← Back to Captchainbox

Privacy Policy

Effective date: April 14, 2026 · Last updated: August 20, 2026

Google API Services User Data Policy: Limited Use

Captchainbox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we only use Google user data to provide or improve user-facing features of Captchainbox; we do not use it for advertising, do not sell it, do not transfer it to third parties (except as necessary to provide the service, comply with applicable law, or with your consent), do not allow humans to read it (except with your explicit consent, for security or legal compliance, or when needed to resolve user-reported support requests), and do not use it to develop, improve, or train generalized AI/ML models.

Captchainbox ("we", "us", or "our") is operated by Felix Doerp (sole proprietor, based in Germany) and provides the website captchainbox.com and the Captchainbox service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

1. Information We Collect

1.1 Account Information

When you sign up, we collect your email address and basic profile information provided by Google during the OAuth authentication flow.

1.2 Gmail Data

With your explicit consent, we access your Gmail account through the Gmail API to:

  • Read email metadata (sender addresses, subject lines, dates) to build your trusted sender whitelist and classify incoming messages.
  • Modify email labels to archive messages from unknown senders and unarchive them after verification.
  • Send emails on your behalf to deliver verification challenge messages to unknown senders.

We do not read the body content of your emails. We only process metadata (sender, recipient, subject, date) necessary for the service to function.

1.3 Data from Email Senders

When an unknown sender receives a verification email and visits our verification page, we collect:

  • Their IP address (for Cloudflare Turnstile CAPTCHA verification)
  • The verification token used
  • The result of the CAPTCHA challenge
  • For pay-to-deliver, the payment amount, currency, Stripe transaction identifiers, processing fee, status, and the email address Stripe associates with the receipt. Card details are submitted directly to Stripe and are not stored by Captchainbox.

1.4 Payout Information

If an inbox owner chooses self-payout, Stripe collects identity, eligibility, tax, and bank-account information for its connected-account onboarding. Captchainbox stores the connected account identifier, onboarding status, payout destination, and transaction-ledger entries. Stripe handles the underlying identity and bank details.

1.5 Usage Data

We collect anonymized analytics data (page views, feature usage) to improve the service. We use Umami, a privacy-focused analytics tool that does not use cookies and does not collect personally identifiable information.

1.6 Referral Data

We store each account's referral code, the relationship between a referring account and a newly created account, and commission ledger records generated by qualifying sender payments. Referral reporting is aggregate and does not show the referred person's identity or email address to the referrer.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Captchainbox service
  • Build and maintain your trusted sender whitelist based on your email history
  • Archive emails from unknown senders and send them verification challenges
  • Unarchive emails and whitelist senders who complete verification
  • Manage grace periods for recently verified senders
  • Calculate transaction splits and facilitate selected payouts
  • Attribute new accounts and calculate referral commissions
  • Handle payment refunds, disputes, and transfer reversals
  • Send you service-related notifications
  • Improve and optimize our service

3. Data Storage and Security

Your data is stored securely using Supabase (hosted on AWS infrastructure) with row-level security policies enforced at the database level. OAuth tokens are stored encrypted. We use HTTPS for all data transmission.

We retain operational account data for as long as your account is active. If you delete your account, we delete account-specific inbox data, including your whitelist, email analysis records, and stored OAuth tokens. We may retain de-identified transaction, payout, refund, and accounting records for the period required by tax, financial, fraud prevention, and other applicable laws.

4. Third-Party Services

We use the following third-party services:

  • Google Gmail API – to access and manage your email on your behalf. Subject to Google API Services User Data Policy, including the Limited Use requirements.
  • Supabase – for authentication, database, and serverless functions.
  • Cloudflare Turnstile – for CAPTCHA verification of unknown senders.
  • Vercel – for hosting and serving the web application.
  • Umami – for privacy-friendly, cookie-free analytics.
  • Stripe – for sender payment processing, connected-account onboarding, and payouts. Senders submit card details directly to Stripe. Inbox owners who select self-payout submit identity and bank details directly to Stripe. Captchainbox receives transaction identifiers, amounts, fee and status data, connected-account identifiers, and onboarding status. Stripe's data retention is governed by Stripe's Privacy Policy.

5. Google API Services User Data Policy

Captchainbox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only request access to the Gmail scopes necessary for the service to function (reading metadata, modifying labels, sending verification emails).
  • We do not use Gmail data for advertising or to serve ads.
  • We do not allow humans to read your email data unless required for security purposes, to comply with applicable law, or with your explicit consent.
  • We do not transfer Gmail data to third parties except as necessary to provide the service, as required by law, or with your consent.
  • We do not use Gmail data to develop, improve, or train generalized artificial intelligence or machine learning models. Any AI features (such as our optional agent-to-agent reply assistant) operate only on data for the requesting user and do not feed training pipelines.

6. Data Sharing

We do not sell, rent, or trade your personal information. We only share data with the third-party service providers listed above, solely to operate the service. We may disclose information if required by law or to protect our rights.

7. Your Rights

You have the right to:

  • Access your data through the Captchainbox dashboard
  • Revoke access to your Gmail account at any time through your Google Account permissions
  • Delete your account and all associated data by contacting us
  • Export your whitelist data from the dashboard

8. Cookies

We use essential cookies for authentication and session management. If you follow a referral link, we also store a first party referral code cookie for up to 30 days so a new account can be credited to the person who shared the link. The first valid referral code remains in place during that period and the cookie is removed after a successful account callback. We do not use third party advertising cookies.

9. Children's Privacy

Captchainbox is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

11. Contact Us

If you have questions about this Privacy Policy, please contact us at felixdoerp@gmail.com.