Privacy Policy
Last updated: June 9, 2026
This Privacy Policy explains how Airbox (“Airbox,” “we,” “us”) collects, uses, and shares information when you use Airbox.fyi, an email-to-LLM routing service available at https://airbox.fyi. By using Airbox you agree to this policy.
Information we collect
- Account data: your email address, optional name, and a hashed password if you set one. Email is our primary identifier.
- Email content you route: the messages you BCC or forward to your Airbox addresses, including subjects, bodies, and attachments. We process this to carry out your instructions and email you a reply.
- Provider credentials: the API keys for your own LLM providers and MCP servers. These are encrypted at rest and used only to make the calls you direct. Your Airbox SDK API key is stored only as a hash.
- Usage analytics and metadata: message status, timestamps, token-usage counts, tool calls, and credit events, used for the activity log, billing tiers, and abuse prevention. We may also use third-party service providers to collect and process analytics and other information related to our website and services. They have their own privacy policies addressing how they use the analytics and other information and we do not have access to, nor control over, third parties’ use of cookies or other tracking technologies.
- Payment data: handled by Stripe. We store a Stripe customer and subscription identifier and your plan — never your full card number.
Bring-your-own-key posture
Airbox is a routing layer: your key, your model, your bill. When you route a message to your AI, LLM, or MCP/tool provider, your email content is sent to that provider under your own account and is subject to that provider’s terms and privacy policy. We are not responsible for how third-party providers you connect handle your data.
How we use information
- To operate and improve the service — parse, route, and reply to your email
- To enforce sender allowlists, anti-spoofing, and credit limits
- To maintain your activity log and provide support
- To process subscriptions and prevent fraud and abuse
- Answering requests for customer or technical support
- Sending you email notifications and communications about your account and service
- Pursuing legitimate interests, such as research and development (including marketing research), network and information security, and fraud prevention
- Complying with legal obligations
We do not sell your personal information, and we do not use the contents of your routed email to train AI models.
Data retention & your controls
We retain processed message content according to your plan: 7 days on Free and 1 year on Pro, after which message bodies and AI results are purged automatically and only minimal metadata (needed for credit counts) is kept. Team and Enterprise plans retain activity logs for the life of the account, consistent with our legal and audit requirements. You can delete your Airbox account at any time from Settings, which removes your stored content and any encrypted credentials.
Your choices
General. You may have the right to object to or opt out of certain uses of your information. Where you have consented to the processing of your information for a specific purpose, you may withdraw that consent at any time by contacting us at privacy@airbox.fyi. Even if you opt out, we may still collect and use your information for other purposes that were not based on your consent.
Email communications. Airbox sends email in connection with the service — for example login codes, routed-message replies, and billing notices. We do not send promotional marketing email today. If we introduce optional marketing messages in the future, you will be able to unsubscribe using the link in those emails. You will continue to receive transaction-related and service-related email while you have an account (for example security alerts, replies to mail you route through Airbox, and updates to this Privacy Policy).
“Do Not Track.” Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications that you do not wish such operators to track certain of your online activities over time and/or across different websites. Like most online services, we do not currently respond to Do Not Track signals. However, as discussed below in the “International users, children, and your rights” section, we honor legally recognized browser-based mechanisms (such as the Global Privacy Control) designed to signal your opt-out choices under certain state laws.
Subprocessors
We share data with service providers (subprocessors) strictly to operate Airbox:
- Amazon Web Services (AWS)
- SendGrid (Twilio)
- Stripe
- Google Analytics (Google)
- Any AI/LLM/MCP providers and tools you connect — at your direction. When used, they process your provided content and information per your input and instructions, and their own terms and privacy policies.
Security
We encrypt provider credentials at rest, hash API keys and passwords, and transmit data over TLS. See our Security page for details. No system is perfectly secure; we cannot guarantee absolute security.
International users, children, and your rights
Airbox is operated from New York, United States. We host application data (including account data, routed email content, and attachments we store) in Amazon Web Services (AWS) facilities, and we configure our production environment to keep processing within the European Union (EU) where technically feasible.
All information processed by us may be transferred, processed, and stored anywhere in the world, including but not limited to, the United States or other countries, which may have data protection laws that are different from the laws where you live. When we engage in such transfers, we endeavor to safeguard your information consistent with the requirements of applicable laws.
Some processing may occur outside the EU, including by subprocessors that help us operate the service (such as email delivery and payment processing) and by the LLM and MCP providers you choose to connect, which process content under your direction and their own terms. Where we transfer personal data from the EEA/UK to countries without an adequacy decision, we rely on appropriate safeguards such as our agreements with processors (including AWS’s Data Processing Addendum) and, where applicable, Standard Contractual Clauses. If you are in the EEA, UK, or Switzerland, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to or restrict certain processing — contact privacy@airbox.fyi to exercise them. You may also have the right to lodge a complaint with your local supervisory authority. Where required by applicable U.S. state law, we honor opt-out signals sent through legally recognized browser-based mechanisms such as the Global Privacy Control (GPC) for certain uses of personal information, such as targeted advertising and the sale or sharing of personal information as those terms are defined under applicable law.
If you are located in the EU or the United Kingdom (UK), you have the right to lodge a complaint with a supervisory authority if you believe our processing of your information violates applicable data protection laws.
Airbox is not intended for children under 16, and we do not knowingly collect their data.
Additional information for California residents
If you are a California resident, the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), requires us to provide the following additional information about: (1) the purpose for which we use each category of “personal information” (as defined in the CCPA) we collect; and (2) the categories of third parties to which we (a) disclose such personal information for a business purpose, (b) “share” personal information for “cross-context behavioral advertising,” and/or (c) “sell” such personal information. Under the CCPA, “sharing” means targeting advertising to a consumer based on personal information obtained from the consumer’s activity across websites, and “selling” means disclosing personal information to third parties for monetary or other valuable consideration.
Our use of website analytics (including Google Analytics), described above, may result in the disclosure of online identifiers (for example cookie data, IP addresses, device identifiers, and usage information) in a way that may be considered a “sale” or “sharing” under the CCPA. We do not sell or share the contents of email you route through Airbox for cross-context behavioral advertising.
For information about our purposes of use of personal information, see the “Information we collect” and “How we use information” sections above.
For purposes of the CCPA, in the last 12 months we have collected the following categories of consumers’ personal information and disclosed personal information to the categories of third parties listed below. “Service providers” includes our subprocessors (such as AWS, SendGrid, and Stripe) and, when you route mail, the AI/LLM/MCP providers you connect at your direction.
| Category | Disclosed for a business purpose | Sold or shared |
|---|---|---|
| Identifiers (for example name, email address, account IDs, IP address, and online identifiers) | Service providers; entities for legal and compliance purposes; entities involved in a business transaction; providers you connect at your direction; entities with your consent. | Google (Analytics) |
| Personal information under Cal. Civ. Code § 1798.80(e) (for example name, email, and routed email content you send through the service) | Service providers; entities for legal and compliance purposes; entities involved in a business transaction; providers you connect at your direction; entities with your consent. | We do not sell or share. |
| Commercial information (for example subscription plan and billing metadata) | Service providers (including Stripe); entities for legal and compliance purposes; entities involved in a business transaction; entities with your consent. | We do not sell or share. |
| Internet or other electronic network activity (for example pages viewed and interactions with our website) | Service providers (including Google Analytics); entities for legal and compliance purposes; entities involved in a business transaction; entities with your consent. | Google (Analytics) |
| Geolocation data (general location inferred from IP address, not precise GPS) | Service providers (including Google Analytics); entities for legal and compliance purposes; entities involved in a business transaction; entities with your consent. | Google (Analytics) |
| Professional or employment-related information (for example company name on enterprise inquiries) | Service providers; entities for legal and compliance purposes; entities involved in a business transaction; entities with your consent. | We do not sell or share. |
| Inferences drawn from the above to create a profile about a consumer | Service providers (including Google Analytics); entities for legal and compliance purposes; entities involved in a business transaction; entities with your consent. | Google (Analytics) |
Your choices regarding “sharing” and “selling.” You have the right to opt out of our sale or sharing of your personal information for purposes of online analytics and advertising. You may submit a request by emailing privacy@airbox.fyi with the subject line “California opt-out,” or by using the “Do Not Sell or Share” link in our website footer (which brings you here). Where supported, we also honor the Global Privacy Control (GPC) signal as described above. Opting out of sale/sharing does not affect our use of personal information to operate Airbox (for example processing email you route through the service).
Other CCPA rights. California residents may have the right to know, access, correct, and delete personal information, and to limit the use of sensitive personal information in certain circumstances. Please see the “International users, children, and your rights” and “Your choices” sections above for how to exercise these rights. We do not offer financial incentives in exchange for your personal information. We do not use or disclose “sensitive personal information” (as defined in the CCPA) for purposes for which you have a right to limit under the CCPA.
Retention. Please see the “Data retention & your controls” section above.
Shine the Light. California’s “Shine the Light” law gives residents the right, under certain circumstances, to request information about how we disclose certain categories of personal information to third parties for their direct marketing purposes. We do not disclose your personal information to third parties for their own direct marketing purposes.
Changes & contact
We may update this policy; we will revise the “Last updated” date and, for material changes, notify you. Questions or requests: privacy@airbox.fyi
