Privacy Policy
Effective date: 11 August 2026 · Last updated: 11 August 2026
Inba is run by Codebrahma ("Inba", "we", "us"). This policy explains what we do with your information. It covers the Inba website at inba.ai, the setup pages you use to connect your accounts, and the private server we run for you.
1. The short version
- Inba gives every customer their own private server. Your email and WhatsApp messages are copied to your server, not to a shared database of ours.
- We do not read your messages, and we do not store their contents.
- We keep a small amount of account information: your email address, your billing status, and whether each connection is working.
- Your messages are answered by an AI model. To do that, parts of your messages are sent to OpenAI, using the OpenAI account you connect.
- You can disconnect any source, or cancel and have everything deleted.
2. What we collect
This is everything we hold on our own systems.
| What | The details | Why we have it |
|---|---|---|
| Your email address | The address you sign up with. | To send you your sign-in link, your receipt, and support replies. |
| Billing information | Your subscription status, and an ID that points to your record at Stripe. | To run your subscription. Card numbers go straight to Stripe. We never see or store them. |
| Your server details | The ID, name, and IP address of the private server we create for you. | To create, start, stop, update, and delete your server. |
| Connection status | Whether each connection (Gmail, Beeper, WhatsApp, OpenAI, Telegram) is connected, still setting up, or failed. | To show you the setup screen and to help when something breaks. |
| A few connection labels | The Gmail address you chose, how many messages have been indexed, the email you use with Beeper, and the username of your Telegram bot. | To show you which account is connected to what. |
| Your sign-in session | A cookie in your browser that lasts up to 180 days, plus a one-time sign-in link that expires in 15 minutes. | To keep you signed in to your own setup page and nobody else's. |
| Service logs | Technical records of requests and errors. Email addresses appear only as a short one-way hash, never in readable form. | To keep the service running, and to stop abuse. |
We do not use advertising trackers, and we do not build a profile of you.
3. What stays on your own server
Your private server holds the things Inba actually works with:
- a copy of the Gmail mailbox you connect, and its search index;
- your WhatsApp messages, synced through Beeper as a linked device;
- the credentials for those connections, including your Google, Beeper, OpenAI, and Telegram logins; and
- the questions you ask and the answers you get.
That server is yours alone. It has its own disk, its own user account, its own firewall, and its own credentials. It is not shared with any other customer, and there is no common message index across customers.
Our staff can reach that server over an administrative SSH key, from our administration network only. We use that access to install and fix things, not to read your mail. We will tell you if we ever need to look at your data to solve a support problem, and we will ask first.
4. What we never store
To be specific, these never reach our systems in a form we keep:
- the contents of your emails or WhatsApp messages;
- your Google sign-in and Google OAuth credentials;
- Beeper one-time codes, recovery keys, or access tokens;
- the WhatsApp QR code you scan;
- your Telegram bot token or your OpenAI device code.
Some of these pass through our servers for a few minutes while you are setting up a connection, so we can hand them to your server. They are held in memory only, for the length of that setup step, and are never written to disk or to logs.
5. How we use your information
We use what we collect to:
- create your account and your private server;
- take payment and manage your subscription;
- sign you in;
- show you the setup and status pages;
- send you service emails, such as your sign-in link;
- answer your support questions;
- keep the service secure and stop misuse; and
- meet our legal obligations.
We do not sell your information. We do not use your messages to train AI models.
6. Who else is involved
Inba is built on other services. Each one sees only the part it needs.
| Company | What it does | What it sees |
|---|---|---|
| Hetzner Cloud (Germany, server in Finland) | Hosts your private server. | The server itself, and its daily backups. |
| Stripe | Handles payment. | Your name, email, and card details. See Stripe's own privacy policy. |
| Resend | Sends your sign-in emails. | Your email address and the message we send. |
| Provides Gmail access. | Your Gmail account, through the permission you grant. | |
| Beeper | Connects WhatsApp to your server. | Your Beeper account and your bridged messages. |
| WhatsApp (Meta) | The messages themselves. | Your linked-device connection, under WhatsApp's own terms. |
| OpenAI | Runs the AI model that answers you. | The parts of your messages sent with each question. |
| Telegram | The chat you use to talk to Inba. | Your questions and answers as they travel through Telegram. |
Two things worth being clear about:
- You connect your own accounts for OpenAI, Telegram, and Beeper. Those sign-ins live on your server and are used under your own agreement with those companies.
- Inba's use of information from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Your Gmail data is used only to answer your own questions. It is never sold and never used for advertising. We do not use it to train any AI model. Whether OpenAI keeps or trains on the text sent with your questions depends on the settings of the OpenAI account you connect, so please check those settings there.
Apart from these, we share your information only when the law requires it, or when it is needed to protect someone's safety or our legal rights. If our business is ever sold or transferred, we will tell you before your information moves.
7. Other people's messages
Your mailbox and your chats contain messages from other people. When you connect them, you are copying those messages to your own server. Please only connect accounts that are yours, and only where you are allowed to keep that copy. You stay responsible for how you use what Inba shows you.
8. Security
- All traffic between you, us, and your server uses TLS 1.2 or newer. Your server checks our certificate before it will talk to us.
- Every customer gets a separate server. Nothing is shared between customers.
- Your server exposes no public application ports. Administrative SSH is limited to our administration network.
- Inba can read your mail and chats to answer you. Only you can instruct Inba. If a message contains an instruction, Inba does not act on it. Inba reads messages as information only, and accepts requests from you alone.
- Sign-in links are single-use, expire in 15 minutes, and are stored only as a one-way hash. Using one signs out your previous session.
- Your server keeps seven days of daily backups at Hetzner.
No system is perfectly safe. If a breach ever affects your data, we will tell you and the relevant authority as quickly as the law requires.
9. How long we keep things, and how to delete them
| Situation | What happens |
|---|---|
| You disconnect a source (Gmail, WhatsApp, OpenAI, Telegram) | The credential is removed from your server and that connection stops. |
| Your payment fails | You get 72 hours to fix it. After that your server is powered off. Paying restores it. |
| You cancel | Your server is powered off straight away, then permanently deleted seven days later, along with its backups. |
| You ask us to delete everything | We delete your account record and your server. Allow up to 30 days. |
| Account records we must keep | Billing and tax records are kept as long as the law requires, even after your server is gone. |
| Service logs | Kept for a short period for security and troubleshooting, then discarded. |
To delete everything, email anand@codebrahma.com from the address on your account.
10. Your choices
You can, at any time:
- See and correct what we hold about you;
- Get a copy of it, or ask us to delete it;
- Disconnect any source from your setup page;
- Take away Google's permission at myaccount.google.com/permissions;
- Remove the WhatsApp link in WhatsApp under Settings → Linked devices;
- Cancel your subscription at any time through the billing portal; and
- Complain to your local data protection authority if you think we have got something wrong.
Email us to use any of these. We will reply within 30 days. We will not treat you differently for asking.
11. Where your data is kept
Your private server is in Helsinki, Finland, inside the EU. Our own systems and our suppliers may process your information in the EU, the UK, the US, and India. Where information leaves the EU or UK, we rely on standard contractual clauses or another approved safeguard.
If you are in the EU or UK: we handle your information to provide the service you have paid for (contract), because you have agreed to a specific connection (consent), and to keep the service safe and lawful (legitimate interests). For customers in California, the uses above are "business purposes". We do not sell or share personal information as those laws define it.
12. Children
Inba is not for anyone under 16. We do not knowingly collect information from children. If you believe a child has signed up, email us and we will delete the account.
13. Changes to this policy
We may update this policy. We will post the new version with a new effective date. If a change matters to you, we will tell you by email at least seven days before it takes effect.
14. Contact us
Questions, requests, or complaints:
Email anand@codebrahma.com. We reply within 30 days.