Privacy policy
Your inbox is not our business model.
TidyInbox uses the minimum data needed to run your cleanup rules and manage your plan. It does not sell Gmail data or use it for advertising.
Effective September 28, 2026
The short version: Gmail processing stays inside Google Apps Script. TidyInbox does not store message bodies, and Gmail-derived data is not sent to the billing service.
1. Scope
This policy covers the TidyInbox Google Workspace add-on, the optional TidyInbox Chrome extension, this website, and TidyInbox billing and entitlement services.
2. Data we handle
Google account and Gmail data
With your permission, TidyInbox can access Gmail search results, thread identifiers, and Gmail label metadata so it can preview and run the rules you create. It can archive, mark read, star, label, or move matching threads to Trash. TidyInbox does not request, store, or transmit message bodies.
TidyInbox also uses Google authorization to operate inside Gmail, create or remove your approximately-hourly automation trigger, and obtain a stable Google account identifier for checking your plan. The raw Google account identifier and identity tokens are not stored by the billing service.
Rules and add-on settings
The add-on stores the following in your private Google Apps Script user properties:
- rule names, Gmail search criteria, selected actions, and enabled state;
- automation preference and managed trigger metadata;
- aggregate cleanup status, such as completion time, processed-thread count, and failure count;
- a cached billing entitlement; and
- a Gmail query sent by the optional extension, which expires after one hour and is removed after it is consumed.
Chrome extension data
The optional extension reads the active Gmail search from the current Gmail tab when you choose to start a rule. It sends that query to your TidyInbox Apps Script account. It does not send the query to the billing service or use it for advertising.
Billing data
When billing features are used, TidyInbox stores a pseudonymous account ID, Stripe customer and subscription identifiers, plan and price identifiers, subscription status and dates, checkout coordination records, entitlement status, and minimal webhook processing records. Webhook receipts are configured to expire after 90 days.
Stripe collects and processes the payment, billing contact, tax, and transaction information needed for checkout and subscription administration. TidyInbox does not receive or store complete payment-card details.
Website data
These static pages do not include advertising, analytics, tracking scripts, or application-set cookies. Hosting providers may process standard network and security logs as part of operating their services.
3. How data is used
Data is used only to:
- create, preview, save, and run the cleanup rules you request;
- schedule and report the status of automatic cleanup;
- transfer a Gmail search from the optional extension to the add-on;
- verify your Google account and provide the correct Free or Pro features;
- process subscriptions, prevent duplicate checkout sessions, reconcile billing events, and provide customer support; and
- protect, troubleshoot, and maintain the service using privacy-limited operational logs.
TidyInbox does not sell Google user data, use it for targeted advertising, or use it to determine creditworthiness. Human access to Google user data is not permitted except with your affirmative agreement for support, when required for security or legal reasons, or where otherwise allowed by Google's policies.
TidyInbox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Retention and deletion
Rules and add-on settings remain in your Google Apps Script user properties until they are replaced or deleted. A pending extension query expires after one hour and is removed after use. Disabling automation removes the managed trigger; removing a rule removes it from the saved rule set.
Billing and entitlement records are retained while needed to provide a subscription, reconcile transactions, prevent fraud, meet accounting or legal obligations, and resolve disputes. Minimal Stripe webhook receipts are scheduled for deletion after 90 days, although deletion can occur later because it is asynchronous. Stripe may retain records under its own legal and service obligations.
To request deletion of TidyInbox-controlled account or billing records, use the support contact below. Some billing records may be retained where required by law. Uninstalling the extension or revoking Google access does not automatically delete billing records held by TidyInbox or Stripe.
6. Security
TidyInbox uses Google authorization, encrypted HTTPS connections, restricted service access, secret management, server-side validation, and private database rules. Billing records use a keyed pseudonymous account identifier rather than a stored raw Google account ID. No method of storage or transmission is completely secure, but access and data are limited to what the service needs.
7. Your choices
- Preview a rule before running it.
- Disable a rule or delete it from the add-on.
- Disable automation from TidyInbox to remove its managed trigger.
- Disconnect the optional extension from its settings page.
- Revoke TidyInbox access from your Google Account security settings.
- Request deletion of TidyInbox-controlled billing or account records through support.
8. Children's privacy
TidyInbox is a productivity tool for Google account holders and is not directed to children under 13. It does not knowingly collect personal information from children.
9. Changes to this policy
This policy may be updated as TidyInbox changes. The effective date above will be revised when material changes are published. Where required, additional notice will be provided.
10. Contact
For privacy questions, support, or deletion requests, open a request in the TidyInbox support tracker. Do not include message content, payment-card details, identity tokens, or other sensitive information in a support request.