Privacy Policy
Covers the website, the newsletter and the Inbox Horizon application.
effective from 16 August 2026
Dear User,
we make every effort to ensure the security and confidentiality of your personal data. We care about your privacy both when you visit the Inbox Horizon website and join the waitlist, and when you create an account in the app, connect your e-mail inbox to it, or simply write to us with a question. We act in accordance with the law, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter: the "GDPR").
In this document we have gathered the most important information about the purposes, legal bases and duration of the processing of your data, whom we entrust it to, and what rights you have. For clarity, we have arranged it in a question-and-answer format.
In short — key information
We care about your privacy, but also about your time, so we start with a summary:
- The controller of your data is MKONDEV Konrad Małocha, with its registered office in Wieliczka. For any matter concerning your data, write to: konrad.malocha@inboxhorizon.com.
- The waitlist and the newsletter operate under a contract for a free newsletter service (you have its Terms) — you conclude the contract by submitting the sign-up form together with your acceptance of the Terms and the Privacy Policy, and you can unsubscribe at any time by writing to our contact address — and, once we start sending messages, also with a single click in any of them. We keep the waitlist itself in our own database hosted by Cloudflare in a European region, and We do not currently use an external sending provider — once we start sending messages, we will name it in the list of processors below. The data remains within the European Economic Area.
- The Inbox Horizon app, once your inbox is connected (IMAP/SMTP), synchronises and processes the content of your messages — solely to provide you with the service: to organise threads, classify them, hide newsletters, and suggest replies. We do not read your mail for any other purpose and we do not sell any data.
- AI features (message classification and reply suggestions) are provided by the external API of Mistral AI, based in France, with data processed by default within the European Union. We use the service on terms under which the content of your messages is not used to train AI models.
- With respect to the content of your inbox (including the data of the people you correspond with), we act as a processor — on your instruction and solely for the purpose of providing the service.
- Website statistics are measured with Google Analytics 4, but only with your consent given in the cookie banner. Without consent, no analytics cookies are stored.
- The app and the database are hosted in the European Union. We entrust data only to trusted entities, listed below in the list of processing entrustments.
If this information is not enough for you — you will find the details below.
Who is the controller of your personal data?
The controller of your personal data is MKONDEV Konrad Małocha, with its registered office at ul. Bajeczna 74, 32-020 Wieliczka, Poland, tax ID (NIP): 6832122113, entered in the Central Register and Information on Economic Activity (CEIDG) (hereinafter: "we").
If you have any questions or doubts, you can contact us by e-mail at: konrad.malocha@inboxhorizon.com.
Note: with respect to the content of mailboxes connected to the app (including the data of the people you correspond with), we do not act as a controller but as a processor. You will find the details in the section "What data do we process as a processor?".
How do we obtain your personal data?
Above all, we receive it directly from you:
- when you join the waitlist or subscribe to the newsletter — you provide your e-mail address in the form on the website;
- when you create an account in the Inbox Horizon app — you provide an e-mail address and set a password;
- when you connect your mailbox — you provide the IMAP/SMTP server details and an app password, and the app begins to synchronise your messages;
- when you contact us by e-mail — you provide us with the sender address and the content of the message.
Providing data is voluntary, but in certain situations necessary: without an e-mail address we cannot add you to the waitlist or create an account for you, and without the access credentials to your mailbox the app will not be able to synchronise it.
Some technical data (e.g. IP address, browser type) is collected automatically in server logs, and — only after you give consent in the banner — also through the cookies of the analytics tool. You will find the details in the sections on cookies and logs.
Independently of the server logs, when you sign up to the waitlist we record the IP address the sign-up was made from, together with the wording and the version of the consent statement shown to you in the form. We do this solely so that we are able to demonstrate what you consented to and when — see point 2 below.
For what purposes, on what legal basis and for how long do we process your data?
We process your personal data for the purpose of:
1. Providing the Inbox Horizon service — that is, concluding and performing a contract for the provision of a service by electronic means: maintaining your account, synchronising the connected mailbox via IMAP/SMTP, organising and classifying threads (including with the use of AI — see the separate section), hiding newsletters, suggesting replies, sending messages and attachments on your behalf, and snoozing threads:
- scope of data: account data (e-mail address, password — stored solely as a cryptographic hash), mailbox access credentials (IMAP/SMTP server details and app password — stored in encrypted form), the content of synchronised messages and attachments together with metadata (senders, recipients, dates, subjects), and AI feature usage events (information on when and for which messages classification or a reply suggestion was triggered),
- the legal basis is the necessity of the processing for the performance of a contract or in order to take steps at your request prior to entering into it (Article 6(1)(b) GDPR),
- we process the data until the provision of the service ends (deletion of the account or termination of the contract); attachments to outgoing messages are stored only transiently — they are deleted immediately after successful sending, and in the event of failure no later than after a short technical period,
- during the beta period the service is free of charge;
2. Running the waitlist and sending the newsletter — that is, performing a contract for a free newsletter service, concluded in accordance with the Newsletter Terms upon your submission of the sign-up form:
- scope of data: e-mail address, chosen language version (Polish or English) and the date of sign-up,
- as evidence that consent was given, we additionally store: the wording of the consent statement shown to you in the form together with its version, the IP address the sign-up was made from, and the date and time of the sign-up and of its last update; the legal basis is our obligation to be able to demonstrate consent (Article 7(1) GDPR) and our legitimate interest in defending against potential claims (Article 6(1)(f) GDPR),
- we keep the waitlist in our own database hosted on Cloudflare infrastructure in a European region; the e-mail address is written to that database at the moment of sign-up and only then passed on to the delivery provider,
- the legal basis is the necessity of the processing for the performance of a contract (Article 6(1)(b) GDPR); by signing up, you separately give consent to receive information by electronic means, as required by the Polish Electronic Communications Law,
- we process the data until you unsubscribe from the newsletter (which terminates the contract) or until we stop sending it; after you unsubscribe, we may retain only the record of the sign-up and the unsubscription for the purpose of defending against potential claims (Article 6(1)(f) GDPR);
3. Answering your questions sent to us by electronic means:
- the legal basis is our legitimate interest (Article 6(1)(f) GDPR) in communicating with users and people interested in the service,
- we process the data for the duration of the correspondence, and then until the limitation periods for potential claims expire;
4. Analysing website traffic (visit statistics, website effectiveness) with the use of Google Analytics 4:
- the legal basis is your voluntary consent (Article 6(1)(a) GDPR), given actively in the cookie banner; until you give it, the tool stores no cookies or identifiers,
- we process the data until you withdraw your consent; statistical data in Google Analytics is retained for 14 months;
5. Establishing, pursuing and defending against potential claims:
- the legal basis is our legitimate interest (Article 6(1)(f) GDPR) in protecting our rights,
- we process the data until the limitation periods for claims under applicable law expire;
6. Fulfilling our obligations in the area of personal data protection (e.g. handling your requests, keeping records of processing activities):
- the legal basis is a legal obligation to which we are subject (Article 6(1)(c) GDPR),
- we process the data until the limitation periods for claims arising from breaches of data protection law expire;
7. Fulfilling tax and accounting obligations (issuing invoices, keeping accounting records) — this purpose will begin to apply once we introduce fees for the service; during the free beta period we do not issue invoices and do not process billing data:
- the legal basis will be a legal obligation to which we are subject (Article 6(1)(c) GDPR),
- the data will be processed until the limitation periods for tax liabilities expire.
REMEMBER! We process personal data for as long as is necessary to achieve the purposes above, unless you submit an effective request for its erasure earlier. The processing period may also follow directly from legal provisions (e.g. those concerning accounting records or limitation periods for claims).
How do we use artificial intelligence?
AI-based features are at the heart of Inbox Horizon, so we describe them plainly:
- What is analysed: the content and metadata of messages from the mailbox you connect.
- What for: to classify threads by urgency (urgent / needs attention / no action), to recognise and hide newsletters, and to propose draft replies to you. AI suggestions are always only proposals — it is you who decides whether and what gets sent.
- Who processes it: classification and suggestions are provided by the external API of Mistral AI (a company based in France, the "La Plateforme" platform), to which we entrust data under a data processing agreement (Data Processing Addendum). Data is processed by default on servers located in the European Union.
- Does the data train models: we use the Mistral AI API on terms under which the input and output data transferred (message content, generated suggestions) is not used to train AI models. In accordance with Mistral AI's policy, data submitted in stateless API requests may be retained for up to 30 days solely for abuse monitoring, after which it is deleted.
- No hidden substitute processing: if the AI service is unavailable, the classification and suggestion features are simply openly unavailable — in such a situation your data is not transferred to any other provider.
- No automated decision-making: message classification only organises the view of your inbox. We do not make any automated decisions about you or your correspondents that would produce legal effects or similarly significantly affect you (Article 22 GDPR).
Who may be a recipient of your personal data?
We use the support of external entities only where it is necessary to achieve the purposes described above. We require every recipient to guarantee appropriate protection and confidentiality of the data, and the entrustment of processing takes place under data processing agreements compliant with Article 28 GDPR.
List of processing entrustments. We entrust the processing of personal data to the following entities:
- ipp.net Krzysztof Taraszka (the Miget platform), al. Powstania Warszawskiego 15, 31-539 Kraków, Poland — for the purpose of hosting the Inbox Horizon app and its database; the data is stored in the eu-east-1 region within the European Union,
- Mistral AI, 15 rue des Halles, 75001 Paris, France — for the purpose of providing the AI features (message classification, reply suggestions); the data is processed by default within the European Union,
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland — for the purpose of website statistics (Google Analytics 4), only after you give your consent,
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA — for the purpose of operating the website and the sign-up form (website hosting, traffic protection) and for the purpose of storing the waitlist in the database we maintain (Cloudflare D1). In that database we store the e-mail address, the language version, the sign-up status, the wording and version of the consent statement, the IP address the sign-up was made from, and the dates of the sign-up and of its update; the database was created in Cloudflare's European region. In addition, technical connection data (e.g. IP address) is processed in connection with operating and protecting website traffic.
All entities to which we entrust the processing of personal data guarantee the application of the data protection and security measures required by law.
Recipients of your data may additionally include: entities supporting our business under separate agreements (e.g. an accounting office — once we introduce fees for the service, IT service providers), authorised public authorities acting on the basis of legal provisions, and other entities whose request for disclosure of data has a basis in applicable law.
Do we transfer personal data to third countries?
As a rule, we process data within the European Union and the European Economic Area: the app and the database are hosted in the EU (Miget, eu-east-1 region), the waitlist database was created in Cloudflare's European region (EEUR), and the Mistral AI API processes data by default on servers in the EU.
The exceptions concern the website:
- Google Analytics 4 — the service is provided by Google Ireland Limited (Ireland), but some data may be transferred to Google LLC in the United States,
- Cloudflare, Inc. — operating and protecting website traffic may involve the processing of technical connection data in the United States; the waitlist database itself, however, is maintained in Cloudflare's European region.
In both cases, the transfer takes place using the mechanisms provided for in the GDPR: the European Commission's adequacy decision for entities certified under the EU-US Data Privacy Framework (Article 45 GDPR), and, supplementarily, the standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR). You will find more information about how these providers process data on their websites.
Do we profile your personal data?
We do not carry out marketing profiling and we do not use your data to personalise advertising. The analytics tool (Google Analytics 4) serves us solely for aggregate website visit statistics — and it operates only with your consent.
Message classification in the app (described in the AI section) only organises the view of your inbox. We do not make any automated decisions that would produce legal effects concerning you or significantly affect you.
What data do we process as a processor?
When you connect a mailbox to Inbox Horizon, we synchronise its contents — which inevitably include the personal data of third parties: your correspondents (their e-mail addresses, names and surnames, the content of messages and attachments). With respect to this data, we are not the controller — we are the processor within the meaning of Article 28 GDPR, acting on the instruction of our customer.
If you use Inbox Horizon within an organisation (a company), your organisation is the controller of the data contained in the connected mailboxes, and we process it solely on its documented instructions, under a data processing agreement forming part of the Terms of Service.
As a processor, we:
- process the entrusted data solely for the purpose of providing the Inbox Horizon service and solely to the extent necessary for that purpose,
- secure it with appropriate technical and organisational measures adequate to the risk (Article 32 GDPR) — including encryption of transmission and isolation of each organisation's data at the database level,
- ensure that persons authorised to process the data have committed themselves to confidentiality,
- engage further processors (sub-processing) solely to the extent described in the list of processing entrustments — mailbox content is concerned by: hosting (Miget) and the AI features (Mistral AI),
- after the provision of the service ends, return the entrusted data to the customer or delete it together with existing copies, unless applicable law requires us to continue storing it.
This data enters our system directly as a result of the mailbox synchronisation initiated by the customer — it is the customer who decides which mailbox to connect and when to disconnect it.
Do we use cookies?
Yes, but only with your active consent — with the exception of what is technically necessary for the website and the app to work (e.g. maintaining your session after logging in).
Cookies are short pieces of text stored on your device, which can be read by our system and, after your consent, also by the systems of the providers whose services we use.
The principles we follow:
- By default: no consent. On your first visit to the website we display a banner in which you can consent to analytics cookies or refuse. Until you give consent, Google Analytics stores no cookies or identifiers — only anonymous technical signals stripped of identifiers reach the tool (Consent Mode v2). Merely continuing to use the website is not treated as consent.
- Consent is revocable. You can withdraw or change it at any time by clicking the "Cookie settings" link in the website footer. Withdrawing consent does not affect the lawfulness of processing carried out before its withdrawal. You can also always delete or block cookies in your browser settings.
- After you give consent, Google Analytics 4 stores statistical cookies which give us aggregate data about visits (number of visits, pages viewed, approximate time on the site). This data is retained for 14 months.
We do not use advertising pixels (e.g. the Meta/Facebook Pixel) or marketing cookies.
Does using the service involve the recording of server logs?
Yes. Using the website and the app involves sending requests to the server. Every request is recorded in server logs, which include, among other things, the IP address, the date and time, and information about the browser and operating system.
We do not link log data to specific individuals and we do not use it to identify you. The logs serve solely to administer the service and to diagnose errors and abuse, and access to them is limited to persons authorised to administer the server.
How do we protect your data?
We apply safeguards adequate to the nature of the data processed — and we process data that is particularly sensitive from a privacy perspective, as it includes the content of correspondence. The measures we apply include, among others:
- encryption of transmission with the TLS protocol (website, app, connections to mail servers),
- storing account passwords solely as a cryptographic hash,
- storing IMAP/SMTP credentials (app passwords) in encrypted form,
- isolation of each organisation's data at the database level (a Row-Level Security mechanism) — one customer's data is not accessible to others,
- automatic deletion of outgoing message attachments immediately after sending,
- restricting access to data solely to authorised persons,
- creating backups,
- security monitoring and incident response,
- hosting in data centres located in the European Union.
What rights do the persons whose data we process have?
You have the right to:
- access your personal data,
- rectification of your data,
- erasure of your data,
- restriction of processing,
- object to processing,
- data portability,
- withdraw your consent to processing (where consent is the basis of processing) — with the proviso that withdrawing consent does not affect the lawfulness of processing carried out before its withdrawal.
These rights are not absolute — in some situations, after carrying out an assessment, we may lawfully refuse to fulfil them (e.g. where legal provisions require us to continue storing the data).
To exercise your rights, write to: konrad.malocha@inboxhorizon.com. We will respond without undue delay, no later than within one month of receiving your request. If, due to the complex nature of the request or the number of requests, we are unable to meet this deadline, we will inform you of an extension — by a maximum of a further two months.
Important — requests concerning mailbox content. If you are a correspondent of our customer (your data is in a mailbox connected to Inbox Horizon by someone else), the controller of that data is our customer — and requests should be directed to them. Requests of this kind that we receive will be forwarded to the relevant customer, and we will support their fulfilment in accordance with the data processing agreement.
How can you complain about irregularities in data processing?
If you believe that we process your personal data unlawfully, you can lodge a complaint with the President of the Personal Data Protection Office (PUODO, the Polish supervisory authority) (ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl).
Can we change our Privacy Policy?
Yes. The protection of personal data is a process that we adapt to the development of the service and changing technology — for example, once we introduce fees for the service, we will update the information about billing purposes. We will announce changes by publishing an updated version on the website, and we will additionally notify registered users and newsletter subscribers of material changes by electronic means.