1. Data controller
Sevy Créations, 3234 Vinelz, Switzerland, is responsible for the processing it determines for ClarInBox. Privacy and security contact: infos@sevy-creations.net.
2. Data used
To provide the functions requested by the user, ClarInBox uses:
- account settings: email address, username, server, port and folders;
- access credentials or OAuth tokens stored in the iOS Keychain;
- elements needed for analysis: sender, recipient, date, subject, preview and available text content;
- folder organization, sorting decisions, learned rules, preferences and the history needed for operation;
- data included in an encrypted backup only when the user chooses to create one.
3. Purposes and legal basis
Data is used only to connect selected accounts, display messages to be analyzed, suggest a classification, apply confirmed moves, remember local decisions and restore a requested backup.
Depending on the applicable law, these operations are primarily based on performing the service requested by the user. Mailbox access is authorized by the user and may be revoked through the relevant provider. Security measures also serve the legitimate interest of protecting the service and its users. Where another legal basis is required, it is requested at the appropriate time.
ClarInBox does not use email data for advertising, commercial profiling, selling data or cross-app tracking.
4. Google user data accessed and how it is used
To connect Gmail through IMAP with OAuth, ClarInBox requests openid, email and https://mail.google.com/. Google requires the latter scope for Gmail access through IMAP; no narrower Google IMAP OAuth scope is available.
Google data accessed by ClarInBox:
- the email address and identifier of the connected Google account;
- the names and hierarchy of Gmail folders or labels;
- technical message identifiers required to find and move the correct message;
- for messages the user chooses to analyze: sender, recipients, date, subject, preview and available text content;
- the detected number of attachments. ClarInBox excludes attachment content from analysis.
How this data is used: to authenticate the account, display available folders, locally analyze recent messages from folders selected by the user, suggest a destination, create a folder or subfolder requested by the user and move only messages the user has expressly approved. When a message is marked “Trash”, ClarInBox moves it to the account’s Trash; it does not permanently delete the message by bypassing Trash.
The https://mail.google.com/ scope technically permits additional operations. ClarInBox does not use it to send email, permanently delete messages or act without a visible user action. It is requested because it is the OAuth scope Google requires for a Gmail IMAP connection.
ClarInBox’s use and transfer to any other app of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Sevy Créations does not sell Google user data, use it for advertising, commercial profiling or surveillance, or disclose it to third parties, except when the user initiates an export to a chosen backup location or when strictly required by law.
No member of Sevy Créations reads the user’s email. Google user data is not used to train, improve or develop a general artificial intelligence or machine-learning model. Sorting learning remains local, specific to the user and limited to the visible ClarInBox function.
5. Local processing and recipients
In the current version, analysis and learning take place on the iPhone. No server operated by Sevy Créations receives email content. The app communicates directly with the mail servers configured by the user, including Google, Microsoft or another chosen IMAP provider.
The email provider processes messages under its own terms. If the user exports a backup to Files, iCloud Drive or another location, that provider may process the encrypted file under its own policy.
6. Retention
Settings and learned rules remain on the device until they are deleted or reset. An account password or OAuth token is removed from the Keychain when that account is deleted in ClarInBox. Exported backups remain in the chosen location until the user deletes them.
7. Deletion and revocation
- In the Accounts tab, open the relevant account, choose to delete it and confirm.
- In Settings, delete a specific rule or clear all learned rules.
- Separately delete exported backups from Files, iCloud Drive or the chosen service.
- To revoke OAuth access completely, also remove ClarInBox from the Google or Microsoft account security settings.
Deleting an account from ClarInBox does not delete the email account at its provider or messages already stored on the server.
8. Individual rights
Subject to applicable law, a person may request information, access, correction, deletion, restriction or portability of their data and may object to certain processing. Revocable authorization may be withdrawn at any time without affecting processing that was lawful before withdrawal.
Because most data remains on the device and with the selected provider, some requests must be performed directly in the app or submitted to that provider. A complaint may be filed with the Swiss Federal Data Protection and Information Commissioner (FDPIC), or with the competent authority where European law applies.
9. Protection mechanisms for sensitive data
ClarInBox applies the following safeguards to Google data and other email data:
- encryption in transit: IMAP server connections use TLS and OAuth exchanges use HTTPS;
- credential protection: the revocable OAuth token and, where a standard IMAP account requires one, its access secret are stored in the secure iOS Keychain, separately from ordinary preferences;
- local processing: message content and sorting learning are processed on the iPhone within the app sandbox and are not sent to a server operated by Sevy Créations;
- data minimization: only accounts, folders and recent messages selected by the user are analyzed; attachment content is excluded;
- human approval: moves and Trash actions are shown to the user and applied only after confirmation;
- backups: a backup exists only if the user voluntarily creates it; it is encrypted with a passphrase that ClarInBox does not retain.
Deleting an account from ClarInBox removes its secret or OAuth token from the Keychain. The user may also revoke access from their Google account security settings. No system can guarantee absolute security.
Server locations and any international transfers depend on the email provider and the export location selected by the user.
10. Children and policy changes
The app is not specifically directed to children. Use by a minor must comply with applicable law and any required parental authority. This policy may change with features or legal obligations; the version date above identifies the applicable text.
11. Contact
Sevy Créations
3234 Vinelz, Switzerland
infos@sevy-creations.net