell uses provider data only to provide user-facing email features inside the desktop app. It does not use mailbox data for advertising, profiling, credit decisions or training shared AI models.

Inboxwell's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Where data goes

The app connects directly from your PC to Google, Microsoft or the IMAP/SMTP servers you configure. Inboxwell does not operate a cloud mail relay and does not upload your mailbox to an Inboxwell backend.

Messages and the search index are cached locally in an encrypted database. OAuth tokens are protected using Windows Credential Manager. Your provider continues to store the authoritative mailbox according to its own terms.

Remote content in messages

HTML email may reference images or other content hosted by the sender or a third party. Loading that content can disclose your IP address and device information to that host. Inboxwell can be configured in Security settings to block remote images when you prefer.

Website data

The Inboxwell verification website does not run the Gosho Bundles analytics tag and does not ask you to create an account. Standard infrastructure logs may temporarily record technical details such as IP address, request time and browser information for security and reliability.

Sharing and sale

Inboxwell does not sell personal data. Data is disclosed only to the mail provider you choose, to infrastructure processors needed to serve this website, when you direct the app to contact another service, or when required by law.

Retention and deletion

Local mailbox data remains on your PC until you remove the account or delete the app data. Removing an account deletes its Inboxwell cache and stored credential; it does not delete messages held by your provider. See the data deletion instructions.

Your choices and rights

You can disconnect an account in Inboxwell, revoke OAuth access at the provider, block remote content and request help with local data removal. Depending on where you live, you may also have rights to access, correct, delete or restrict processing of personal information.

Children

Inboxwell is not directed to children under 13 and is not intended for use where parental consent would be required.

Changes and contact

Material changes will be posted on this page with a revised effective date. Contact support@gosho.app for privacy questions.