Privacy Policy
Last updated 6 September 2026
intbox works with the contents of your conversations. This is what we collect, what leaves your device, how long we keep it, and how to delete it.
Introduction
intbox (intbox.ai) is operated by Ascimov Technologies Private Limited, registered at Door No. 340/D, Room No. 3EACE Kunjo Plaza, Kombara Junction, Kochi, Ernakulam, Kerala – 682018, India (CIN: U62013KL2025PTC093452). This policy covers our website and our applications. intbox connects to messaging channels you choose and turns the information inside them into structured records you can search and export.
Data we collect
- Account information — name, email address and authentication details.
- Structured records — contacts, commitments, collections and other output extracted from your chats. We hold these in readable form, because that is what makes search and export work.
- Your archive — your conversation history, encrypted on arrival under a key held only on your devices.
- Device and usage data — device model, operating system, app version, and diagnostic and crash reports.
Analytics, cookies and advertising
Our website uses cookieless analytics to count page views. It sets no cookies and builds no per-visitor profile. The apps do not use cookies.
We also use the Meta Pixel and Conversions API to measure how our advertising performs. These set advertising cookies in your browser (_fbp and _fbc) and share event data with Meta: the pages you visit and actions you take, together with your IP address and browser details. Where you have given us your email address or phone number, we may send it to Meta in hashed form so it can match a visit to an account. Meta uses this to measure and target advertising, and processes it as a controller in its own right under its data policy.
You can limit this in your Meta ad settings, or by blocking these cookies in your browser. Email admin@intbox.ai to ask us to stop sending your data to Meta.
How we use and process personal data
We use your data to run your account, connect the channels you choose, and extract structure from your conversations. Each channel connects through a bridge on our servers, which encrypts your messages as they arrive. The key that unlocks them is held only on your devices, so we cannot read your stored conversations; your device keeps a local decrypted copy, and that is what you search.
To extract structure, your device sends message text to a third-party AI model provider. Before it is sent, identifiable details — names, phone numbers, email addresses and similar — are replaced with placeholder tokens on your device and mapped back locally when the result returns. This matching is pattern-based and may not catch everything. There is more detail on how this works.
We process content only from channels you connect. Disconnecting a channel stops new capture immediately. We do not sell your data, and your conversations and the records extracted from them are never shared for advertising — the advertising data described above is website activity only.
Third-party services
We rely on these categories of provider:
- Infrastructure and hosting — running the service and storing your account, records and encrypted archive.
- Analytics — cookieless page-view counts for the website.
- Advertising and measurement — Meta Platforms, for measuring and targeting our advertising, as described above.
- AI model providers — extraction, summarisation and question answering. We describe them by category rather than naming a vendor, because we test and change models as the technology moves. Customers with a data processing agreement can request the current identities.
- Payment processors — if we introduce paid plans, payment details go to the processor directly and are not stored by us.
On training: we do not train on your conversations, and we choose providers whose terms exclude your content from training wherever we can — but we cannot guarantee what a third-party API does with data sent to it, which is why identifiable details are stripped out before anything is sent.
Data security
Your archive is stored encrypted, under a key we do not hold. Access to the structured records we hold is restricted and monitored, and no one at Ascimov reads your messages as part of normal operation.
Data retention
We keep your data while your account is active. If an account is inactive for three months we delete it and everything in it. You can delete your data yourself from the app at any time, or ask us to; deletion removes your records and your encrypted archive from our servers within 30 days.
Your rights
You can access, correct, export or delete your data. Most of this is available in the app; for anything else, email admin@intbox.ai and we will act on your request. If we do not resolve a complaint to your satisfaction, you can raise it with our Grievance Officer below and then with the Data Protection Board of India.
Children’s privacy
intbox is for people aged 18 and over. We do not knowingly collect data from children. If we learn that we have, we delete it.
Updates to this policy
We will update this policy as the service changes, and will revise the date at the top when we do.
Contact
admin@intbox.ai, or write to us at Ascimov Technologies Private Limited, Door No. 340/D, Room No. 3EACE Kunjo Plaza, Kombara Junction, Kochi, Ernakulam, Kerala – 682018, India.
Grievance Officer: P Mathew Varghese — admin@intbox.ai, appointed under India’s Digital Personal Data Protection Act, 2023.