Legal

Privacy Policy

1. Who We Are and What This Policy Covers

LitInboxes, a product of CINELLI E TRINDADE TECNOLOGIA LTDA (trading as HalTuring) ("LitInboxes", "we", "us", "our"), provides an email deliverability monitoring platform. This Privacy Policy covers the marketing website at litinboxes.com, the application at app.litinboxes.com, our API and MCP server, our free tools, and the forms we operate.

It explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have. For your account, billing, and website data, LitInboxes acts as the data controller. For content you submit that contains information about other people (for example, email addresses you verify or reports about your own sending), we process that data on your behalf and under your instructions in order to provide the service.

If anything in this policy is unclear, contact us at support@litinboxes.com.

2. Information You Provide

Account information

When you register we collect your name, email address, password, and language preference. Passwords are stored as secure one-way hashes and are never readable by us. If you sign in with Google or GitHub, we receive your name and email address from that provider. You can also choose whether to receive our newsletter.

Billing information

Payments are processed by Stripe. We store your plan, subscription status, billing email, and references to invoices. Full card details are handled by Stripe and never touch our servers.

Domains and monitoring settings

The domains you add, their DNS records and check results, blocklist and reputation status, health scores, and your alert preferences.

Email content you submit

When you run a spam check we process the subject, body, and headers of the email you paste or forward to your unique check address. When you use email preview we process the HTML you submit and the screenshots rendered from it. When you verify addresses we process the addresses you enter or upload; uploaded files are parsed in memory and are not stored, we keep only the file name and the per-address results.

DMARC reports

Mailbox providers send DMARC aggregate and failure reports to the unique LitInboxes reporting address you configure. Aggregate reports include sending source IPs and authentication results. Failure reports can include headers and fragments of individual messages.

Forms and inquiries

If you request a lead magnet, join a waitlist, run the email health assessment, send a contact message, or submit a consulting inquiry, we collect the details you enter (such as name, email, company, and your answers) together with your IP address and the page you submitted from. These forms are protected by Cloudflare Turnstile to prevent abuse.

3. Information We Collect Automatically

  • Sign-in history: the time and IP address of your recent sign-ins, kept for account security.
  • Server logs and API usage: requests, endpoints, response codes, timing, API key identifiers, and rate-limit counters, used to operate and protect the service.
  • Product analytics: inside the application we use PostHog to understand which screens and features are used so we can improve the product.
  • Error monitoring: we use Sentry to detect and fix errors. Error reports may include a replay of your interactions with the application around the time of the error, used only for debugging.
  • Approximate location: we derive the country of your IP address using a geolocation database that runs on our own servers, only to suggest the right language. Your IP is not sent to any third party for this and no location profile is built.

The marketing website itself sets no advertising trackers and no third-party analytics.

4. Cookies and Local Storage

  • litinboxes_lang (cookie, 1 year): remembers your language choice.
  • lit_ref (cookie, 90 days, shared across litinboxes.com subdomains): set only with your consent when you arrive through a partner referral link, so we can credit the referring partner if you sign up.
  • Application storage: the app keeps your session token and interface preferences in your browser's local storage so you stay signed in. The email health assessment saves your draft answers in your browser until you submit.
  • Cloudflare Turnstile: our public forms and free tools use Turnstile to tell humans from bots; Cloudflare may set its own cookies for that purpose.

We use no third-party advertising cookies. You can clear or block cookies in your browser; the application needs its local session storage to keep you signed in.

5. Data About Other People

Some features process personal data about people who are not LitInboxes users: addresses in verification lists, message headers and fragments inside spam checks and DMARC failure reports, sender IPs, and recipient addresses in bounce or complaint events forwarded by your email provider.

  • We process this data solely to provide results and insights to you. You are responsible for having a lawful basis to submit it.
  • Verifying an address requires contacting the mail server responsible for it, which necessarily discloses the address to that mail provider.
  • To improve verification accuracy we keep aggregated deliverability signals (such as prior bounce or complaint counts) for addresses processed on the platform. These signals are used only to produce verification results, never for marketing, and are never sold.
  • If your data was submitted to LitInboxes by one of our customers and you want it removed, contact us at support@litinboxes.com and we will handle the request.

6. Connected Accounts and Google User Data

All account connections are optional, are limited to the scopes listed below, and can be disconnected at any time from your settings or revoked directly at the provider. OAuth access and refresh tokens are encrypted at rest.

Google Postmaster Tools

If you connect Google Postmaster Tools we request read-only Postmaster scopes and use them to fetch the metrics Google publishes about your sending domains: spam rate, SPF, DKIM and DMARC success rates, delivery errors, and IP or domain reputation. We store those metrics along with the email address of the Google account used, so you can identify the connection.

Mailbox connections (Gmail and Outlook)

If you connect a mailbox for deliverability testing we request read-only access (Gmail "gmail.readonly", Microsoft "Mail.Read") and use it exclusively to locate test messages you initiated and record which folder they landed in, along with their headers and authentication results.

Slack

If you connect Slack we request permission to post messages and list channels, and use it only to deliver the alerts and digests you configure to the channel you choose.

Third-party apps you authorize

You can authorize third-party applications, including AI assistants connecting through our MCP server, to access your LitInboxes data via OAuth. They receive only the scopes you approve, you can revoke them at any time, and their use of the data is governed by their own policies.

LitInboxes' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features described above. We do not use it for advertising, we do not sell it, we do not allow humans to read it except with your permission, for security purposes, or to comply with law, and we do not use it to train generalized artificial intelligence or machine learning models.

7. How We Use Information

  • Provide and operate the service: run checks, monitor domains, ingest reports, compute health scores, and deliver alerts.
  • Send transactional email such as account confirmations, password resets, alerts, and billing notices.
  • Send the newsletter and product updates when you have opted in. Every message includes an unsubscribe link.
  • Provide support and respond to your requests.
  • Prevent fraud, abuse, and security incidents, including rate limiting and bot protection.
  • Improve the product using aggregated usage information.
  • Credit partner referrals when you sign up through a referral link.
  • Comply with legal obligations, including tax and accounting rules.

8. Legal Bases

Where the GDPR (EU) or the LGPD (Brazil) applies, we rely on the following legal bases:

  • Performance of a contract: providing the service you signed up for, including processing the content you submit.
  • Legitimate interests: securing the platform, preventing abuse, improving the product, and defending legal claims.
  • Consent: the newsletter, optional account connections, and any processing where we ask you first. You can withdraw consent at any time.
  • Legal obligation: retaining billing records and responding to lawful requests.

9. AI Features

Our spam analysis and writing assistant use third-party language models. When you use these features, the email content you submitted and your conversation with the assistant are sent to the model provider, currently OpenAI, with Groq as a fallback, to generate scores, explanations, suggestions, and rewrites. Under their API terms these providers use the content to return the response and do not use it to train their models.

Suggestions and conversation history are stored with your account so you can revisit them. Avoid including sensitive personal data in content you submit to AI features.

10. Who We Share Data With

We never sell personal data. We share it only with service providers that help us run LitInboxes, with parties you direct us to send it to, or when the law requires it. Our providers:

  • Amazon Web Services: cloud infrastructure, sending and receiving email, and storage of preview screenshots.
  • Stripe: payment and subscription processing.
  • Cloudflare: website hosting and delivery, and Turnstile bot protection.
  • Google: sign-in with Google, Postmaster Tools data, Gmail connections, and web fonts on the marketing site.
  • Microsoft: sign-in to Outlook mailbox connections.
  • Slack: alert delivery, if you connect it.
  • Sentry and PostHog: error monitoring and product analytics.
  • OpenAI and Groq: AI features, as described in section 9.
  • DNS and reputation infrastructure: the domains and IPs you monitor are queried against public DNS resolvers and blocklist operators (such as Spamhaus, SpamCop, and Barracuda) to produce your results.
  • Endpoints you configure: if you set up webhook, Slack, or Discord alerts and integrations, we deliver event data to the destinations you choose.

We may also disclose data when required by law or legal process, to protect our rights and users, or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply and we will notify you of material changes.

11. Data Retention

  • Account data: kept for the life of your account.
  • Monitoring history (DMARC aggregate reports, email, bounce and complaint events, infrastructure checks, Postmaster snapshots): kept for your plan's history window, currently 30 days on Starter, 6 months on Growing, and 24 months on Pro (30 days during trials).
  • Spam checks: raw message content is deleted after 30 days; results are deleted after 180 days.
  • Verification results: deleted after 180 days. Uploaded list files are never stored.
  • DMARC failure reports: deleted after 30 days.
  • Email provider webhook payloads: deleted after 7 days.
  • Form submissions and inquiries: kept until the purpose is fulfilled or you ask us to delete them.
  • Backups and server logs: rotated on a limited schedule.

To delete your account, email support@litinboxes.com from your account address. We delete or anonymize your personal data within 30 days of a verified request, except where we are legally required to keep it (for example, billing records).

12. Links You Share

Shared reports and email health assessment results live at unlisted URLs: anyone who has the link can view them. They are excluded from search engine indexing, and some shared reports can be given an expiry date. Share these links only with people you trust.

13. Security

All traffic is encrypted in transit with TLS. Connected-account tokens and mailbox credentials are encrypted at rest. Passwords and API keys are stored as one-way hashes. Access to production systems is restricted, API keys are scoped to the permissions you grant, and rate limiting protects against abuse.

No method of storage or transmission is completely secure, so we cannot guarantee absolute security. If you believe you have found a vulnerability, report it to support@litinboxes.com.

14. International Transfers

Our service providers process data in the United States and other countries. Where data protection law applies to a transfer, we rely on appropriate safeguards such as standard contractual clauses, adequacy decisions, or the equivalent mechanisms under the LGPD.

15. Your Rights

Depending on where you live (including under the GDPR, the LGPD, and the CCPA), you may have the right to:

  • Access your personal data and receive a copy of it
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Receive your data in a portable format
  • Withdraw consent at any time, without affecting prior processing
  • Complain to a supervisory authority, such as the ANPD in Brazil or your local data protection authority in the EU

We do not sell personal information and do not share it for cross-context behavioral advertising, and we will never discriminate against you for exercising your rights. To exercise any of them, email support@litinboxes.com; we will verify your identity and respond within the legally required time.

16. Children

LitInboxes is not directed at anyone under 16 years of age and we do not knowingly collect their data. If we learn that we hold data about a child, we will delete it.

17. Changes to This Policy

We may update this policy as the product evolves. We will post the new version here and update the date at the top. For material changes we will also notify you by email or inside the application before they take effect.

18. Contact

This service is operated by CINELLI E TRINDADE TECNOLOGIA LTDA (trading as HalTuring), the controller for the personal data described in this policy.

Data protection officer (encarregado under the LGPD): Mauricio Andre Cinelli, reachable at support@litinboxes.com.

For any privacy question or request, contact support@litinboxes.com.