AI Mailbox Privacy Notice
Last updated July 20, 2026
This notice explains the mailbox data Freightbox accesses, why it is used, where it is processed, and how you can disconnect or delete it. It supplements the Freightbox website privacy policy.
Data we access
When you connect Gmail or Outlook, Freightbox reads mailbox messages, thread metadata, participants, and attachments needed to sync and understand your logistics conversations. We also store the labels or categories applied, generated drafts, classification results, and operational activity needed to show what the assistant did.
How we use mailbox data
- Sync and organize email in Freightbox.
- Classify logistics workflows and apply Gmail labels or Outlook categories.
- Create reply drafts when a message appears to need a response.
- Provide search, history, audit activity, and customer-requested support.
- Protect the service, investigate failures, and prevent duplicate provider actions.
AI Mailbox is draft-only. Freightbox does not automatically send these replies.
Google and Microsoft access
Gmail uses Google's gmail.modify permission, which Google documents as allowing apps to read, compose, and send email. AI Mailbox uses it only to read and synchronize mail, manage labels, and create drafts; it does not call Gmail send endpoints or automatically send messages. Outlook uses delegated Mail.ReadWrite for the same mailbox-scoped functions and does not request Mail.Send. Freightbox's use and transfer of Google user data follows the Google API Services User Data Policy, including its Limited Use requirements.
Service providers
Freightbox uses Google or Microsoft for mailbox connectivity; Supabase for authentication, database, and file storage; Railway for application hosting; Anthropic and OpenAI APIs for AI processing; and Sentry for error monitoring. These providers process data only to operate Freightbox under their service terms. Freightbox does not use customer mailbox content to train third-party AI models.
Security and access
Connections use OAuth. Provider credentials are encrypted server-side and are not shown in the product. Access is organization- and mailbox-scoped, sensitive operations are audited, and data is encrypted in transit. Learn more on our security page.
Retention, disconnect, and deletion
Disconnecting a mailbox stops new synchronization, removes Freightbox's stored OAuth credentials, and attempts to stop the provider watch or subscription. Existing synced history remains available until the organization is deleted. Organization admins can export data and schedule deletion from Profile settings. Provider access is removed immediately; active tenant data is permanently purged after the 30-day grace period. Limited backup copies may remain for the infrastructure provider's recovery window and are not available in the active product.
Your choices
You can disable AI Mailbox, disconnect a provider, export organization data, or request deletion. See the data deletion guide, or contact hello@getfreightbox.com for access, correction, portability, or deletion requests.