Inbox & Chill

Privacy Policy

Who this is

Inbox & Chill is made by Brandon Lucas Green, an individual developer in Massachusetts, United States. In this policy, "I" and "my" mean that person, and "the app" means the Inbox & Chill macOS application. Questions go to [email protected].

What the app collects

Nothing. The app contains no analytics, no telemetry, no advertising identifiers, and no usage tracking of any kind. It does not create an account, and it does not transmit your items, message contents, settings, or credentials to me or to any third party acting on my behalf.

The one thing that could look like collection is not: the app has a Diagnostics pane that reads the crash reports macOS itself writes for it and shows them to you, alongside its own log of failed connections. All of that stays on your Mac. It leaves only if you press Copy Report, Email Support or Export, and then it goes where you send it. Crash reports are trimmed of message text before they are shown, and your credentials are never in them.

Everything the app stores — your queue, your archive, your settings — is stored locally on your Mac, in your user Library folder and, for credentials, in your macOS login Keychain.

Credentials and connected services

To show you items from a service, the app needs a credential for that service — an API key, a personal access token, or similar. Those are stored in your macOS Keychain, protected by the operating system, and are used only to make requests from your Mac directly to that service.

When you connect a service, your Mac talks to that service directly. I am not in the middle of that connection and have no visibility into it. Those services will see your requests and may log them according to their own policies. The services the app can connect to include Linear, GitHub, GitLab, Trello, Asana, Slack, Sentry, Todoist, ntfy, and any custom JSON feed you configure. Apple Mail and Apple Reminders are read locally, on your Mac, with your permission, and involve no server of anyone's beyond the accounts those apps already sync.

Their handling of your data is governed by their privacy policies, not this one. If you are using a work account, check whether your employer permits connecting it to third-party tools before you do.

You can remove a credential at any time from the app's settings, which deletes it from your Keychain.

Local integrations

Two features touch your machine beyond the app's own storage:

Software updates

The app checks for updates using Sparkle, a widely used open-source update framework for macOS. To do that it requests an update feed hosted on GitHub. That request reveals your IP address and the app version you are running to GitHub, in the same way that visiting any web page reveals your IP address to that site. It does not include any information about your queue, your connected services, or your credentials. You can turn automatic update checks off in the app's settings.

This website

inboxandchill.app is a static site. It sets no cookies, and nothing on it follows you to other sites or builds a profile of you. It does count page views, and a few parts of it involve someone else's servers, as is true of essentially any website:

The site also loads a typeface from Google Fonts, which reveals your IP address to Google when the font is fetched.

Payment

Inbox & Chill is sold for a one-time price, and purchases are processed by Lemon Squeezy, which acts as the merchant of record: the sale is made through them, and your payment details are handled by Lemon Squeezy under its own privacy policy and never reach me. I do receive an order record, which will include your email address, so that a licence key can be issued and support can be provided.

What I actually hold about you

If you email me, I have your email and whatever you wrote, for as long as that correspondence is useful. If you buy a licence, I have the order record described above. That is the complete list. There is no user database beyond it, because the app has no accounts.

The visit tallies described under “This website” are not part of that list, because they are counts of pages rather than records of people. Neither I nor GoatCounter can connect them to you, to your email address, or to each other.

If you would like me to delete correspondence or an order record, email [email protected] and I will, subject to any records I am required to keep for tax or accounting purposes. Depending on where you live, you may have rights to access, correct, delete, or port personal data held about you; the same address is how to exercise them.

Children

Inbox & Chill is a tool for working adults and is not directed at children. I do not knowingly collect personal information from anyone under 13, and given the app collects nothing, there is nothing to collect.

Changes to this policy

If this policy changes, the updated version will be posted here with a new date at the top. Material changes — particularly anything that would introduce data collection where there is none today — will be noted in the app's release notes as well, not made quietly.

Contact

Anything at all: [email protected].