Privacy Policy / Politique de Confidentialité
Last updated: July 23, 2026 | Dernière mise à jour : 23 juillet 2026
Company: ICRAFT SAS — 58 Rue de Monceau, 75008 Paris, France — RCS Paris 992 314 237
Contact: contact@bumblebox.ai
1. Introduction
BumbleBox ("we", "our", "us") is an AI-powered email management platform operated by ICRAFT SAS. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at bumblebox.ai.
BumbleBox connects to your email accounts via IMAP/SMTP protocols to classify, organize, and help manage your email. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable French data protection laws.
2. Information We Collect
2.1 Account Information
- Email address (used for authentication)
- Display name (from Google OAuth or manual entry)
- Profile photo (from Google OAuth, if available)
2.2 Email Account Credentials
- IMAP/SMTP server details, email address, and app-specific passwords for connected email accounts
- Google OAuth tokens (for Gmail connections)
- All credentials are encrypted with AES-256-GCM at rest
2.3 Email Metadata
- Sender, recipient, subject, date, folder information
- Email classification results (spam, newsletter, important, etc.)
- Email body content: to provide the service (classification, search, AI reply drafts), we store the text and HTML of your emails in our database, encrypted in transit and access-controlled at rest. Bodies and attachments of messages that are not in your inbox (archived, filed, older mail) are automatically stripped after 30 days; the metadata row is kept until you delete the account or the message. We never use your email content to train generalized AI models (see Section 4).
2.4 Usage Data
- Actions taken in the app (classify, archive, delete, draft)
- Feature usage analytics (anonymized)
- Browser type, device, IP address (for security)
3. How We Use Your Information
- To provide the BumbleBox email management service
- To classify and organize your emails using AI
- To generate AI reply drafts (Pro/Business plans)
- To detect phishing and security threats
- To send transactional emails (welcome, password reset, billing)
- To comply with legal obligations
4. Google API Services & Limited Use of Gmail Data
When you connect a Gmail account, BumbleBox accesses your Gmail data via Google APIs to provide the email management features you have requested. Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, BumbleBox:
- Does NOT transfer your Gmail data to third parties, except as strictly necessary to provide or improve user-facing features that are prominent in the BumbleBox user interface, with your consent, or to comply with applicable law.
- Does NOT use your Gmail data for serving advertisements, profiling, or any advertising purposes.
- Does NOT allow humans to read your Gmail data, except (a) with your explicit consent for specific messages, (b) where necessary for security purposes (such as investigating a confirmed security incident or abuse), (c) to comply with applicable law, or (d) where the data is aggregated and anonymized for internal operations.
- Does NOT use your Gmail data to develop, improve, or train generalized or generic AI/ML models. AI classification runs per-message to deliver the features you enabled. AI processing is performed primarily on a self-hosted model (operated by us on dedicated infrastructure) and, as a fallback, via the Google Gemini API; these general-purpose models are not trained on your data. Your email content is stored only to power your own account's features (classification, search, drafts) and is never used to improve models for other users.
- Does NOT sell your Gmail data to any party for any purpose.
OAuth scopes requested when you connect Gmail are limited to what is necessary to deliver the feature you enable (read, classify, archive, send, draft). You may revoke access at any time via your Google Account permissions page or by disconnecting the account in BumbleBox settings; upon revocation we delete the corresponding OAuth tokens and cached metadata for that account.
5. Legal Basis (GDPR)
- Consent: You consent to email processing when you connect your accounts
- Contract: Processing is necessary to provide the service you subscribed to
- Legitimate interest: Security monitoring, fraud prevention, service improvement
6. Data Sharing
We do NOT sell your data. We share data only with the following sub-processors, each for a specific purpose:
- OVHcloud (France, EU): our primary hosting and database — where your account data and email content are stored. Servers are located in the European Union.
- Google Firebase (EU/US): authentication (sign-in sessions) and static hosting of the web app.
- Resend (US): delivery of transactional emails (welcome, billing, password reset) and, for outbound campaigns you send, the campaign emails. Recipient address and message content pass through Resend for delivery.
- Google Gemini API (US): AI classification fallback when our self-hosted model is unavailable. Content sent for classification is not used by Google to train models. Our primary AI runs on self-hosted infrastructure operated by us.
- Stripe (US/EU): payment processing (we never see or store your card details).
- Sentry: error monitoring — email bodies and credentials are redacted before events are sent, and only after you consent to error tracking.
7. Data Retention
- Account data and email metadata: retained while your account is active; deleted when you delete your account.
- Email body content & attachments: for messages outside your inbox (archived/filed/old), automatically stripped after 30 days; inbox content is retained while it remains in your inbox.
- AI classification corrections: retained up to 180 days, then purged.
- Scheduled/sent campaign records: retained up to 90 days after a message reaches a final state, then purged.
- Credentials (IMAP/OAuth): deleted immediately upon account disconnection or deletion.
- Usage analytics: retained for 12 months (anonymized).
8. Your Rights (GDPR)
As an EU resident, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a machine-readable format
- Objection: Object to data processing
- Restriction: Request limited processing
To exercise these rights, contact us at contact@bumblebox.ai.
9. Data Security
- All credentials (IMAP passwords, OAuth tokens, third-party API keys) encrypted with AES-256-GCM at rest
- HTTPS/TLS for all data in transit; TLS enforced for IMAP/SMTP connections
- Every database query is scoped to your user ID (application-level tenant isolation in PostgreSQL)
- Passwords are hashed (scrypt); no plaintext passwords stored anywhere
- Regular security audits and restore-tested encrypted backups
10. Cookies & Email Tracking
On our website we use essential cookies for authentication (Firebase Auth session) and localStorage for user preferences (theme, language). We do not use advertising cookies. Error-tracking (Sentry) loads only after you consent via the cookie banner.
Outbound campaign emails: when you (as a user) send a marketing/prospecting campaign through BumbleBox, the campaign emails you send include a 1×1 open-tracking pixel so you can see whether your message was opened. If you are a recipient of such an email, you can stop this by not loading images, and every campaign email carries a one-click unsubscribe link that opts you out of further messages.
11. Children's Privacy
BumbleBox is not intended for users under 16 years of age. We do not knowingly collect data from children.
12. Prospecting & Recipients of Campaign Emails
Some BumbleBox customers use the service to send B2B prospecting emails (e.g. public-procurement outreach). Where BumbleBox processes the personal data of such recipients on a customer's behalf, the legal basis is the customer's legitimate interest in B2B communication (Art. 6(1)(f)), balanced against recipients' rights. Recipients can object at any time via the one-click unsubscribe link in every campaign email, which suppresses all further messages. If you received a BumbleBox-sent email and want your data removed, contact contact@bumblebox.ai.
13. International Data Transfers
Your account data and email content are stored on OVHcloud servers located in the European Union (France). Some sub-processors are based outside the EU (Resend, Stripe, Google/Gemini in the US); transfers to them rely on Standard Contractual Clauses and/or the EU-US Data Privacy Framework. Our self-hosted AI runs on infrastructure we operate. ICRAFT SAS is a French company subject to GDPR.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users via email or in-app notification of material changes. The "last updated" date at the top reflects the most recent revision.
15. Contact
For privacy-related inquiries:
- Email: contact@bumblebox.ai
- Company: ICRAFT SAS
- Address: 58 Rue de Monceau, 75008 Paris, France
- RCS: Paris 992 314 237