1. Purpose and scope
Agent Inbox enables AI agents to work with email, persistent context, tools, integrations, policies, and approvals. This Policy applies to Customer Content processed by those capabilities and supplements the Terms of Service and Privacy Policy.
2. Customer direction and control
Customers determine the content submitted, agents and workflows configured, integrations connected, authority delegated, recipients contacted, and retention settings selected. Agent Inbox processes Customer Content to provide those configured functions, maintain security and reliability, provide support, comply with law, and enforce the Terms.
Customers must establish lawful bases and required notices, avoid submitting data they are not authorized to process, and apply appropriate human review and access controls.
3. Model use and training
Agent Inbox does not use Customer Content to train generalized AI models unless the customer gives separate, express authorization for that purpose. Customer Content may be transmitted to an AI provider when a customer enables a feature that requires model processing. Such processing is limited to delivering the requested feature and is subject to applicable provider safeguards and contractual terms.
4. Inputs, memory, and outputs
- Inputs may include email bodies, headers, attachments, contacts, prompts, instructions, workflow state, and connected-service data.
- Persistent memory may retain facts, summaries, relationships, commitments, and prior actions to support continuity across conversations.
- Outputs may include summaries, classifications, drafts, extracted data, decisions, tool calls, and executed actions.
- Customers can reduce risk by limiting data sources, setting narrow scopes, requiring approvals, reviewing audit logs, and applying retention controls.
5. Accuracy and human oversight
AI systems can produce inaccurate, incomplete, biased, or unexpected results. Customers must test workflows before production, define approval boundaries, monitor performance, and ensure qualified human review where errors could affect rights, safety, finances, employment, healthcare, legal obligations, or other consequential interests. Agent Inbox does not guarantee factual accuracy or fitness of AI outputs.
6. Sensitive and regulated data
Do not process special-category, highly sensitive, regulated, or confidential data unless your use is lawful, your plan and configuration are suitable, and any required agreement has been executed. This includes health information, payment card data, government identifiers, biometric data, precise location, children’s data, and secrets or credentials. Never place passwords, private keys, or access tokens into prompts or email content unless an expressly supported secure mechanism requires them.
7. Security and isolation
Agent Inbox applies access controls, authentication, tenant-aware authorization, encryption in transit, logging, and infrastructure safeguards designed to prevent unauthorized access. Access by personnel and subprocessors is limited to operational need. No system eliminates all risk, and customers remain responsible for endpoint, identity, integration, and recipient security.
8. Abuse prevention
Agent Inbox may use automated and manual controls to detect spam, malware, credential abuse, unsafe automation, policy violations, anomalous behavior, and threats. It may block, rate-limit, quarantine, suspend, or investigate activity where reasonably necessary. Such controls may produce false positives and do not replace customer monitoring.
9. Deletion and portability
Customer Content is retained for the service period, the customer’s configured retention period, or as otherwise instructed under the applicable agreement. Following account termination or a valid deletion instruction, production Customer Content is ordinarily deleted or de-identified within 30 days unless earlier deletion is supported or longer retention is legally required. Where supported, customers may export relevant records before deletion or termination.
10. Account, authentication, and security retention
- Core account records are retained while an account is active and ordinarily for up to 90 days after closure.
- Active sessions expire after their configured duration and may be invalidated earlier.
- Authentication, access, and security event records may be retained for up to 12 months to detect abuse, investigate incidents, and protect the service.
- Records reasonably necessary to document consent, enforce restrictions, or prevent repeat abuse may be retained longer where lawful.
11. Operational and legal retention schedule
- Contact submissions are ordinarily retained for up to 24 months after the last meaningful interaction.
- Beta applications are ordinarily retained for up to 24 months after the last interaction or application decision. Accepted applicants’ information may become part of account or contractual records.
- Contracts, invoices, transaction records, tax records, and records needed to establish, exercise, or defend legal claims may be retained for up to seven years, or longer where applicable law requires.
- Failed transaction details, consent records, and limited anti-fraud records may be retained as reasonably necessary to protect the service and meet legal obligations.
12. Backups, legal holds, and retention exceptions
Deleted Customer Content may remain in encrypted, access-restricted backups and disaster-recovery systems for up to 35 additional days before automatic expiration. Backup data is not restored for ordinary business use and, if restored for recovery, remains subject to the original deletion requirement.
Agent Inbox may preserve information beyond ordinary periods when required by law, court order, governmental request, litigation hold, security investigation, fraud prevention, or the protection of rights and safety. When the reason ends, the information returns to the applicable deletion schedule.
13. Contact
Questions about AI processing, model providers, security measures, or data handling may be sent to support@agentinbox.si.
Questions about these terms?
Contact Agent Inbox at support@agentinbox.si.