Privacy policy

Inbox Aquarium is local-first. Your mail stays on your device — that is the product promise, not a footnote.

Last updated: 7 August 2026Brand site: www.inboxaquarium.com

Scope

The extension turns visible Gmail list rows into a local aquarium. The website markets the product and shows a synthetic demo tank. Neither surface is a general email client, and neither is a backend for inbox synchronization.

What we never do

  • Send email metadata to our own backend by default
  • Read, store, or display email bodies
  • Download or process attachments
  • Sell personal data or use inbox content for advertising
  • Log subjects, sender addresses, or message IDs in shared product code paths
  • Include email content in analytics events
  • Set cookies of any type (see Cookies)

Chrome extension

When processing starts

Live Gmail observation starts only after you accept privacy onboarding in the extension. Until then, the aquarium can run on demo fixtures only.

Categories of data (on your device)

After onboarding, the content script may observe only currently visible Gmail list metadata on mail.google.com:

  • Sender name or address when shown
  • Subject, displayed time, unread state, labels, attachment indicators
  • A link or route to open the original message in Gmail

The extension may also store local preferences (for example quality settings, background, source mode), an onboarding acceptance flag, the last visible list snapshot used to keep the tank stable, and — if you opt in — local usage counters (see Analytics).

It does not read bodies, compose drafts, contacts directories, or intercept Gmail network requests.

Where it is stored

Extension data stays in chrome.storage.local on your computer. It is not uploaded to an Inbox Aquarium server as part of the current product.

Why we process it (legal bases under GDPR)

  • Consent — you accept privacy onboarding before live list observation; you can clear local Gmail snapshots and related data in Settings.
  • Consent — optional local analytics only if you opt in.
  • Legitimate interests — storing minimal UI preferences so the aquarium works as you configured it (balanced against your right to clear them anytime).

Permissions (Chrome Web Store)

  • sidePanel — daily aquarium UI beside Gmail
  • storage — preferences, onboarding flag, last visible snapshots, optional local analytics
  • Host access to https://mail.google.com/* — observe visible list metadata after onboarding and open the original message in Gmail

These permissions are limited to the aquarium’s single purpose: a local visual layer on the Gmail list you already see.

How to delete extension data

In Settings you can clear local Gmail snapshots and clear local analytics data. Uninstalling the extension removes its local storage from that Chrome profile.

This website

The marketing site explains the product and hosts this policy. The homepage aquarium is a client-only demo driven by synthetic fixtures. It does not connect to your Gmail account and does not receive real mail metadata.

We do not run accounts, sign-in, forms that collect email addresses, or a waitlist on this static site in the current version.

Cookies and similar technologies

Inbox Aquarium does not use cookies of any type.

  • No first-party cookies
  • No third-party cookies
  • No advertising, analytics, or “preference” cookies on this website
  • No cookie consent banner is required for cookies we set — because we set none

The Chrome extension does not use browser cookies to operate the aquarium. Local state uses chrome.storage.local, which is not a cookie.

Your browser or network may still exchange ordinary technical connection data with the host that serves this static site (for example IP address in server logs). That is infrastructure of the host, not a cookie we place, and we do not use it to identify you for marketing.

Analytics

Website: this static marketing site does not include a product analytics or advertising pixel in the current version.

Extension: optional usage counters may stay on-device if you opt in. Allowlisted events only (for example aquarium opened, panel opens, settings changed, onboarding complete, crash code). Props may include extension version and quality tier. They never include subjects, senders, message IDs, or inbox content. There is no remote analytics sink in the current milestone — counters do not leave your device.

Third parties

We do not sell your personal data.

  • Google / Chrome — the extension is installed and updated through the Chrome Web Store / Chromium platform under Google’s terms. Gmail itself remains Google’s service; we only observe visible list UI after your consent.
  • Website hosting — the static site is delivered by a third-party CDN / hosting provider. The host may process technical request data under its own privacy policy in order to deliver the pages.

We do not share Gmail list metadata with these parties as part of Inbox Aquarium’s own processing — that metadata stays local to the extension on your device.

Retention

  • Extension snapshots and preferences — kept on device until you clear them in Settings or uninstall the extension.
  • Optional local analytics — kept on device until you clear them or uninstall.
  • Website — we do not maintain a product database of visitors in the current version. Host access logs, if any, follow the host’s retention practices.

Your rights (GDPR)

If the GDPR or UK GDPR applies to you, you may have rights including:

  • Access to personal data we hold about you
  • Rectification of inaccurate data
  • Erasure (“right to be forgotten”)
  • Restriction of processing
  • Objection to processing based on legitimate interests
  • Data portability, where applicable
  • Withdrawal of consent at any time (without affecting prior lawful processing)
  • Lodge a complaint with your local supervisory authority

Because most Inbox Aquarium data lives only on your device, the practical way to erase extension data is to use Settings clear actions or uninstall. For any request we can fulfill (or questions about this policy), email piergiorgio.reggiani@blanksrl.ink.

You may withdraw consent for live Gmail observation by clearing local snapshots and disabling or uninstalling the extension. You may withdraw analytics consent by turning analytics off / clearing local analytics in Settings.

International transfers

Extension mail metadata is not transferred to an Inbox Aquarium server in the current product. If you visit this website from outside the region where the host operates, technical delivery of static files may involve infrastructure in other countries under the host’s safeguards. We do not use that path to export your inbox.

Children

Inbox Aquarium is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided data through a channel we control, contact piergiorgio.reggiani@blanksrl.ink.

Security

We design for local-first processing so inbox metadata does not need to travel to our servers. The extension uses Chrome’s extension isolation and local storage. No security measure is perfect; protect access to your device and browser profile as you would for Gmail itself.

Changes to this policy

We may update this page when the product or hosting setup changes. The “Last updated” date at the top will change when we do. For material changes that affect the Chrome extension’s handling of Gmail data, we will also reflect the truth in the in-extension privacy / onboarding copy.

← Back to the aquarium