MyColdInbox

Privacy Policy

Last Updated: August 18, 2026

1. Introduction

This Privacy Policy describes how Clustox LLC, doing business as MyColdInbox ("MyColdInbox," "we," "our," or "us"), collects, uses, stores, and protects information about you when you visit our website at mycoldinbox.com (the "Site") or use our unified team inbox platform and associated services (collectively, the "Services"). MyColdInbox is operated by Clustox LLC, a Delaware limited liability company, with its registered address at 8 The Green, STE A, Dover, DE 19901, United States.

Our Services allow teams to connect multiple email accounts — including Gmail, Google Workspace, Microsoft Outlook, Office 365, and other IMAP mailboxes — into a single shared workspace, so that replies to outbound campaigns can be read, assigned, annotated, answered, and tracked from one place. Delivering this functionality necessarily involves accessing, syncing, and storing email message content and metadata from the mailboxes you connect, strictly within the scope you authorize.

MyColdInbox is not a sending or sequencing tool. We do not run outbound campaigns on your behalf, we do not provide a leads database, and we do not perform contact enrichment or list building. We do not send email to any recipient except when you or a member of your workspace composes and sends a reply through the Services.

All data collected through the Services is stored and processed on servers located in the United States.

Please read this Privacy Policy carefully before using the Services. By accessing or using the Services, you acknowledge that you have read, understood, and agreed to this Privacy Policy. If you do not agree, please discontinue use of the Services. Your use of the Services is also governed by our Terms of Use, which are incorporated herein by reference.

2. Information We Collect

We collect information in the categories described below.

2a. Personal Data

When you register for an account, create or join a workspace, subscribe to a plan, or contact us, we collect personal data you provide directly, including:

  • Full name
  • Email address
  • Workspace or organization name
  • Company name and role (if provided)
  • Phone number (if provided)
  • Billing information and billing address; payment card processing is handled exclusively by Stripe, Inc., and we do not store full card numbers on our systems
  • Account credentials, including hashed passwords
  • Mailbox connection details for each inbox you connect. Depending on the provider, this is either (a) the mailbox email address, IMAP and SMTP server settings, and the app password or mailbox password you supply, or (b) OAuth access and refresh tokens issued by your provider when you authorize our application. All such credentials and tokens are stored in encrypted form and used solely to provide the Services
  • Any other information you voluntarily submit through support requests, surveys, or direct communications

2b. Usage Data

When you use the Services, we automatically collect technical and behavioral data to operate, maintain, secure, and improve the platform, including:

  • IP addresses and approximate geographic location derived from IP
  • Browser type, version, and language preferences
  • Device and operating system identifiers
  • Pages visited, features accessed, and actions taken within the platform
  • Date, time, and duration of sessions
  • Referring URLs and navigation paths
  • Error logs and diagnostic data
  • Aggregate workspace metrics such as number of connected inboxes, thread volume, assignment counts, and response times

2c. Email Account and Message Data

To deliver the core function of the Services, we access the mailboxes you connect and sync message data into your workspace. This may include:

  • Message content, including subject lines, message bodies, and quoted thread history
  • Message metadata, including sender and recipient addresses, display names, timestamps, message IDs, and threading headers
  • Attachments and attachment metadata, where you have enabled attachment sync
  • Folder, label, and read/unread status information needed to sync accurately and avoid duplication
  • Messages you compose and send from within the Services

We access and store this data solely to provide the user-facing features of the Services — presenting a unified reply feed, threading conversations, enabling assignment and collaboration, allowing you to reply, and maintaining status and audit history. We do not use your mailbox contents for advertising, we do not sell them, and we do not use them to build or enrich any product dataset, mailing list, or contact database.

Because the Services are a shared workspace, message data synced from an inbox you connect will be visible to other members of your workspace in accordance with the roles and account-level permissions configured by your workspace administrator. You are responsible for configuring those permissions appropriately and for ensuring that the mailboxes you connect are ones you are authorized to connect.

2d. Team and Collaboration Data

Where you use collaboration features, we collect and store the content you and your teammates generate in the platform, including:

  • Internal notes and comments on conversations
  • Thread assignments and reassignments
  • Status changes (for example, Open, Pending, Closed)
  • Activity log entries, including which user performed which action and when
  • Workspace configuration, roles, invitations, and per-account access settings

2e. Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar tracking technologies on the Site. The categories we use are:

Strictly Necessary Cookies. Essential for the Site and Services to function and cannot be disabled. They enable user authentication, session management, and security. Third-party providers in this category may include our cloud infrastructure and payment providers.

Analytics and Performance Cookies. These cookies help us understand how users interact with the Site, such as which pages are visited most frequently. We may use third-party analytics providers such as Google Analytics. You may opt out of analytics cookies through our cookie preference center or your browser settings.

Marketing and Advertising Cookies. These optional cookies enable us and our advertising partners to deliver relevant advertisements and measure campaign effectiveness. You may disable these through our cookie consent mechanism.

You can manage cookie preferences at any time through our cookie consent tool or via your browser settings. Further detail is available in our Cookie Policy. For general guidance on managing cookies, visit www.allaboutcookies.org. Note that disabling certain cookies may affect Site functionality.

3. Our Role: Controller and Processor

Our role under data protection law depends on the data in question.

We act as a controller in respect of account, billing, workspace administration, support, marketing, and usage data relating to you as our customer and to the individual users in your workspace. This Privacy Policy governs that processing.

We act as a processor (or service provider) in respect of the message content and contact information contained in the mailboxes you connect — including personal data relating to the prospects, candidates, customers, and other third parties who correspond with you. You are the controller of that data. We process it only on your instructions and as necessary to provide the Services, and we do not use it for our own purposes.

4. Personal Data of Third Parties in Your Mailboxes

The Services necessarily process personal data about people who are not our customers — for example, individuals who reply to your outbound campaigns. As the controller of that data, you are responsible for:

  • Having a valid lawful basis for your outbound communications and for the processing you instruct us to perform
  • Providing any notice and honoring any rights requests owed to those individuals under applicable law
  • Complying with applicable anti-spam and electronic marketing law, including the CAN-SPAM Act, CASL, the GDPR, and the ePrivacy Directive as implemented in your and your recipients' jurisdictions
  • Ensuring you are authorized to connect each mailbox and to make its contents available to the members of your workspace

If we receive a rights request directly from a third-party data subject relating to data in your workspace, we will, where permitted by law, refer that person to you and provide you with reasonable assistance in responding.

5. Mailbox Connections and Access to Your Email

5a. How Mailboxes Are Connected

The connection method depends on your email provider.

Gmail, Google Workspace, and other IMAP mailboxes. You connect these by supplying the mailbox email address, the applicable IMAP and SMTP server settings, and an app password issued by your email provider. This also applies to mailboxes on custom domains and other providers that support IMAP access.

We strongly recommend generating a dedicated app password for MyColdInbox rather than supplying your primary account password. An app password can be revoked independently at any time from your provider's account settings without changing your main credentials. We never receive or store your Google account password when you connect using an app password.

Microsoft Outlook and Office 365. You connect these through OAuth using the Microsoft identity platform. You authenticate directly with Microsoft and grant our application permission to access the mailbox; we never see or store your Microsoft account password. We receive only an access token and a refresh token, which allow our systems to connect to the mailbox you authorized.

In both cases, credentials and tokens are encrypted at rest, are never transmitted to any third party, and are used solely to authenticate to the specific mailbox you designated.

5b. What We Access, and the Limits on That Access

Using the credentials you supply, our systems connect to the mailbox in order to:

  • Read messages and threads, so they can be synced into your MyColdInbox workspace and presented in a unified reply feed
  • Read message metadata, folder structure, and read/unread state, so conversations thread correctly and messages are not duplicated on repeat syncs
  • Send messages from the mailbox when you or a member of your workspace composes and sends a reply through the Services
  • Update message state — such as marking a message read — where you enable two-way sync, so actions taken in MyColdInbox are reflected in the mailbox

We limit our own use of this data as follows:

  • We use mailbox data only to provide and improve the user-facing features of the Services that are prominent in the product experience.
  • We do not transfer mailbox data to third parties except to the service providers listed in Section 9b who are necessary to operate the platform, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not use or transfer mailbox data for advertising of any kind, including retargeting, personalized, or interest-based advertising.
  • We do not export your contacts, and we do not compile the addresses in your mailboxes into any database, list, or dataset of our own.
  • We do not permit our personnel to read the contents of your mailboxes except (a) with your specific affirmative agreement, (b) where necessary for security purposes such as investigating abuse or a suspected incident, (c) where necessary to resolve a support request you have raised, (d) to comply with applicable law, or (e) where the data has been aggregated and anonymized. Such access is limited to authorized personnel and is logged.

Where you connect a Microsoft Outlook or Office 365 account, our use of data received through Microsoft APIs is limited to the purposes described in this section and complies with the applicable Microsoft API terms of use and limited-use requirements. We request only the permissions needed to sync messages, send the replies you compose, and update message state where you enable two-way sync. We do not access your Microsoft calendar, files, directory, or any service other than the mailbox you authorized.

5c. AI and Machine Learning Restrictions

We do not use the contents of your connected mailboxes—including message bodies, attachments, headers, or metadata—to train, develop, or improve generalized AI or machine-learning models.

We may process mailbox data to provide and improve features for you, including AI-powered features such as message analysis, classification, summarization, response assistance, and personalization. Where permitted, personalization based on mailbox data is limited to features provided to the applicable user or account and is not used to train generalized models for other users.

For data obtained through Google Workspace APIs, our use and transfer of such information complies with the Google API Services User Data Policy, including its Limited Use requirements.

5d. Disconnecting a Mailbox

You may end our access to a mailbox at any time by:

  • Disconnecting the inbox from your MyColdInbox workspace, which immediately stops all automated access and deletes the stored credentials or tokens for that mailbox;
  • For Gmail, Google Workspace, and other IMAP mailboxes, revoking the app password from your email provider's account settings, which immediately invalidates our ability to authenticate to that mailbox; or
  • For Microsoft Outlook and Office 365 mailboxes, removing MyColdInbox from your Microsoft account permissions at https://myaccount.microsoft.com/consent-management, which immediately revokes the tokens issued to our application.

Message data already synced into your workspace is handled as described in Section 10 (Data Retention); you may request its deletion at any time.

6. Artificial Intelligence Features

Where the Services offer AI-assisted functionality — for example, reply drafting, summarization, or categorization — the following applies:

  • These features run only when you invoke them, on the specific conversation you are working in.
  • Content submitted to an AI provider for these features is processed solely to return output to you, under contractual terms that prohibit the provider from retaining the content beyond what is needed to serve the request and from using it to train or improve their models.
  • Your mailbox contents are not submitted to any AI provider in bulk, in the background, or for any purpose other than fulfilling a feature request you initiated.
  • We do not use your mailbox contents to train our own models.

7. How We Use Your Information

We process your information for the following purposes:

  • Providing and operating the Services, including account and workspace management, mailbox connection, message sync, unified reply display, assignment, notes, status tracking, and activity logging
  • Sending messages from your connected accounts when you or a member of your workspace composes and sends a reply
  • Processing payments and managing billing through Stripe, including invoices, subscription management, and transaction communications
  • Responding to support requests, inquiries, and technical issues
  • Sending transactional communications, such as account confirmations, invitations, password resets, security alerts, sync failure notices, and service notifications
  • Sending marketing communications about our Services, feature updates, and promotions where you have opted in or where we have a legitimate interest — you may opt out at any time via the unsubscribe link in our emails or by contacting support@mycoldinbox.com
  • Analyzing usage patterns and platform performance, using aggregated and de-identified data, to improve, optimize, and develop features
  • Detecting and preventing fraud, abuse, security incidents, and violations of our Terms of Service
  • Complying with applicable legal obligations, including responding to lawful requests from regulatory or law enforcement authorities
  • Enforcing our agreements and protecting the rights, safety, and property of MyColdInbox and its users

We do not sell or rent your personal data to third parties. We do not use the contents of your connected mailboxes for advertising or to train AI models.

8. Legal Basis for Processing (GDPR)

MyColdInbox is actively working toward full compliance with the EU General Data Protection Regulation (GDPR) and the UK GDPR. Where these regulations apply — that is, where you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland — we process personal data for which we are the controller on one or more of the following legal bases:

  • Contractual Necessity: Where processing is necessary to perform the contract we have with you — for example, providing access to the Services, connecting your mailboxes, syncing your replies, managing your subscription, and processing billing.
  • Legitimate Interests: Where we have a legitimate business interest that is not overridden by your rights — for example, improving our Services, preventing fraud and abuse, monitoring platform performance and security, and sending marketing communications to existing customers.
  • Legal Obligation: Where processing is necessary to comply with applicable laws and regulations, including tax, accounting, and data protection obligations.
  • Consent: Where required — for example, setting non-essential cookies or sending marketing communications to prospective customers. You may withdraw consent at any time without affecting the lawfulness of prior processing.

Where we act as a processor in respect of your mailbox contents (see Section 3), you are responsible for establishing the lawful basis for that processing.

For questions about the specific legal basis applicable to a processing activity, contact us at support@mycoldinbox.com.

9. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data. We may share your information only in the following limited circumstances:

9a. Within Your Workspace

Message data, notes, assignments, statuses, and activity history are shared with other members of your workspace according to the roles and per-account permissions your administrator configures. Workspace administrators may be able to view activity and content across all connected accounts in the workspace.

9b. Service Providers

We engage trusted third-party service providers to perform functions on our behalf. These providers are granted access to information only as necessary to perform their services and are bound by contractual data protection obligations. Current categories of service providers include:

  • Payment processing — Stripe, Inc. (payment card handling; we do not store full card numbers)
  • Cloud infrastructure, hosting, and database providers
  • Email delivery providers used for our own transactional and marketing email
  • Error monitoring, logging, and application performance tools
  • AI providers supporting the features described in Section 6
  • Customer support and helpdesk platforms
  • Analytics and product usage tools

9c. Legal and Regulatory Requirements

We may disclose personal data to government authorities, law enforcement, or other third parties if required by applicable law, court order, subpoena, or regulatory requirement. We may also disclose data where we in good faith believe disclosure is necessary to protect the rights, property, or safety of MyColdInbox, our users, or the public.

9d. Business Transfers

In the event of a merger, acquisition, asset sale, reorganization, or similar corporate transaction involving Clustox LLC, your personal data may be transferred to a successor entity. We will provide reasonable notice before your personal data becomes subject to a materially different privacy policy.

9e. With Your Consent

We may share your information with third parties where you have given explicit consent to such sharing.

10. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Our specific retention practices are:

  • Account and Workspace Data: Retained for the duration of your active account. Following account deletion, we retain core account records for up to 3 years to comply with legal, tax, and dispute-resolution obligations, unless a longer period is required by law.
  • Mailbox Credentials and OAuth Tokens: Stored in encrypted form and retained only for as long as the relevant inbox remains connected. Deleted promptly upon disconnection or account termination.
  • Synced Message Content and Metadata: Retained for the duration of your account so that conversation history remains available in your workspace. Deleted within 30 days of account closure, or sooner on request. Where your plan or workspace settings define a shorter sync window or retention period, that setting controls.
  • Notes, Assignments, and Activity Logs: Retained for the duration of your account and deleted with your workspace, except where a record must be retained for security or legal purposes.
  • Transaction and Billing Records: Retained for a minimum of 7 years to comply with financial recordkeeping requirements under applicable law.
  • Support and Communication Records: Retained for up to 3 years from the date of the interaction, or as required by applicable law.
  • Marketing Consent Records: Retained for as long as you remain a subscriber, and for up to 3 years following opt-out, to demonstrate compliance.
  • Cookies and Analytics Data: Session cookies are deleted when your browser session ends. Persistent cookies and analytics data are retained in accordance with the retention periods of the applicable third-party provider.
  • Backup Copies: Residual copies of data may persist in encrypted backup systems for a limited period after deletion due to technical constraints.

You may request deletion of your data at any time by contacting us at support@mycoldinbox.com. Upon such request, we will take reasonable steps to delete your data, unless retention is required for legal, security, or operational purposes.

11. Data Security

We implement and maintain appropriate technical, administrative, and organizational security measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include:

  • Encryption of data in transit using TLS/SSL protocols
  • Encryption of sensitive data at rest, including all mailbox credentials, app passwords, and OAuth tokens
  • Logical separation of workspace data, so that one customer's data is not accessible to another
  • Role-based access controls within the product, allowing you to limit which team members can access which connected accounts
  • Internal role-based access controls limiting employee and contractor access to customer data on a need-to-know basis, with access logged
  • Regular security assessments, dependency monitoring, and vulnerability reviews
  • Use of reputable, security-certified third-party infrastructure providers
  • Employee and contractor training on data privacy and information security practices

While we take reasonable and industry-standard precautions, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security of your data. In the event of a security breach that is reasonably likely to result in a risk to your rights and freedoms, we will notify affected users and relevant regulatory authorities in accordance with applicable law and without undue delay.

12. Your Rights

12a. Rights Under GDPR (EEA, UK, and Switzerland)

If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights in respect of your personal data:

  • Right of Access: The right to obtain confirmation of whether we process your personal data and to receive a copy of that data.
  • Right to Rectification: The right to have inaccurate or incomplete personal data corrected.
  • Right to Erasure: The right to request deletion of your personal data, subject to applicable legal retention requirements.
  • Right to Restriction of Processing: The right to request that we limit how we use your data in certain circumstances.
  • Right to Data Portability: The right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller where technically feasible.
  • Right to Object: The right to object to processing based on legitimate interests or for direct marketing purposes.
  • Rights Related to Automated Decision-Making: The right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
  • Right to Withdraw Consent: Where processing is based on consent, the right to withdraw consent at any time, without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: The right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your personal data in compliance with applicable law.

12b. Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights under the CCPA and CPRA:

  • Right to Know: The right to request disclosure of the categories and specific pieces of personal information we have collected, the sources, our business purposes, and the categories of third parties with whom we share it.
  • Right to Delete: The right to request deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to Correct: The right to request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: We do not sell personal information as defined under CCPA/CPRA, nor do we share it with third parties for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: To the extent we collect sensitive personal information, you have the right to limit its use to purposes permitted under applicable law.
  • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising any of your CCPA/CPRA rights.

12c. How to Exercise Your Rights

To exercise any of the rights described above, contact us at support@mycoldinbox.com. We will respond to verifiable requests within the timeframe required by applicable law — generally 30 days under GDPR and 45 days under CCPA/CPRA, with a possible extension where permitted. We may need to verify your identity before processing your request. There is no charge for submitting a rights request unless requests are manifestly unfounded or excessive.

Where your personal data sits within a workspace controlled by your employer or another customer of ours, we may need to direct your request to that customer as the controller of the data.

13. Where Your Data Is Stored

MyColdInbox is operated by Clustox LLC, based in the United States (Delaware). All information collected through the Site and Services — including account data, workspace data, and message content synced from your connected mailboxes — is stored and processed on servers located in the United States.

If you access the Services from outside the United States, your information will be transferred to and stored in the United States, where data protection laws may differ from those in your country of residence. By using the Site and Services, you consent to this transfer, storage, and processing in the United States. If you are not comfortable with your data being stored in the United States, please do not use the Services.

For questions about where and how your data is stored, contact us at support@mycoldinbox.com.

14. Children's Privacy

The Services are intended solely for use by individuals who are at least 18 years of age, as required by our Terms of Service. We do not knowingly collect, solicit, or process personal data from anyone under the age of 18. If you are a parent or guardian and believe that a minor has provided us with personal data without your consent, contact us immediately at support@mycoldinbox.com. Upon verification, we will take prompt steps to delete such data from our systems.

15. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. The "Last Updated" date at the top of this Policy indicates when the most recent revision was made.

When we make material changes, we will provide notice by updating the effective date and, where required by law or where changes are significant, by notifying you via email to your registered address or through a prominent notice on the Site. Your continued use of the Services after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms.

We encourage you to review this Privacy Policy periodically to remain informed about how we protect your information.

16. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us:

MyColdInbox (operated by Clustox LLC)

Registered Address: 8 The Green, STE A, Dover, DE 19901, United States

Privacy and Data Requests: support@mycoldinbox.com

General Support: support@mycoldinbox.com

For EEA or UK users wishing to lodge a complaint with a supervisory authority: EEA authorities are listed at https://edpb.europa.eu. The UK authority is the Information Commissioner's Office (ICO) at https://ico.org.uk.

© 2026 Clustox. All rights reserved.