This notice explains what Machine Inbox handles when you visit the site, create an inbox, receive mail, or send a reply.
Data we handle
- Inbound and outbound message content, headers, addresses, attachments, timestamps, and delivery status.
- Mailbox identifiers, hashed bearer tokens, quotas, expiration times, and API idempotency records.
- Public blockchain transaction data, including wallet addresses, token amount, network, and transaction hash.
- Security and operational data such as request time, route, error code, and abuse signals. Application logs are designed to exclude bearer tokens, payment signatures, and message bodies.
Why we handle it
We use this data to provide the requested inbox, settle payment, route and store mail, send authorized replies, enforce limits, investigate abuse, secure the service, keep financial records, and meet legal obligations.
Retention
Message content and attachments are scheduled for deletion when the inbox expires, normally after seven days, or after you delete it. Idempotency records expire with the inbox. Application audit events are normally retained for 90 days. Payment and accounting records may be kept for the period required by tax, fraud, and financial-record laws. Cloudflare platform logs and backups may follow separate limited retention schedules.
Service providers and public networks
Cloudflare processes website, Worker, database, object-storage, logging, DNS, and email-delivery data. Stripe processes payment credentials and payment records for paid inbox creation. Machine Inbox stores the resulting Stripe PaymentIntent reference, not card details. Email also passes through the sender’s and recipient’s mail providers.
Disclosure
We do not sell personal information. We may disclose data to service providers, to investigate abuse, to protect rights and systems, in a business transfer, or when law requires it.
Security
Mailbox tokens are returned to the caller and stored as hashes. Access requires the bearer token. No system is perfectly secure, so do not use the beta for secrets, regulated data, or information whose disclosure could cause serious harm.
Your choices
Delete an inbox through the API to revoke its token and start content deletion. Send privacy requests to info@machineinbox.com. Do not submit personal data that requires a formal request channel.
Children
The service is not directed to children under 13, and we do not knowingly collect their personal information.
Changes
We may update this notice. The date above identifies the current version.