This Privacy Policy explains how FNF Technologies Inc. ("we", "us"), the operator of FNF Inbox (the "Service"), collects, uses, stores, and protects information when you use our website and application at inbox.fnfapp.com and the FNF Inbox worker software. By using the Service you agree to this Policy.
FNF Inbox is designed so your most sensitive data stays with you. The worker software runs on your own machine. Your mailbox passwords, app passwords, and OAuth tokens are stored only on that machine and are not retained on our servers. When you add an account, the credential passes through only briefly to reach your worker and is then removed. We hold only the minimum account and billing data needed to run your subscription, plus a capped mirror of recent message metadata so the web app can display it.
What we do NOT retain on our servers: your mailbox passwords, app passwords, or email-provider OAuth tokens. During account setup they pass through our systems only briefly to reach your worker, then are removed; the stored copy lives only on your worker machine.
We do not sell your personal information, and we do not use the contents of your email to build advertising profiles.
If you connect a Gmail account, FNF Inbox's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Email content accessed via Google is used solely to provide the in-product features you request (syncing, searching, and running your rules) and is not transferred to others except as needed to provide those features, to comply with law, or with your consent. Google credentials are stored only on your local worker.
We rely on: Google Firebase / Google Cloud (hosting, authentication, database, storage; United States), Stripe (payments), Cloudflare (optional secure tunnel for mobile access to your worker), and Discord (optional sign-in and notifications). When you configure webhooks, data you route is delivered to the endpoints you specify. Each provider processes data under its own privacy terms.
Server-side account, subscription, and mirrored message data are stored on Google Cloud infrastructure (United States). Mirrored message data is capped and rotates automatically. We retain account and billing records for as long as your account is active and as required for legal, tax, and accounting purposes.
You can delete your account at any time from Settings → Data → Delete account. This cancels your subscription, and permanently deletes your server-side account record, mirrored message data, stored bodies/attachments, and authentication record. Data held on your own worker machine is under your control: uninstall the worker and delete its folder to remove it. You may also email support@fnfapp.com to request deletion.
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, use the in-app deletion tool or contact support@fnfapp.com.
We use industry-standard measures including encryption in transit (HTTPS), scoped access rules, and a local-first credential design. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
The Service is not directed to children under 16, and we do not knowingly collect their data.
We may update this Policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, additional notice.
Questions about this Policy or your data: support@fnfapp.com.