BetterBox

Privacy Policy

Last updated: June 24, 2026

BetterBox is a faster, denser web client for your Google inboxes, built on the Gmail API, that can also bring your GitHub pull requests and issues alongside your mail. It is operated by Aidan McAlister as an individual developer (“BetterBox,” “we,” “us”). This policy explains what data we access, why, how long we keep it, and the choices you have. BetterBox is not affiliated with or endorsed by Google.

BetterBox is in active development and has not yet completed Google’s verification, so when you sign in Google shows an “unverified app” warning. This is expected: to continue, click Advanced, then Proceed to BetterBox. It is a client for Gmail, not a new email service. Your email continues to live in your Google account.

1. Information we access and collect

We keep what we collect to the minimum needed to run the client.

From your Google account (with your consent)

  • Basic profile: your name, email address, profile picture, and Google account identifier, used to show who is signed in and to label your inboxes.
  • OAuth tokens: the access and refresh tokens Google issues so the app can stay signed in and call the Gmail API on your behalf. These are encrypted at rest in our database.

Gmail data, accessed through the Gmail API

With the gmail.modify scope you grant, BetterBox can read your messages and their metadata, send messages on your behalf, and change message state (such as marking as read or adjusting labels). This data is fetched on demand to display and act on your mail inside the app.

We do not store the contents of your emails on our servers. Message headers and bodies are retrieved from Google when you open or act on them and are held only transiently in your browser to render the interface. We do not maintain a server-side copy or archive of your mailbox.

From GitHub (optional, if you connect it)

BetterBox can show your GitHub pull requests, review requests, and issues (those assigned to or opened by you) alongside your inbox. If you connect a GitHub account, we store the OAuth tokens GitHub provides (encrypted at rest, the same as Google) and use them to make read-only calls to the GitHub API on your behalf. We do not write to your repositories, and your GitHub data is fetched on demand rather than stored on our servers. Connecting GitHub is optional; you can use BetterBox with Gmail alone.

Automatically, to operate the service

  • Session & technical data: a session token, your IP address, browser user-agent, and timestamps, used to keep you signed in and to protect the account against abuse.

We do not use third-party advertising, analytics, or tracking SDKs, and we do not place non-essential cookies.

Your app preferences (theme, layout, density, and similar settings) are stored locally in your browser and are never sent to or stored on our servers.

2. How we use your information

  • To authenticate you and keep your session active.
  • To display, search, compose, send, and organize your mail through the Gmail API.
  • To operate, maintain, debug, and secure the service, including preventing unauthorized access.
  • To comply with legal obligations where applicable.

We do not use your data for advertising, profiling, or building a marketing profile, and we never sell it.

3. Google API Services: Limited Use

BetterBox’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use access to Google user data to provide and improve the user-facing features of BetterBox.
  • We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition.
  • We do not use Google user data for serving advertisements.
  • We do not allow humans to read your Gmail data unless we have your affirmative consent for specific messages, it is necessary for security or to comply with applicable law, or the data has been aggregated and anonymized.

4. How your information is shared

We do not sell your personal information. We share data only with:

  • Google, to authenticate you and access the Gmail API at your direction.
  • GitHub, if you connect it, to access the GitHub API at your direction and show your pull requests and issues.
  • Stripe (coming soon), our payment processor for hosted-plan billing once it launches. Stripe will collect and process your payment details directly under its own privacy policy; BetterBox does not receive or store your full card information.
  • Infrastructure providers that host the application and database under our instruction (acting as data processors), solely to operate the service.
  • Legal authorities, where required by valid legal process or to protect rights, safety, and security.

5. Data retention

  • Profile and OAuth tokens: kept while your account is connected. When you disconnect or request deletion, they are removed from our database.
  • Session & technical data: retained for the life of the session and a short period afterward for security, then deleted.
  • Email contents: not retained, fetched on demand and not persisted on our servers.

6. Your choices and rights

  • Revoke access at any time from your Google Account under Security → Third-party access. Revoking immediately stops BetterBox from accessing your Gmail.
  • Access or delete your data: email us and we will delete your stored profile, tokens, and session records.

Depending on where you live, you may have additional rights. If you are a California resident (CCPA/CPRA), you have the right to know what personal information we collect, to request deletion, and not to be discriminated against for exercising those rights, and we confirm we do not sell or share your personal information. If you are in the EEA or UK (GDPR), you have rights to access, correct, delete, restrict, and port your data, and to object to processing; our legal bases are your consent and the performance of our service to you. To exercise any of these, contact us below.

7. Security

Data is transmitted over encrypted connections (TLS), and OAuth tokens are stored in an access-controlled database. We restrict access to the systems that hold your data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to respond promptly to any incident.

8. Children's privacy

BetterBox is not directed to children under 13 (or the minimum age of digital consent in your country), and we do not knowingly collect their data. If you believe a child has provided us information, contact us and we will delete it.

9. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by updating the “Last updated” date above, and where appropriate we will provide additional notice. Continued use after an update means you accept the revised policy.

10. Contact

For any privacy question or request, email aidankmcalister@gmail.com. We will respond as promptly as we reasonably can.

Operated by Aidan McAlister · aidankmcalister@gmail.com