Privacy policy
Last updated: 27 September 2026
In short: To-inbox has no server of its own, no user accounts, no ads and no tracking. What you share goes straight from your phone to your own Gmail. Your settings stay on your device.
1. Who we are
To-inbox is an app by Dennis Smit ("the developer"). Questions about this policy can be asked through the contact form.
2. What data the app processes
- Sign in with Google. If you choose this, the app only requests permission to send email on your behalf (Gmail scope
gmail.send). It cannot read, delete or manage your email. Access is managed by Google on your device and used only to send the messages you share or create. - Gmail address and app password. If you choose an app password, your address and that password are stored only on your device. The password is encrypted with a key in the Android Keystore and used only to sign in to Gmail's mail server.
- What you share or type. Links, text, photos, videos, files and reminders are sent as email to the address you set. Temporary copies of attachments are deleted from your device after sending.
- Recently sent. The app keeps a short list of the last three sent items on your device so you can find them quickly.
- Note when sharing. If you add a short note when sharing, it appears at the top of the email. The note is not stored anywhere other than in that email.
- A different recipient address. If you enter an email address other than your own Gmail under Account, the app sends directly there. From that point on, that service's own terms and privacy policy apply to what happens with your data there; To-inbox has no influence over that, and stores that address only on your own device.
- Scheduled items. For a scheduled reminder or link, the app remembers on your device the time, label, a short description and any attachments, so you can find, change or delete them in the overview.
- Notifications. If you turn this on, the app shows a notification once a scheduled reminder has been sent. This notification is created only on your own device and is never sent anywhere.
- Attachments. Photos and files you share or add are stored temporarily on your device until they have been sent. They are then deleted; leftovers from failed sends are cleaned up after 30 days at most.
- Photos with reminders. If you add a photo, you pick it yourself through Android's file picker. The app only gets access to that one photo.
- Backup file. If you make a backup, your Gmail address, recipient, labels and preferences are saved to a file in a location you choose. Your password is not included.
- Purchases. If you buy To-inbox Pro or make a donation, Google Play handles the payment. The app only stores on your device whether Pro is unlocked, and checks this with Google Play. The app never sees or stores payment details.
- Settings. Such as recipient, subject prefix, labels, language and theme. These stay on your device.
The developer does not receive or store any of this data.
3. Third-party services
- Google (Gmail and Google sign-in). Your emails are sent through the Gmail API or Gmail's secure mail server and arrive in your own mailbox. Google's privacy policy applies.
- Google Play (payments). To-inbox Pro purchases and donations are handled entirely by Google Play Billing. Google's privacy policy applies.
- The website you share. For a link preview the app fetches the page's title, description and image, just like your browser would. The app identifies itself openly as To-inbox when doing so.
- Contact form on this website. If you send a message through the contact form, your name, email address and message are delivered to the developer by email by To-inbox's own web server. No external service is involved and messages are not stored in a database. The data is used only to answer your question. Like any web server, it temporarily keeps technical log files (such as IP address and time) for security.
- Cloudflare Turnstile (spam protection). To protect the contact form against spam, this website uses Cloudflare Turnstile. Only when you reach the form does Cloudflare check, based on technical details of your browser and your IP address, that you are human. This data is used only for that purpose. See the Cloudflare Turnstile privacy policy.
- WordPress mShots (Automattic). If the Website screenshots option is on and a page has no image of its own, the app requests a screenshot from mShots. Only the web address is passed on. See Automattic's privacy policy.
4. Use of Google user data
To-inbox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is not used for advertising, not sold and not read by humans.
5. What the app does not do
- No ads and no advertising ID.
- No analytics or tracking services.
- No selling or sharing of data, other than as described above to make the app work.
- No access to your contacts, location or photo library. The app only sees what you share to it.
6. Security
The app password is stored encrypted (AES-256-GCM, Android Keystore) and is excluded from backups. Connections to Google are encrypted.
7. Children
The app is not intended for children under 13 and does not knowingly collect data from children.
8. Changes
This policy may be updated when the app changes. The date at the top shows the latest revision.
Deleting your data
Because To-inbox has no server and no accounts, all your data lives on your own device and in your own mailbox. To remove everything:
Clear app data
Android Settings > Apps > To-inbox > Storage > Clear data, or uninstall the app.
Revoke access
Go to myaccount.google.com > Security and remove To-inbox under third-party apps, or revoke your app password.
Clean up emails
Sent messages are in your own Gmail. Delete them there like any other email.