Last updated: May 2026
Inbase ("we", "us", "our") is a multi-tenant email inbox and team collaboration service, operated by Pichayut Pongpeaw, an individual based in Thailand. This policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have over it.
Contact for privacy matters: hello@inbase.dev
When you register, we collect your email address and display name via Supabase Auth. We also store a profile record (avatar URL if provided via OAuth) and your billing relationship with us via Stripe.
When you create or join a workspace we store: workspace name, domain, your role assignment (owner / admin / moderator / agent / viewer), and the sender email addresses you configure.
Inbase stores inbound and outbound email messages — including subject, sender, recipient, HTML body, plain-text body, and email headers — in our database for the duration of your plan's retention window (see section 5). Attachments are stored in Supabase Storage and subject to the same retention window.
Inbound email arrives via Resend webhooks. This means email sent to your workspace's domain by third parties (people who are not Inbase users) is processed and stored by us. By configuring a domain webhook, you acknowledge that you are responsible for informing senders that their messages are processed by Inbase.
We maintain an audit log of significant actions taken by workspace members — for example, sending a reply, changing a member's role, or updating integrations. Audit logs are visible to workspace owners and admins. They are retained for the life of the workspace and deleted when the workspace is deleted.
When a workspace admin invites a new member, we store the invitee's email address to send the invitation and verify acceptance. If the invitation expires or is cancelled without being accepted, the invitation record (including the email) is deleted.
We use Vercel Analytics to understand how the service is used. Vercel Analytics collects: pages visited, referrer URL, country (derived from IP, not stored), device type, and browser type. It does not use cookies, does not track users across sites, and does not collect personally identifiable information. Data is aggregated and anonymised before storage. Vercel's privacy policy governs their data handling.
We do not use advertising networks, social media tracking pixels, or behavioural profiling tools. We may also log server-side request metadata (IP address, timestamp, HTTP method) in infrastructure logs for security and debugging; these logs are retained for a maximum of 30 days.
Billing is handled entirely by Stripe. We do not store payment card numbers or bank details. We store your Stripe customer ID and subscription status to manage your plan.
We do not use your email content to train machine learning models, sell data to third parties, or serve advertising.
We share data with the following processors to operate the service:
We do not use advertising networks, data brokers, or social media tracking pixels.
| Data type | Free plan | Pro plan |
|---|---|---|
| Email message content (body, headers) | No automatic deletion* | No automatic deletion* |
| Attachments | 7 days from receipt | 365 days from receipt |
| Account & workspace data | Until deletion requested or account terminated | |
| Audit logs | Life of workspace | |
| Infrastructure logs (IP, timestamps) | 30 days | |
| Pending invitations (unaccepted) | 7 days (expires automatically) | |
*Message body content is retained until you delete the thread or delete your workspace. We may introduce per-plan message retention limits in a future update; we will provide 30 days' notice before any such change takes effect.
We use a minimal set of cookies:
inbase:theme — stores your light/dark preference. First-party, session-persistent, not shared.We do not use analytics cookies, advertising cookies, or any third-party tracking scripts.
Depending on where you are located, you may have the following rights:
To exercise any of these rights, email hello@inbase.dev. We will respond within 30 days.
We implement the following measures to protect your data:
No system is completely secure. In the event of a data breach affecting your personal data, we will notify you as required by applicable law.
Your data is stored in Supabase's EU West (Ireland) region. If you access the service from outside the EU, your data may be transferred to and processed in the EU. If you are located in the EU, data is processed within the EU and is not transferred outside the EEA except to Stripe (USA) and Resend (USA) under appropriate safeguards.
Inbase is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has created an account, please contact us at hello@inbase.dev and we will delete the account promptly.
We will notify you by email at least 30 days before any material change to this policy takes effect. Non-material changes (e.g., clarifications, typo fixes) will be reflected in the "updated" date above without prior notice.
For any privacy questions or to exercise your rights: hello@inbase.dev