Privacy Policy

Last updated: June 20, 2025

What TrimBox does

TrimBox connects to your Gmail account to scan your inbox for mailing list subscriptions and frequent senders. It reads email headers (sender addresses and List-Unsubscribe headers) to identify who has been sending you bulk email, surfaces unsubscribe links for mailing lists, and groups all high-volume senders so you can clean them up easily. At your explicit request, TrimBox can archive, move to trash, or mark as read emails from selected senders in bulk.

Data we access

TrimBox requests access to your Gmail account (gmail.modify scope) in order to read message headers during scanning and to archive or trash emails when you explicitly request it. We only read:

  • Email headers (From, List-Unsubscribe)
  • Your Gmail address (to display your signed-in account)

We do not read email body content. Write actions (archive, trash, mark as read) are only performed on messages belonging to senders you select and only when you click the corresponding action.

Data we store

We do not store any of your email data on our servers. All scanning happens in memory during your session and is discarded when you close the tab or sign out. We store a short-lived access token in an HTTP-only cookie solely to authenticate your scan request. It expires after one hour.

Google API Limited Use

TrimBox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we only use your Gmail data to perform the inbox scan you request, we do not transfer it to third parties, we do not use it for advertising, and we do not allow humans to read your email.

Third-party services

TrimBox uses Google OAuth 2.0 for authentication and the Gmail API to read your inbox. Your data is subject to Google's Privacy Policy. We use Vercel to host this application; see Vercel's Privacy Policy.

Revoking access

You can revoke TrimBox's access to your Gmail account at any time through Google Account Permissions.

Contact

Questions about this policy? Reach out at support@infinitetoken.com.