Privacy Policy
Last updated: September 19, 2026
1. Information We Collect
When you use Incoho, we collect and store the following information:
- Account information: Your email address, business name, and password (stored as a hash by our authentication provider) when you create an account. If you sign up or sign in with Google, we receive your name and email address from Google instead of a password. We also store the settings you choose, such as your notification email address, tone, business hours, auto-send settings, and email signatures.
- Email credentials: For accounts connected with IMAP/SMTP, the server details and password (or app password) you provide. For Gmail and Google Workspace accounts connected with Google, an OAuth refresh token instead of a password. Passwords and refresh tokens are encrypted at rest using Supabase Vault.
- Customer emails: For each incoming email we process, we store the sender's email address, subject, message text, received date, and threading headers, together with any attachments up to 10 MB each (stored as files in private cloud storage). We also keep a short record (sender address and mailbox message identifier) of automated, blocked, or duplicate emails that we skip, so we don't download them again. Which emails we read is described in Section 3 (Gmail) and Section 5 (other providers).
- AI results and your work: The category, confidence score, and reasoning produced by the AI, the draft replies it writes (including drafts revised on your instruction; we keep the revised draft and how many times it was revised, not the instructions themselves), the replies you or Incoho send, your category corrections, internal notes, and files you attach to outgoing replies.
- Knowledge base data: Store policies, FAQs, brand voice, discount codes, and other information you provide, including text we import from your website or from files you upload (we keep the extracted text, not the uploaded file).
- Billing information: Your plan, usage, and Stripe customer and subscription IDs. Payment details are collected and stored by Stripe. We never see or store your full card number.
- Messages to us: The name, email address, and message you submit through our contact form are emailed to our team inbox through Resend (we don't store them in our database). Bug reports and feature requests you send from the dashboard are stored with your account, and bug reports are also emailed to our team.
- Usage and technical data: Aggregate page-view and performance data (see Section 7), and server logs of processing events. Logs record internal identifiers (account, task, and message IDs), your connected mailbox address, the AI's category and confidence score, and error messages. They do not include customer email addresses, message text, or the AI's reasoning, although an error message returned by a mail server can occasionally contain an email address.
2. How We Use Your Information
- To classify incoming customer emails and draft suggested replies based on your knowledge base, using the AI model providers listed in Section 5.
- To send replies on your behalf: when you approve a draft or write your own reply, and, if you turn on auto-send, when a draft meets the auto-send rules you configured. Replies are sent through the Gmail API for Gmail and Google Workspace accounts connected with Google, or through your mail server's SMTP for other accounts.
- To show you your emails, drafts, threads, and analytics in your dashboard, and to send the notifications you have turned on (such as escalation alerts, new-draft notifications, and daily digests).
- To manage your account, process payments, provide customer support, and keep the service secure.
- To maintain and improve the quality of the features you use, subject to the additional limits on Google user data in Section 3.
We do not sell your data or your customers' data, and we do not use it for advertising.
3. Google API Services Usage Disclosure
Incoho's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access
When you connect a Gmail or Google Workspace account, we request only the https://www.googleapis.com/auth/gmail.readonly and https://www.googleapis.com/auth/gmail.send scopes, plus the basic openid and email scopes used to identify which Google account you connected. With these scopes Incoho cannot modify, label, or delete any email in your mailbox, and we do not request access to any other Google service (such as Drive, Calendar, or Contacts).
Once connected, Incoho checks the mailbox about once a minute and downloads, in full (including attachments), every message received since the last check that is not in Sent, Spam, Trash, Drafts, or Scheduled. This includes messages under other labels or already archived, not only the Inbox. On the first check after you connect, it looks back up to 24 hours (or to when you signed up, if later). Automated messages and senders you have blocked are then skipped and only a short record of them is kept (Section 1).
How we use it
- Reading emails: We read incoming emails from your connected inbox to classify them by category (e.g., returns, shipping, order status) and generate draft replies using AI.
- Sending emails: When you approve a draft or write a reply, or when auto-send is enabled and a draft meets your auto-send rules, we send the reply through the Gmail API from your connected account.
We use Google user data only to provide and improve these user-facing features. We do not use it for advertising, we do not sell it, and we do not use it to train or develop general AI models. We do not allow humans to read it unless you give us permission for specific messages (for example, when you ask for support), it is necessary for security purposes such as investigating abuse, it is required to comply with the law, or it has been aggregated and anonymized for internal operations.
How we store it
OAuth refresh tokens are encrypted at rest using Supabase Vault. Email content and attachments are stored in our database and private file storage so you can review, send, and look back on them in your dashboard. They are kept as described in Section 4.
How we share it
Email content is sent to the AI model providers listed in Section 5 solely to classify emails and draft replies for you. It is otherwise shared only with the service providers that host and operate Incoho (Section 5), or when required by law.
Revoking access
You can revoke Incoho's access at any time from your Google Account permissions page; the stored refresh token then stops working immediately and Incoho can no longer read or send from that account. Clicking Disconnect on the Settings > Email Accounts page in your dashboard stops Incoho from checking that mailbox and from sending from it (including replies you approve and auto-send), but does not revoke Google's grant. The encrypted token stays stored so you can reconnect later. Deleting your account (Section 4) deletes the token and its email data, and we ask Google to revoke the token. If the same Google account is connected by another Incoho user, that shared grant stays in place, and you can always remove it yourself on the Google Account permissions page above. To delete one mailbox without closing your account, email us at support@incoho.ai.
4. Data Retention and Deletion
- We keep your data, including emails, attachments, drafts, sent replies, corrections, notes, and your knowledge base, for the life of your account, and delete it when your account is deleted. The exceptions are the short-lived items below.
- Files you attach to an outgoing reply are deleted once that reply is sent, or when you remove them. If the reply is never sent, they are kept with that email like the rest of your data.
- Records of skipped automated, blocked, or duplicate emails are deleted automatically after 7 days.
- You can delete your account yourself at any time from Settings > Billing > Delete account. Deletion is immediate and permanent: your account, your connected email accounts and their stored credentials, your emails, drafts, attachment files, and knowledge base are all deleted, and any paid subscription is cancelled. We also ask Google to revoke the tokens for connected Gmail accounts; if the same Google account is connected by another Incoho user, that shared grant stays in place and you can remove it yourself in your Google Account permissions. Stripe keeps its own customer record (billing email and invoice history) for tax and accounting purposes. Copies may remain in our service providers' encrypted backups and server logs (for example Vercel's runtime logs) until they expire under those providers' retention limits.
- To delete less than the whole account (specific emails, or one connected mailbox and its data), email support@incoho.ai.
- Canceling a paid plan does not delete your data. Your account moves to the Free plan and your data stays available.
5. Service Providers (Subprocessors)
We use the following companies to operate Incoho. Each receives only the data it needs to provide its service to us:
- Vercel Inc.:Hosts the Incoho website and application, runs our scheduled background jobs (checking inboxes, auto-send), stores server logs, and provides privacy-friendly web analytics. Vercel's AI Gateway may also be used to route AI requests to the model providers below.
- Supabase Inc.: Database hosting, user authentication, file storage for email attachments, and encrypted credential storage (Supabase Vault).
- AI model providers: The text of customer emails (sender, subject, message text, and earlier messages in the thread), your knowledge base, your recent category corrections, and any instructions you give to revise a draft are sent to an AI model to classify emails and draft replies. Website text you import, files you upload to your knowledge base, and anything you enter in the Sandbox are also processed by an AI model. Attachments are not sent to AI models.
Today these requests go directly to Anthropic. We can also route them through Vercel AI Gateway, which is restricted in our code to the model families and serving companies below. It cannot send your data to any other AI provider:
- Claude models by Anthropic (in use today), served by Anthropic, Amazon Web Services, Amazon Web Services (Amazon Bedrock), Google Cloud (Vertex AI).
- OpenAI models (may be used), served by OpenAI, Microsoft Azure.
- Google Gemini models (may be used), served by Google Cloud (Vertex AI).
Requests sent through Vercel AI Gateway require zero data retention, so they are routed only to providers that have agreed not to retain them. Requests sent directly to Anthropic are governed by Anthropic's commercial terms, under which Anthropic does not use them to train its models. The list above is generated from the same configuration that restricts where our code may send AI requests, so it cannot fall out of date.
- Google LLC: The Gmail API, for Gmail and Google Workspace accounts you connect with Google, and Google sign-in, if you use it.
- Stripe, Inc.: Payment processing and subscription management.
- Resend:Sends our emails to you (welcome, notifications, escalation alerts, daily digests, and payment notices) and delivers contact form messages and bug reports to us. Escalation alerts include the customer's email address and the email's subject line.
For accounts connected with IMAP/SMTP, Incoho also connects to your own email provider's servers with the credentials you gave us, to read new mail in your Inbox (downloaded in full, including attachments, looking back up to 24 hours when you first connect) and to send replies (and save a copy of each sent reply to your Sent folder).
6. Data Security
Email passwords and OAuth refresh tokens are encrypted at rest using Supabase Vault and are only decrypted on our servers when needed to connect to your mailbox. Our website and APIs are served over HTTPS. Incoho always uses TLS when connecting to IMAP and SMTP servers (SMTP servers that don't support TLS are refused), and uses HTTPS for the Gmail API. Row Level Security in our database ensures each merchant can only access their own data, and attachments are served through short-lived private links. No method of storage or transmission is completely secure, but we work to protect your data using these and other safeguards.
7. Cookies and Analytics
We use a small number of cookies and similar technologies that are needed to run the service: authentication cookies that keep you signed in, and browser storage for preferences such as your light or dark theme. We use Vercel Web Analytics and Vercel Speed Insights to measure page views and site performance in aggregate; these do not use cookies. We do not use advertising or cross-site tracking cookies. Stripe sets its own cookies on its checkout and billing pages.
8. Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Delete your account and data yourself (Settings > Billing > Delete account), or ask us to delete part of it.
- Request a copy of your data in a portable format (Business plan accounts can also export email tasks as CSV from the dashboard).
- Withdraw consent for data processing at any time by disconnecting your email accounts, revoking Google access, or deleting your account.
To make a request, email support@incoho.ai. If you are a customer of a merchant who uses Incoho, please contact that merchant; we process their customers' emails on their behalf and will help them respond to your request.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the date at the top of this page and, for material changes, notify you by email or in the dashboard.
10. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at support@incoho.ai.