Privacy Policy
Effective 3 September 2026 · Last updated 3 September 2026
Inboxy reads the things you save, so this page is specific about what that means: exactly what we hold, which companies see it on the way, where it sits, and how you get it back or get rid of it.
1. Who we are
Inboxy AI (“Inboxy”, “we”) is a personal knowledge tool operated by Jellyworkz. Jellyworkz is not an incorporated company; Inboxy is run as an independent project. We are the controller of the personal data described here.
For anything in this policy — access, correction, deletion, or a complaint — write to info@jellyworkz.com.
2. What we collect
Your account
- Your Telegram numeric user ID, and your Telegram username if you have one set. This is how the bot knows which library is yours. We never receive your phone number from Telegram.
- Your email address, only if you choose to sign in to the mobile app by email instead of through Telegram.
- Your settings: interface and summary language, time zone, digest time, summary length and tone, and which plan you are on.
What you send us
This is the substantive part. When you send Inboxy a link, a file, a forwarded post, a note or a voice message, we store:
- the original URL or text you sent;
- the full content we extracted from it — the article text, the video transcript, the text read off screenshots or slides. Not just a summary: the source text is kept so the material can be re-summarised, searched and re-read later;
- the transcript of any voice note you record;
- what the AI produced from it: the one-line essence, the summary, key points, extracted to-dos, the category and tags, and a confidence score;
- a numeric embedding of the content — a long list of numbers that represents its meaning, which is what makes search-by-meaning work;
- fact-check results, if you run one: the analysis, the verdict and the source links it was based on.
How you use it
- Product events: that you saved something, ran a search, opened a digest, exported your data, rated a summary, changed a setting — with a timestamp. These are counters and feature names, stored in our own database. There is no third-party analytics service, no advertising SDK and no tracking pixel anywhere in Inboxy.
- Feedback you send us through the bot, including the text you write and which saved item it was about.
- Errors: when something fails to process we log the URL and the error so we can fix it.
Sign-in and sessions
- One-time login codes, stored only as a hash, valid for 10 minutes.
- App sessions: a hashed session token, whether you signed in by Telegram or email, your device's browser/app user-agent string, and the times the session was created and last used. Sessions last 60 days.
3. Why we process it
To provide the service you asked for — that is the whole of it. Concretely: to extract and summarise what you save, to categorise and index it so you can find it again, to send the digests and reminders you have switched on, to keep you signed in, and to fix the thing when it breaks. Product events are used in aggregate to see which features are actually used and where processing fails.
Where the GDPR applies, our legal basis is performance of a contract with you (running the service you signed up for) and, for the error logs and aggregate usage counters, our legitimate interest in keeping Inboxy working and improving it.
4. What we never do
- We do not sell your data, and we do not share it for anyone's marketing.
- We do not show you ads, and there is no ad network in the product or on this site.
- We do not use your saved content to train our own AI models, and we do not publish it. Your library is visible only to your account.
- We do not use third-party analytics, session recording or tracking pixels.
On training by others: the AI providers listed below process your content to return a result. What they may do with it beyond that is governed by their own terms, which we do not control. We use their standard APIs, not consumer products.
5. Who else sees it
Inboxy is not self-contained — it reads the web and it uses AI models it does not host. The companies below receive some of your data in order to do a specific job. This is the complete list.
| Who | What they receive | What for |
|---|---|---|
| Telegram | Every message between you and the bot, and your Telegram account identifiers | It is the channel Inboxy runs in. Telegram's own privacy policy applies to your Telegram account. |
| The text of the content you save, and your questions | Gemini models produce the summaries, categories, embeddings and answers. The fact-check feature additionally sends search queries derived from your saved content to Google Search. | |
| Groq | The audio of your voice notes, and of videos being transcribed | Speech-to-text transcription. |
| SearchAPI | YouTube video URLs you send | Fetching existing captions, so we don't have to transcribe the audio. |
| Apify | Instagram, TikTok, Facebook and Threads URLs you send | Fetching the post content behind those links. |
| Resend | Your email address, if you use email sign-in | Delivering the one-time login code. |
These providers operate outside Ukraine, including in the United States, so using Inboxy involves international transfers of the data described above. We rely on the transfer terms in each provider's standard data processing agreement.
6. Where it is stored
Your library lives in a PostgreSQL database on a server we rent in Ukraine, alongside a Redis instance used for the processing queue. Traffic between you, the bot and our server is encrypted in transit (HTTPS/TLS). Session tokens and login codes are stored only as hashes, never in a form we could read back.
Being straight with you: this is a small project, not an enterprise platform. There is no formal security certification behind it, and the database is not encrypted at rest. Please do not put material in Inboxy that would seriously harm you if it leaked.
7. How long we keep it
- Saved items and their extracted content: for as long as your account exists.
- Items you delete: deleting an item hides it from your library and from search, but the row is retained so it can be restored and so re-saving the same link behaves sensibly. It is removed for good when your account is deleted, or sooner on request.
- Login codes: 10 minutes.
- Sessions: 60 days, or until you sign out.
- Product events and error logs: kept while the account exists; they are useful only in aggregate.
8. Your rights, and how to use them
If you are in the EU/EEA or the UK, the GDPR gives you the rights below; we will honour them for everyone regardless of where you are.
-
Get a copy of your data. Send
/exportto the bot and it replies immediately with your whole library as JSON and as Markdown. No request, no waiting, no ticket. - Correct it. Titles, categories and tags are editable in the bot and the app. For anything else, email us.
- Delete it. See the note below.
-
Object or restrict. You can switch off digests, reminders and
re-engagement messages in
/settings. For anything broader, email us. - Complain. If you are in the EU/EEA or the UK you may complain to your national data protection authority.
Deletion is not yet self-serve. You can delete individual saved items
yourself, but there is no button that erases your whole account. Until there is, email
info@jellyworkz.com from the address on your
account, or message the bot, and we will delete everything we hold about you — account,
saved items, extracted content, embeddings, events and sessions — within 30 days and
confirm when it is done. Export first with /export; deletion cannot be
undone.
9. The website itself
This website sets no cookies and runs no analytics, so there is nothing to consent to and no banner to dismiss.
It does load fonts from Google Fonts, which means your browser makes a request to Google's servers and Google receives your IP address as part of that. That is the only third-party request the site makes.
Our web server keeps standard access logs (IP address, time, page requested, user agent) for security and troubleshooting.
10. Children
Inboxy is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has used Inboxy, email us and we will remove the account.
11. Changes to this policy
If we change how we handle your data — a new subprocessor, a new kind of data, a different retention period — we will update this page and the “last updated” date at the top. For anything significant we will also tell you in the bot rather than relying on you to re-read this page.
12. Contact
info@jellyworkz.com — for access, deletion, questions or complaints. A person reads it.