inboxintake

Privacy Policy

Last updated: September 1, 2026

1. Who we are

Intake is an AI-powered email intake service operated by costa.ai, based in Switzerland (“costa.ai”, “we”, “us”), available at intake-app.costa.ai (the “Service”). costa.ai is the controller of the personal data described in this policy. This policy explains what personal data we process when you use the Service, why, and the choices you have. It should be read together with our Terms of Service.

2. Data we collect

  • Account data — your name, email address, password (stored hashed), and settings.
  • Mailbox content — when you connect a mailbox or forward email to the Service: message headers, bodies, attachments, and the identities of senders and recipients.
  • Derived data — tasks, deadlines, contacts, organizations, and other structured information our systems extract from your mailbox content.
  • Billing data — subscription status and payment records. Card details are collected and stored by our payment processor (Stripe), not by us.
  • Usage and technical data — log data such as IP address, browser type, and actions in the app, used for security and troubleshooting.

3. How we use your data

We use your data to provide and secure the Service: ingesting and storing your email, extracting tasks and other structured information, showing it to you in the app, notifying you about items that need attention, handling billing, providing support, and preventing abuse. We do not sell your personal data, and we do not use the content of your emails for advertising.

4. AI processing

The Service sends portions of your mailbox content to third-party AI model providers to generate summaries and extract structured information. These providers process the content on our behalf to deliver the Service. We do not use your content to train models, and our agreements with AI providers restrict their use of your content to providing the service to us and exclude training on your data.

5. Google user data (Limited Use disclosure)

If you connect a Google account, Intake’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing features described in this policy, is not transferred to third parties except as necessary to provide those features (or as required by law), and is never used for advertising.

6. Sharing and service providers

We share personal data only with service providers that process it on our behalf under contractual confidentiality and data-protection obligations. They fall into these categories:

  • application hosting and database infrastructure;
  • file storage for attachments (mailbox content and attachments are stored in the EU — Germany and Belgium);
  • email routing and delivery;
  • mailbox connectivity (when you connect an account via OAuth);
  • AI model providers (for the processing described in section 4);
  • payments (Stripe — card details never reach us).

A current list of these subprocessors, with names, roles, and processing locations, is provided with our Data Processing Agreement — contact us at the address below to receive it.

We may also disclose data if required by law, to protect the rights and safety of our users or the public, or as part of a corporate transaction (in which case this policy will continue to apply to the transferred data).

7. Data retention and deletion

We retain your data for as long as your account is active. If you disconnect a mailbox, we stop syncing from it. If you delete your account, or ask us to, we delete your mailbox content and derived data within a reasonable period, except for records we must keep for legal, billing, or security purposes. Backups are deleted on their normal expiry cycle.

8. Security

Data is encrypted in transit, mailbox credentials and tokens are stored encrypted, and access to production systems is restricted to authorized personnel. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the competent authorities as required by law.

9. Your rights

Under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU/EEA GDPR, you have rights to access, correct, export, restrict, or delete your personal data, to object to certain processing, and to lodge a complaint with a supervisory authority (in Switzerland, the Federal Data Protection and Information Commissioner). You can exercise these rights by contacting us at the address below; we will respond within the timeframes required by applicable law.

10. International transfers

We are based in Switzerland, and our service providers may process data in other countries, including the United States. Where data leaves Switzerland or the EU/EEA for a country without an adequacy decision, transfers are protected by appropriate safeguards such as standard contractual clauses.

11. Children

The Service is intended for business use by adults and is not directed at children under 16. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email or an in-app notice before they take effect. The “Last updated” date above reflects the latest revision.

13. Contact

Questions or requests about your data? Contact us at luca@costa.ai.

Terms of Service·Privacy Policy·Sign in