INBOX ESCAPE — PRIVACY POLICY Effective Date: August 31, 2026 · Version: 1.0
1. In plain language (what we collect and how we use it)
- What we collect: (a) info you give us (name, email, 18+ affirmation); (b) your transactional mail from Gmail (orders, receipts, shipments, events, codes, etc.); (c) your activity in the offer layer (impressions, taps, redemptions); (d) hashed user/device IDs; and (e) inferences we derive (brand preferences, buying habits, imminent intent).
- How we use it: classify, summarize, group, and display your mail; detect and expire codes; personalize offers within the service (if you opted in) using our proprietary AI algorithm — entirely in‑system; and honor your consent.
- Do we sell it? No. We do not “sell” your raw data to third parties.
- Do we “share”** it?** No. We do not “share” your data for cross‑context behavioral advertising. Our personalization is first‑party, in‑system: our proprietary AI algorithm considers various ad options, narrows to one, and personalizes it — all within the Service. Your data/persona is never sent to a third‑party system (merchant, ad network, or external context). The “cross‑context” element is absent because the offer appears in the same service where the data was collected/processed.
- Your rights (CCPA/CPRA): Know/Access (with lineage — what we know about you, how we derived it, and when), Delete (full sync: raw + derived + tags + service providers + merchant aggregates), Opt‑out of Sale/Share (we don’t sell or share; implemented as a courtesy / future‑proofing), Correct, and Limit sensitive PI (precise geo). Exercise these from Settings → Data & Offers or via our DSR endpoints.
- Minors: We require 18+ (checkbox affirmation). COPPA (under 13) and CPRA (16–18) are covered by the 18+ gate (no under‑18s use the Service). Noted for completeness.
2. Information we collect (personal information)
Under the CCPA/CPRA, “personal information” (PI) means info that identifies, relates to, describes, or is reasonably linkable to a person — including “inferences” drawn from other data that create a profile.
2.1 From you (direct): name, email, login, profile, preferences, consent, 18+ age affirmation (representation/warranty).
2.2 From Gmail (the main source): your transactional mail — orders, receipts, payments, shipments, tracking, pickups, returns, food delivery; login codes, OTPs, 2FA tokens; status alerts; meetings, appointments, flights, reservations, calendar invites, RSVPs; nudges; one‑way info; real threads; to‑dos; marketing. We read these to classify, summarize, group, detect codes, and expire [1].
2.3 From the offer/ads layer: impressions, taps, dismisses, feedback codes, redemptions (with amount), context tags.
2.4 Device / usage: pseudonymous, hashed user/device ID; session; mailbox; event time; source.
2.5 Inferences (persona signals): We derive brand preferences, buying habits, and imminent intent from your events. These are “inferences”** = PI** under CCPA. We keep lineage (source event IDs + derivation rule + timestamp) for your Right to Know.
3. How we use it
- Classify & summarize
- Group into sequences
- Detect & display codes
- Expire
- Personalize offers within the service (first‑party, in‑system; if opted in): Our proprietary, AI‑driven algorithm considers various ad options (using your in‑service data, persona signals, and context), narrows to a specific ad, and personalizes it (AI‑filled template) for display in the dedicated offer layer. Your data/persona is not sent to a third‑party system. This is first‑party processing (data stays in our system), not a disclosure to a third party for cross‑context behavioral advertising.
- Improve
- Support
- Legal
- Consent
4. Sale vs. share (the CPRA nuance) — “No sale AND no share” (both cleared by first‑party, in‑system personalization)
4.1 No “sale.” “Sale” (CCPA) = disclosing PI to a third party for monetary or other valuable consideration. We do not sell your raw data. Google = service provider (DPA). Merchants = transactional redemptions or aggregates only (k‑anonymity + DP, n≥50). → The “sale” trigger is cleared. ✅
4.2 No “share.” “Share” (CPRA) = disclosing PI to a third party for cross‑context behavioral advertising — even with $0 exchanged. – What would “sharing”** look like (the trigger)? Using your data from one context** (e.g., your email in our Service) to serve hyper‑personalized ads in another context (e.g., a different app, website, or ad network) — i.e., sending your data/persona to a third‑party system for cross‑context matching/ad delivery. – What we do instead (first‑party, in‑system — NOT “sharing”): Our proprietary, AI‑driven algorithm considers various ad options, narrows to a specific ad, and personalizes it — entirely within the Service. Your data/persona is never sent to a third‑party system (merchant, ad network, or external context). The offer is retrieved from our catalog (our inventory), matched (our algorithm), and personalized (our system) — all in‑house. The “cross‑context” element is absent because the offer appears in the same service (the same context) where the data was collected/processed. It’s first‑party personalization within a single context, not cross‑context behavioral advertising. – → The “share”** trigger is also cleared.** ✅
4.3 The opt‑in (transparency + purpose limitation; FTC § 5). The personalized tier requires explicit opt‑in (checkbox/toggle) with granular toggles (event / location / time), a “Data & Offers”** dashboard** (matches, deliveries, savings, provenance/lineage), and one‑tap “Remove My Data.” – Legal basis: Since we’re not “selling”** or “sharing” (both cleared), the opt‑in is not strictly required** by the CCPA/CPRA “opt‑out of sale/share” right. It’s a matter of: (a) transparency (you know what’s happening with your data); (b) purpose limitation (your data is used for a specific purpose — personalized offers — not e.g. sold for research or used for cross‑context ads); (c) FTC Act § 5 (no deceptive practices — if we say “your data stays in‑system” and “we personalize offers,” you should be able to see/opt into that clearly); and (d) good consumer practice / voluntary consent (you actively agree, which is stronger than passive notice). – We exceed the minimum: The minimum would be “notice” (tell you we’re personalizing offers) or “opt‑out” (tell you and let you opt out). We go further: affirmative opt‑in (you must actively tick a box / enable a toggle) + granular choices (you can pick exactly which types of data/purposes) + dashboard (you can see what’s happening) + one‑tap delete (you can remove everything quickly). This is stronger than required and shows good faith / privacy‑by‑design.
4.4 Document it. In this policy + the at‑collection notice + the checkbox, we state: “By joining the personalized tier, you consent to the processing of your personal information (including inferences derived from your email activity and offer interactions) within the Service for the purpose of matching and delivering a personalized offer. Our proprietary AI algorithm considers various ad options, narrows to one, and personalizes it — entirely in‑system. Your data/persona is not sent to a third‑party system (merchant, ad network, or external context). You can withdraw consent (opt out) or delete your data at any time from Settings → Data & Offers — here’s exactly what that deletes.”
5. Sharing (now much simpler: “We don’t”)
5.1 We don’t “sell”** or “share” your PI to third parties.** – No “sale”: We don’t disclose your PI to a third party for monetary or other valuable consideration. – No “share”: We don’t disclose your PI to a third party for cross‑context behavioral advertising. Personalization is first‑party, in‑system (our algorithm; your data stays in our system; no third‑party transmission).
5.2 Service provider (Google). Google (OAuth/Gmail) under a DPA — processes on our behalf (sign‑in, Gmail access). “No sale / no share” holds (Google is a service provider / processor, not a “third party” buyer or cross‑context ad recipient). You can revoke access anytime.
5.3 Merchants (transactions / aggregates only). In the offer layer: – Transactional redemption: When you redeem an offer, the merchant may receive a confirmation (hashed user ID, offer ID, amount, date) — this is a transaction (like a purchase receipt), not a “disclosure of PI for behavioral advertising.” It doesn’t trigger “sale” or “share.” – Aggregated stats (optional): We may share aggregated, anonymized stats with the merchant (e.g., “1,000 users in your target segment redeemed your offer this month; 30% were in the ‘frequent buyer’ category; average redemption time was 2 days”). These are aggregates (many users combined, no single user identifiable) with k‑anonymity + differential privacy (min cohort n ≥ 50; small segments suppressed/noised). The merchant sees stats / trends, not individuals or your personal data. – What the merchant does NOT get: Your raw email, your full persona signals (brand affinities, buying habits, imminent intent), your hashed tags (unless part of a transactional/aggregated bundle), your name/address/contact (unless you provide it in the redemption), or any cross‑context ad profile. You are not a “third‑party buyer”** of your data** or a “cross‑context ad recipient.”
5.4 To you. We display your mail, feed, and offers.
5.5 Legal. Disclosure, merger, audit (with safeguards).
5.6 Consent. What you toggled (personalized, geo, marketing).
6. Retention
6.1 Auto‑purge. 30‑day auto‑purge of raw signals (keep aggregates).
6.2 On‑demand delete. You can delete your data anytime (full sync — see § 9.2).
7. Consent (now: transparency + purpose limitation + FTC § 5
7.1 Opt‑in (personalized tier). Explicit opt‑in (checkbox/toggle). Not strictly required by CCPA/CPRA (since we don’t “sell” or “share”), but provides transparency (you know what’s happening), purpose limitation (your data is used for a specific purpose — personalized offers — not e.g. sold for research or cross‑context ads), FTC § 5 (no deceptive practices), and voluntary consent (you actively agree). Exceeds the minimum (which would be notice or opt‑out).
8. Minors (simplified: 18+ gate)
8.1 18+ required. You must be 18 or older
8.2 COPPA (under 13) / CPRA (16–18) covered by the gate. No under‑18s use the Service, so: – Under 13 (COPPA): No under‑13s → no COPPA flow needed. (Noted for completeness.) – Ages 13–17: No 13–17s → no minor‑consent flow needed. – Ages 16–18 (CPRA parental auth): No 16–17s → no parental auth needed. An 18‑year‑old is an adult.
8.3 Age‑gating. The “I am 18 or older” checkbox is our age‑gate for the Service and any restricted (brand‑safety) content in the offer layer.
8.4 If a minor (under 18) uses the Service (e.g., false age representation). The 18+ checkbox is their representation/warranty. If it’s false (they’re under 18), we may: – Suspend/terminate their account. – Request parental consent (if under 13, per COPPA) or parental authorization (if 16–17, per CPRA) to cure the misrepresentation. – Delete their data (if the parent/consent‑holder requests). – Hold them responsible for damages/costs (if the misrepresentation caused us loss).
9. Your rights (CCPA/CPRA)
9.1 Right to Know / Access. Ask: what PI + inferences did you collect, for what purposes, with whom did you share? → We answer with lineage (source event IDs + derivation rule + timestamp).
9.2 Right to Delete. “Delete My Personal Information” + direct service providers. → On request / on opt‑out, we purge not just raw events but the derived signals, brand affinities, imminent intent, and hashed tags (the 30‑day auto‑purge helps, but you need on‑demand). → DSR Delete endpoint (full sync: raw + derived + tags + service providers + invalidate merchant aggregate contributions).
9.3 Right to Opt‑out of Sale/Share. “Do Not Sell or Share My Personal Information.” → We don’t sell or share (both cleared by design). Implemented as a courtesy / future‑proofing (in case a legal interpretation changes, or we add a new feature that might trigger “sale” or “share”). If you opt out, you get the baseline / non‑personalized offer set (no hyper‑personalization; curated public offers).
9.4 Right to Correct (CPRA). Make your PI accurate → DSR Correct.
9.5 Right to Limit Use/Disclosure of Sensitive PI (CPRA). If we use precise geo / health‑adjacent data → consent + purpose limitation; we treat geo as “sensitive” and gate it behind a toggle. → props.geo** only when consented; mark sensitive; DSR Limit.**
9.6 Non‑discrimination. We don’t penalize you for opting out / exercising rights. → Baseline (non‑personalized / curated‑public) offer set for opt‑outs (you still see offers; just not hyper‑personalized).
9.7 Consent for minors. COPPA; CPRA 16–18. (Covered by the 18+ gate; fallback for false representation.)
9.8 DSR tooling. Know / Delete / Opt‑out / Correct / Limit endpoints. Delete = full sync: raw events + persona signals + brand affinities + imminent intent + hashed tags + propagate to service providers (Google) + invalidate merchant aggregate contributions.
10. Changes
10.1 Updates. We may update this policy.
10.2 Notice. For material changes, conspicuous notice (in‑app + email) + reasonable period.
11. Contact
Questions? Contact our privacy team at [email protected].
