Your data security is our priority
Inbox SuperPilot is built with security-first principles. We protect your emails, documents, and knowledge base with industry-leading security practices.
Encryption Everywhere
All traffic is encrypted in transit (TLS 1.2+, with TLS 1.3 where supported). OAuth tokens and credentials are encrypted at rest (AES-128 via Fernet) and are never stored unencrypted.
Isolated Data Storage
Each user's knowledge base is stored in isolated environments. There's no cross-user data access, ever.
No Model Training
Your data is never used to train AI models. We use commercial AI APIs that do not retain inputs for training.
Minimal Data Retention
Raw email content is processed in real-time and cached for at most one hour, never stored. We retain only derived data — subjects, summaries, extracted facts, embeddings — for up to 90 days, deletable anytime and erased when you delete your account.
Compliance Roadmap
Our infrastructure is built on AWS with enterprise security controls. SOC 2 Type II certification is on our roadmap.
Access Controls
Role-based access control, SSO/SAML support for teams, and audit logs for enterprise compliance.
Compliance & Data Rights
| Framework | Status |
|---|---|
| SOC 2 Type II | Planned — on our roadmap |
| GDPR data-subject requests | Supported — export or delete your data anytime |
| CCPA data-subject requests | Supported — export or delete your data anytime |
Infrastructure & Technology
How Your Data Flows
You connect your knowledge base
Documents from Google Drive, Notion, or file uploads are securely transferred using OAuth 2.0 and encrypted connections.
Content is processed and indexed
Documents are chunked, embedded, and stored in your isolated vector database. Original files are not retained.
Email context is analyzed
When you request a draft, email content is sent to our AI providers for real-time inference. Raw content is cached for at most one hour, then discarded; only derived summaries and extracted facts are retained.
Draft is generated and delivered
The AI-generated reply is sent directly to your browser. Drafts you review are retained for up to 90 days to improve your writing profile; raw email content is not persisted.
Contact our security team at security@inboxsuperpilot.com
For vulnerability reports, please use responsible disclosure.