Trust and data handling

Precise boundaries beat
vague security slogans.

This page explains the approval model and the questions a business proof must settle before mailbox access, exports, or payment change hands.

Current product boundaries

What you should know before connecting an account.

Trust depends on the exact product and platform. These are the operating principles; the applicable privacy notice controls the implementation details.

01

Provider authorization

Google and Microsoft handle account sign-in. Zero Inbox requests provider permissions needed for the connected workflow; the exact scope depends on the product and platform you use.

02

Review before consequential action

Starting a cleaner scan does not itself move messages. The authorized user reviews proposed changes before confirming the keep, move, archive, trash, or other supported action.

03

Processing is described precisely

The mobile notice explains collection, AI processing, service providers, retention, deletion, and choices for iOS. Business proofs add a written source-specific scope before work begins.

04

Exceptions remain visible

A service closeout reports excluded sources, false positives, unsupported fields, unresolved records, and other limitations instead of hiding them inside a completion claim.

Before a business proof

Put the operating promises in the scope.

A landing page cannot substitute for a source-specific review. The signed scope should make these decisions explicit.

01Named customer authority and named Zero Inbox owner.
02Authorized source, account count, date range, and economic event.
03Data received, data produced, access method, and approved providers.
04Retention and deletion terms for proof artifacts and exports.
05Actions requiring approval, excluded actions, and escalation contacts.
06Closeout evidence, unresolved exceptions, and access-removal steps.

Questions

Ask before you authorize.

Does Zero Inbox need my Google or Microsoft password?

No. Account connection uses the provider's sign-in and authorization flow. Do not send passwords, access tokens, exports, or mailbox content by email.

Does the cleaner change messages as soon as a scan starts?

No. The cleaner separates review from execution. The authorized user reviews proposed message-changing actions before confirming them.

Can a business request a data and security review?

Yes. A business proof should define authorized sources, owners, data boundaries, retention, deletion, providers, exclusions, and incident contacts before access or payment.

Should regulated data be included in a founding proof?

Not by default. Regulated or unusually sensitive environments require a separate legal, security, and data review and must be explicitly accepted in the signed scope.

Business review

Bring your actual questions.

Tell us the program, source system, reviewers, deadline, and specific security or privacy concerns. Do not attach private data.