LEGAL
Privacy policy
This page describes what duoinbox.com collects when you send a request through it, where that goes, and how to get it back or have it removed. It is written from what the site actually does, so it is short.
Effective
Who is responsible for this data
duoinbox.com is operated by DuoInbox, 30 North Gould Street, Sheridan, Wyoming 82801, United States. DuoInbox decides what the forms on this site ask for and what happens to the answers, which makes it the controller of that data.
Written questions about this policy go through the contact page, or by email to mail at duoinbox dot com .
What this policy covers
It covers the website duoinbox.com and every form on it: the early-access request, and any message you send from the contact page.
It does not cover mail inside a customer's Google Workspace. How DuoInbox handles a customer's messages is set by the agreement that customer signs, and this page will not stand in for that document.
What the site collects
Only what you type, plus what any web server sees when a browser asks it for a page.
- A work email address. Required, because without it there is no way to reply.
- Free text, if you write any. The inbox workflow you would govern first, or whatever you want to ask. Optional, and capped at 500 characters.
- Anything else you choose to type into a form field. The form asks for nothing beyond the two things above.
One field on the form is hidden and is not a question for you. If it comes back filled in, the request is discarded without being stored. It is there to drop automated submissions, not to learn anything about you.
Serving the page needs your device's IP address and the headers your browser sends, including the user agent. Cloudflare processes those as the network and hosting provider for duoinbox.com. Fathom Analytics separately counts aggregate page visits, and DuoInbox does not connect that measurement to the address you type into a form.
Cookieless, aggregate analytics
duoinbox.com uses Fathom Analytics to count aggregate page visits. Fathom sets no analytics cookies, records no sessions, and is not used for advertising or individual visitor profiles. DuoInbox sends it no form values and does not join analytics to early-access or contact records.
The analytics script is loaded from Fathom's content-delivery domain. Other site assets are served from duoinbox.com, and a form request is made only when you submit one.
Why it is collected
To answer you. A person reads the request and replies to the address you gave, about the thing you asked.
Your address is not sold. It is not shared for anyone else's marketing. It is not used to build an advertising profile, and it is not added to a general mailing list you did not ask for.
What the record holds
A stored request is six things.
- Your email address
- Trimmed and lowercased before it is written, so the same address is never stored twice in different spellings.
- The free text you typed
- Stored as you wrote it, up to 500 characters. If you left the field empty, nothing is stored in its place.
- Which form the request came from
- A short label such as the early-access request, so a reply can pick up where you left off.
- When it arrived and when it last changed
- Two timestamps, set by the database rather than by your browser.
- How many requests that address has sent
- A counter. Sending a second request from the same address updates the existing record and raises the count instead of creating a new record.
- A follow-up status
- One of new, contacted, qualified, converted, or closed, used only to track whether a person has replied to you yet.
There is no field for your name, your employer, your job title, your location, or your IP address, because the form never asks and the code never writes one.
Where it is stored
In a database DuoInbox operates on Cloudflare, the same infrastructure that serves this site. Access to it is limited to the people who run DuoInbox.
When someone replies to you, your address and the reply pass through the email provider DuoInbox uses to send it. That is the full list: the site's host, the database, and the mail path of the reply.
This policy does not state a storage region or promise where data is physically held. Data residency is not something DuoInbox can currently guarantee, so it is not claimed here.
How long it is kept
Two periods, both the same length.
- Early-access and contact records. Kept for 24 months from the last contact with you, then deleted. Sending another request, or replying to one, is a new last contact and restarts the 24 months.
- Email correspondence. The reply thread with you is kept for 24 months, then deleted.
Ask for deletion earlier and it happens earlier. A verified request is actioned within 30 days, as set out in the next section.
These periods cover website data. They say nothing about mail inside a customer's Google Workspace, which is governed by the agreement that customer signs.
Asking for a copy, a correction, or deletion
Use the contact page, choose Privacy request as the topic, and say which of the three you want. You can also email mail at duoinbox dot com instead. You do not need to give a reason.
- A copy. You get back the six fields above as they stand for your address.
- A correction. Tell us what is wrong and it is changed.
- Deletion. The record is removed. Nothing is retained in its place except the fact that the deletion happened.
A record is found by email address, so write from the address you used or name it in the message. That is also how a request is verified as yours. A verified request is actioned within 30 days.
What this policy does not claim
The absences below are deliberate. Each one is a sentence a longer policy would include without being able to support it.
- No certification or attestation
- This page claims no security certification, audit report, or compliance framework. If one matters to your review, ask on the contact page and you will get a direct answer rather than a badge.
- No storage region or residency guarantee
- DuoInbox does not publish where its data is physically held. A residency claim is the first thing your counsel would test, so it is not made here.
- No entity type or registration
- This policy names DuoInbox and gives its business address. It does not publish a company registration, an entity type, a tax number, or a founding date, because none is published for this site. The address is where post reaches DuoInbox, nothing more.
- No description of the product's data handling
- This policy covers the website. It is not the document that would govern mail inside a customer's Google Workspace.
Changes to this policy
The effective date at the top of this page is the date of the version you are reading. If what the site collects, why it collects it, or where it is kept changes, this page is rewritten and that date moves with the change.
This page is the record of the current terms. There is no separate announcement list, so check the date here rather than waiting to be told.
If you were on your way to the form: request early access.