Privacy Policy
Last updated: 3 August 2026
1. Who operates Inflow AI
Inflow AI is operated by Codium Systems (“we”, “us”). This policy explains what data we collect when you use Inflow AI, why we collect it, and how you can control it. If you have questions, contact us at privacy@codiumsystems.com.
2. What Inflow AI does
Inflow AI connects to a business email account you authorise (Outlook or Gmail), reads newly arriving messages, classifies them, and — depending on your settings — sends an automatic reply, holds the message for your review, or takes no action. You configure what the product knows about your business and how it should behave from your Inflow AI dashboard.
3. Data we access and why
- Email content.When you connect an inbox, we request the minimum Microsoft Graph or Gmail API scopes needed to read new messages and send replies on your behalf (for example, Outlook’s
Mail.ReadandMail.Send, or Gmail’s equivalent read/send scopes). We do not request access to your calendar, contacts, files, or any other part of your Microsoft or Google account. - OAuth tokens. We store the access and refresh tokens issued by Microsoft or Google so we can keep checking your inbox without asking you to log in again. These tokens are stored encrypted at rest in our database and are never shared with third parties.
- Processed email metadata and content excerpts. For each email we process, we store the sender, subject, a short excerpt of the body, our classification of it, and any reply we drafted or sent. This is what powers your Activity feed and lets you review, edit, or reclassify past decisions.
- Account and business information. Your business name, login email, password (hashed, never stored in plain text), and the knowledge base you provide (services you offer, tone of voice, and similar configuration).
4. How your email content is processed
To classify an email and draft a reply, the relevant text (sender, subject, and a body excerpt) is sent to a third-party AI provider (currently Groq, running Meta’s Llama models) for analysis. This provider processes the request and returns a classification and suggested reply; it does not use your data to train its models under our agreement with them. No email content is sent to any other third party.
5. Where your data is stored
Application data (account details, processed email records, knowledge base configuration) is stored in a managed PostgreSQL database (Supabase). Infrastructure and automation components run on servers we operate directly. We do not sell your data, and we do not use your email content for advertising.
6. How long we keep data
We retain processed email records and account data for as long as your account is active, so your Activity history remains available to you. If you delete your account, we delete your account data and disconnect any linked inboxes; associated OAuth tokens are revoked.
7. Your controls
- Disconnect a connected inbox at any time from your dashboard — this immediately stops all further access to that account.
- Turn off automatic sending entirely and review every reply before it goes out.
- Request a copy of your data, or request deletion of your account and associated data, by contacting privacy@codiumsystems.com.
8. Sharing with third parties
We use a small number of infrastructure providers to operate Inflow AI: Microsoft and Google (for the inbox connection you authorise), Groq (for email classification, as described above), and Supabase (for database hosting). We do not sell, rent, or share your data with anyone else, and we do not use it for advertising.
9. Changes to this policy
If we make material changes to this policy, we’ll update the date at the top of this page and, where appropriate, notify active users directly.
10. Contact
Questions about this policy or your data can be sent to privacy@codiumsystems.com.