AI Mailbox Privacy Notice
Last updated July 28, 2026
This notice explains the mailbox data Freightbox accesses, why it is used, where it is processed, and how you can disconnect or delete it. It supplements the Freightbox website privacy policy.
Data we access
When you connect Gmail or Outlook, Freightbox accesses the connected account identifier and email address, mailbox messages, thread metadata, participants, attachments, labels or categories, and synchronization activity needed to operate the features you enable. When you connect Google Calendar, Freightbox accesses calendar metadata, availability, and events needed to display and manage your calendar.
Freightbox derives and stores classifications, summaries, reply-needed decisions, generated drafts, provider-action records, and security and reliability metrics. Aggregated or anonymized operational statistics are used only to operate, secure, and improve user-facing Freightbox features. They are not used for advertising, credit decisions, data brokerage, or training general-purpose AI models.
How we use mailbox data
- Sync and organize email in Freightbox.
- Classify logistics workflows and apply Gmail labels or Outlook categories.
- Create reply drafts when a message appears to need a response.
- Provide search, history, audit activity, and customer-requested support.
- Protect the service, investigate failures, and prevent duplicate provider actions.
AI Mailbox is draft-only. Freightbox does not automatically send these replies.
Google and Microsoft access
Gmail uses Google's gmail.modify permission, which Google documents as allowing apps to read, compose, and send email. AI Mailbox uses it only to read and synchronize mail, manage labels, and create drafts; it does not call Gmail send endpoints or automatically send messages. Google Calendar uses calendar.readonly to load calendar identifiers and availability, and calendar.events to create, update, and delete events when you use those features. Outlook uses delegated Mail.ReadWrite for mailbox-scoped functions and does not request Mail.Sendor Microsoft calendar access. Freightbox's use and transfer of Google user data follows the Google API Services User Data Policy, including its Limited Use requirements.
Service providers
Freightbox uses Google for mailbox and calendar connectivity and Microsoft for mailbox connectivity; Supabase for authentication, database, and file storage; Railway for application hosting; Anthropic and OpenAI APIs for AI processing; and Sentry for error monitoring. Relevant message content is transferred to Anthropic or OpenAI only when needed to produce a user-facing classification, summary, or draft. Freightbox does not opt customer mailbox data into provider model-training programs. These providers process data only to operate, secure, and support Freightbox under their service terms. We do not sell Google user data or transfer it to advertising platforms, data brokers, or lenders.
Security and access
Connections use OAuth. Provider credentials are encrypted server-side and are not shown in the product. Access is organization- and mailbox-scoped, sensitive operations are audited, and data is encrypted in transit. Learn more on our security page.
Retention, disconnect, and deletion
Disconnecting a mailbox stops new synchronization, removes Freightbox's stored OAuth credentials, and attempts to stop the provider watch or subscription. Existing synced history remains available until the organization is deleted. Organization admins can export data and schedule deletion from Profile settings. Provider access is removed immediately; active tenant data is permanently purged after the 30-day grace period. Limited backup copies may remain for the infrastructure provider's recovery window and are not available in the active product.
Your choices
You can disable AI Mailbox, disconnect a provider, export organization data, or request deletion. See the data deletion guide, or contact hello@getfreightbox.com for access, correction, portability, or deletion requests.