Privacy policy

This policy describes what Unified E box does with personal data, including everything we obtain from Google APIs. It reflects how the application actually behaves.

Last updated September 21, 2026

1. Who we are

Unified E box is an internal email-management platform operated by UniEbox LLC for the use of its members. This policy covers the Unified E box web application and the public pages on this site.

For any question about this policy or about your data, contact privacy@uniebox.vercel.app.

2. Data we collect

2.1 Account data

When a member signs in, we store their email address, an authentication identifier, and the organization they belong to. Authentication is handled by our identity provider; we do not store passwords ourselves.

2.2 Google user data

When a member connects a Gmail account, we receive data from Google APIs under the scopes they approved. Specifically:

CategoryWhat it includesPurpose
Message contentSubject, snippet, plain-text and HTML bodies, sender and recipient addresses, and timestamps for the messages we sync.The inbox renders conversations and searches across them without re-fetching from Gmail on every keystroke.
Thread metadataGmail thread and message identifiers, message counts, read state, and the RFC 5322 headers needed to thread replies correctly.Keeps the application in sync with Gmail and makes replies land in the right conversation.
Attachment metadataFile name, MIME type, and size. Attachment bytes are not stored; they are fetched from Gmail on demand when a member opens one.Lets the interface list attachments without holding copies of their contents.
OAuth credentialsThe refresh token and the current access token, encrypted at rest with AES-256-GCM, plus the granted scopes and expiry time.Maintains the authorized connection so background sync continues without prompting on every request.
Account recordsThe connected Gmail address, Google's stable account identifier, and the connection status.Identifies the mailbox and surfaces connection problems to the member.
Audit recordsWhich member connected or disconnected a mailbox, and when.Security review and abuse investigation.

Because email is correspondence, the content we sync can contain personal data about people who are not Unified E box members, such as the people a member exchanges mail with. We treat that content with the same protections described here, and we use it only to display and search the member’s own mailbox.

2.3 Operational data

We keep application logs and audit records: which member connected or disconnected a mailbox and when, synchronization outcomes, and error diagnostics. Our logs are written to identify accounts and operations by identifier rather than by message content.

2.4 What we do not collect

  • We do not collect Google Account passwords. Authorization happens on Google’s domain.
  • We do not read your Google Contacts, Calendar, Drive, or any Google service other than Gmail.
  • We do not read your Gmail settings, filters, forwarding rules, or signature.
  • We do not use advertising trackers or third-party analytics that profile you across sites.

3. How we use Google user data

We use Gmail data solely to provide the features that a member can see in the application: displaying the unified inbox, opening conversations, searching mail, marking conversations read or unread, opening attachments, and composing and sending replies. Each one is described in detail on the Gmail integration page.

Limited Use commitment

Unified E box’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3.1 What we never do

  • We do not sell Google user data, and we do not transfer it to data brokers or information resellers.
  • We do not use Google user data for advertising of any kind, including retargeting and personalized or interest-based advertising.
  • We do not use Google user data to determine credit-worthiness or for lending purposes.
  • We do not use Gmail message content to train machine learning or AI models, whether ours or a third party's.
  • We do not permanently delete mail from a connected mailbox; the scopes we request do not permit it.
  • We do not read, change, or export a member's Gmail settings, filters, or forwarding rules.
  • We do not allow staff to read message content except in the narrow cases described in our privacy policy.

3.2 Human access to your mail

Our personnel do not read Gmail message content as a matter of course. We access it only when one of the following applies, and only to the extent the situation requires:

  • You explicitly ask us to examine a specific message or conversation to resolve a support issue.
  • It is necessary to investigate a security incident, abuse, or suspected violation of our terms.
  • We are required to by law, such as a valid legal order.

Aggregated and anonymized data that cannot identify you or the contents of your mail may be used for internal operations such as capacity planning.

Where data protection law requires a legal basis, we rely on your consent for connecting a Gmail account and accessing its data, which you give through Google’s consent screen and may withdraw at any time; and on legitimate interests for operating, securing, and troubleshooting the application.

5. Sharing and disclosure

We do not sell personal data, and we do not share Gmail content with third parties for their own purposes. We share data only with the infrastructure providers that run the service on our behalf, listed on the subprocessors page, each bound to process it only on our instructions. We may also disclose data where legally required, or to protect the rights and safety of our members and the public.

If the business is involved in a merger, acquisition, or sale of assets, any transfer of Google user data would be handled in line with the Limited Use requirements, which require prior notice and your explicit consent.

6. Security

These are the protections the application actually implements:

  • OAuth refresh and access tokens are encrypted at rest with AES-256-GCM authenticated encryption, using a key held outside the database. Tokens are never sent to a browser.
  • Data is isolated per organization at the database level using row-level security, so one organization’s mail cannot be read by another. Every API route independently re-checks the caller’s session rather than trusting the client.
  • Data is encrypted in transit using TLS, and all site traffic is served over HTTPS.
  • Message content is sanitized before it is rendered, so mail cannot execute scripts in the application.
  • The OAuth flow uses single-use, server-side, time-limited state tokens to prevent cross-site request forgery and replay.
  • Administrative access to production systems is restricted to the personnel who need it.

No system is perfectly secure, and we do not claim otherwise. Our security practices are described more fully on the security page.

7. Retention

  • OAuth tokens are kept while the mailbox is connected. They are revoked with Google and deleted as soon as the mailbox is disconnected.
  • Synced mail is kept while your account remains active, so the team retains its history of correspondence. Disconnecting a mailbox does not by itself erase mail that was already synced.
  • Deletion requests remove the stored Gmail-derived content as described on the data deletion page, within 30 days of a verified request.
  • Audit and security logs are kept for a limited period for security and accountability, and contain operational identifiers rather than message content.

Deleting data from Unified E box never deletes anything from Gmail. Your mail remains in your Google account exactly as it was.

8. Your choices and rights

  • Withdraw access. Disconnect a mailbox in the application, or revoke Unified E box from your Google Account permissions page. Either stops our access.
  • Request deletion. Ask us to erase the Gmail-derived data we hold for you, through the data deletion process.
  • Access and correction. Depending on where you live, you may have the right to a copy of your personal data, to have it corrected, to restrict or object to certain processing, or to lodge a complaint with a supervisory authority.

To exercise any of these, write to privacy@uniebox.vercel.app. We respond within 30 days.

9. International transfers

Our members work in multiple countries, and our infrastructure providers may process data in regions other than where you live. Where such transfers happen, we rely on the safeguards our providers offer, including standard contractual clauses where applicable.

10. Children

Unified E box is a workplace tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

11. Changes to this policy

If we change how we handle Google user data, we will update this page and the Last updated date above. Where a change materially expands how we use data you have already shared, we will seek your consent before it takes effect, as the Google API Services User Data Policy requires.

12. Contact

Privacy enquiries: privacy@uniebox.vercel.app. Security reports: security@uniebox.vercel.app. Postal address: 1309 Coffene Avenue Sheridan Wyoming 82801.