This Privacy Policy explains how Lowside Labs, Inc., operating Intray ("Intray", "we", "us", or "our"), collects, uses, and shares information about you when you use our website, our applications, and related services (collectively, the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.
Information We Collect
We collect the following categories of information:
- Account information. When you create an account, we collect your name, email address, and a password (or, if you sign in with Google, the profile information Google shares with us — your name, email address, and profile picture).
- Workspace and email data. Information you and your team create or process within the Service, including connected domains and addresses, email messages, drafts, attachments, settings, and related delivery metadata.
- Usage and device information. Information about how you interact with the Service, such as log data, IP address, browser and device type, and pages viewed. We use this to operate, secure, and improve the Service.
Connected Mailboxes
A workspace owner can connect an existing mailbox to Intray over IMAP. We store the connection settings (server, port, username) and the mailbox password in encrypted form, and we copy mail from the folders the owner selects.
Copies include message headers, sender and recipient addresses, subjects, plain-text and HTML bodies, attachment files, message flags, and folder position. They cover mail already in those folders, not only new arrivals.
Selecting folders limits what we import. It does not limit what the credential can reach: a mailbox password normally grants access to the entire mailbox at your provider. Connect only a mailbox you are authorized to make available to your workspace.
Imported mail is readable by every member of that Intray workspace, including members added later, and they can open every attachment.
Your existing provider keeps receiving your mail. Intray holds a copy and does not replace your provider.
We store imported messages, bodies, and attachments in our application database and file storage, and we index message text so you can search it. Our infrastructure providers are listed on our Subprocessors page.
Sending Through Your Own Mail Server
If you configure a connected mailbox to send over SMTP, we connect to the mail server you specify and hand it the message. That mail goes through your provider rather than through the email infrastructure Intray operates.
Scheduling and Google Calendar
If you set up a booking page, you authorize Intray to use your Google Calendar. That authorization is separate from signing in with Google and is something you do in workspace settings. It grants three things: the list of your calendars and your access to them, the busy times on the calendars you select, and the ability to create, read, update, and delete the booking events Intray puts on your destination calendar. We do not request access to Gmail.
From the calendars you select we read busy times only: the start and end of a period you are unavailable. We do not read, store, or receive the titles, descriptions, guests, locations, or attachments of any event we did not create. For events Intray created, we hold the event identifier, the calendar it is on, the meeting time, and the Google Meet link.
We store the access tokens for your Google account encrypted, and no part of the Service returns them to a browser. One authorization belongs to you rather than to a workspace, so disconnecting it affects every workspace where you host. Disconnecting removes the stored tokens and pauses your booking pages. It does not delete calendar events that already exist.
Intray's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Booking Guests
When someone books a meeting through one of your booking pages, they give us their name, their email address, their time zone, and an optional note. That is everything we store about a guest. We use it to create the calendar event, to send the guest a confirmation and any reminders, and to let the guest cancel or reschedule from a private link.
Google sends the calendar invitation. Intray sends the confirmation, reminders, and messages about changes or cancellations, from the sending address the host chose. A booking becomes a conversation in the host workspace, so members of that workspace can read the guest's details and note.
The link a guest uses to manage their booking is a high-entropy token. We store only a hash of it, so a database read does not yield a working link.
We keep a guest's details for as long as the booking exists in the workspace. Deleting the customer record removes the guest's name, email address, and note, and keeps the meeting time so the host's history stays intact. Deleting the workspace removes its bookings with it. Backup copies are removed when that backup expires on its own schedule, as described under Data Retention.
AI Features
Some features send the content of your mail to third-party model providers so they can draft replies, judge automation rules, or answer questions about a thread. This happens when you use an AI feature or enable an automation rule that uses one. It can include mail imported from a connected mailbox.
We use Anthropic, OpenAI, and Google as model providers. We do not use your mail to train our own models. Importing mail does not by itself trigger any AI processing or automated reply.
How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Service;
- Authenticate you and secure your account;
- Send transactional communications, such as account, security, and support messages;
- Monitor and analyze usage and trends to improve the user experience; and
- Detect, prevent, and address fraud, abuse, security, or technical issues.
Google Sign-In
If you choose to sign in with Google, we request only the basic profile scopes (email, profile, and openid). We use this information solely to create and authenticate your account. Signing in with Google does not give Intray access to your Gmail, Drive, contacts, or calendar, and we do not sell or share this information with third parties for advertising.
Connecting a mailbox is separate. If you connect a Gmail or Google Workspace mailbox over IMAP, you supply a mailbox password or app password directly to us, and we import mail from the folders you select. That is a distinct action you take in workspace settings, not something Google Sign-In enables.
Connecting Google Calendar is separate too, and is a further authorization you give in workspace settings. See Scheduling and Google Calendar above.
How We Share Information
We do not sell your personal information. We share information only in the following limited circumstances:
- With your workspace. Content you create is visible to other members of your workspace as part of the Service's normal operation.
- With service providers. We use third-party providers for hosting, storage, email delivery, analytics, and AI processing. They process information on our behalf under written terms. Our current providers are listed on our Subprocessors page. We update that page before a new provider begins processing customer data.
- With Intray staff. A small number of authorized staff can access workspace content, including imported mail, when needed to operate the Service, investigate abuse, or provide support you request. Access is limited to those purposes.
- For legal reasons. We may disclose information if required to do so by law or in response to valid legal process.
- In a business transfer. If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
Email Delivery and Safety
To send, receive, and protect email, we process message content, sender and recipient addresses, delivery events, bounces, complaints, and similar technical data. We may use email infrastructure providers to deliver messages and use delivery signals to prevent abuse and protect sending reputation.
Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. We will delete or anonymize your information when it is no longer needed, subject to legal and operational retention requirements.
We keep imported mailbox content for as long as the workspace exists. Disconnecting a mailbox erases the stored credential and stops all further access to your provider. It does not delete mail already imported. A workspace owner can delete imported mail from workspace settings, and deleting the workspace removes its mail with it.
We keep encrypted backups of our database and file storage. We cannot remove an individual message from a backup that has already been written. When we delete data at your request, we delete it from the live service; copies held in a backup are removed when that backup expires on its own schedule.
We may retain a minimal record of a recipient address, suppression reason, and related delivery event when necessary to prevent further delivery following a hard bounce, complaint, unsubscribe request, or abuse report. This safety record may be retained after related message content or account data is deleted.
Security
We use industry-standard technical and organizational measures to protect your information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Mailbox credentials. Your mailbox password is encrypted in your browser before it is sent to us, and we store only the ciphertext. No Intray API returns it. Our systems decrypt it in memory when connecting to your mail server, so we can read the mail that credential reaches.
Imported mail is encrypted in transit and at rest. It is not end-to-end encrypted. Intray can read it, and so can every member of your workspace.
To report a suspected security issue, contact us at security@intray.ai.
Your Rights
Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. We will honor valid requests as required by applicable law.
Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we collected this information, we will take steps to delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
Contact Us
For privacy questions or requests, contact us at privacy@intray.ai.