Privacy Policy

Last updated 3 September 2026

Who we are

InboxGuards is owned and operated by Orion CMD LLC, Omaha, Nebraska (“we”, “us”). This policy explains what information we collect when you use InboxGuards, why we collect it, and what we do with it. Questions: hello@inboxguards.com.

What we collect

Account information. Your name, email address, and the organization name and notification email you provide when you sign up.

Audit log metadata. When you connect Microsoft 365 or Google Workspace, we read your tenant's audit logs with read-only access. This includes metadata such as sign-in events (account, IP address, approximate location), mailbox rule and forwarding changes, app consent grants, admin role changes, and security setting changes. We store only the events that trigger an alert, along with a short evidence excerpt of the audit record.

Security posture data. To power the daily security posture check and monthly scorecard, we also read — with the same read-only access — your user directory (user email addresses and whether each has multi-factor / 2-Step Verification enabled), guest account counts and ages, tenant security configuration status (such as whether Microsoft security defaults are on), and sign-in events your provider itself has flagged as risky. We store aggregate counts plus a limited sample (up to 50) of the addresses of users without MFA, kept as a single snapshot per organization that is overwritten on each check.

Dark-web check data. Once a day (and when you press Scan now) we read the primary email address of each user in your directory and check it against two breach-data services, Have I Been Pwned and LeakCheck, plus each email domain your users have. We store one record per address (the address, when it was last checked, and the names of the leaks it has already been reported in) and one per domain (the domain, when it was last swept, and which leaked addresses have already been reported). Findings become alerts naming the leak, its date, and the kinds of data exposed. Leaked values themselves — such as passwords — are never stored or shown.

Domain and departure-watch data. If you configure a DMARC reporting domain, mail providers send aggregate DMARC reports for that domain to a reporting mailbox we operate; we store the report rows (sending-server IP, message counts, authentication results, reporting provider) per organization. Once a week we look up common misspellings of your domain in public DNS and store any that are registered (the domain name and its mail servers). If you list accounts on your Departure Watch, we store those email addresses on your organization record until you remove them.

Usage estimates. We keep an estimate of the number of active users in your tenant (derived from distinct sign-in accounts in the audit log) for per-user billing.

Payment information. Payments are processed by our payment provider, Base44 Payments (Wix). We never see or store your card number — we keep the checkout and subscription identifiers, billing status, seat count, purchaser email, and amount.

Optional integrations. If you connect Slack, we store the workspace bot token and selected channel details needed to send alerts. The token is removed when the organization is deleted.

What we do NOT collect

We do not read, store, or have access to the content of your email, your files, or your passwords. Our access to your tenant is read-only and limited to audit/activity logs, security configuration status, and basic directory metadata (user email addresses and MFA enrollment status). We cannot change anything in your tenant. We do not sell your data, and we do not use it for advertising.

How we use your information

We use the information above solely to:

• Detect and alert you to suspicious activity in your tenant.
• Send you the alert emails, digests, and reports you configure.
• Bill your subscription and provide support you request.
• Keep the service running securely and diagnose problems.

Google API Services disclosure

InboxGuards’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access only the Google Workspace Admin SDK Reports API (audit logs, read-only) and the Admin SDK Directory API (read-only, limited to user email addresses, suspension status, and 2-Step Verification enrollment status), and use that data only to provide security alerting and posture reporting to you. The only onward transfer is the daily dark-web check described above: each user's primary email address is sent to Have I Been Pwned (as the address) and to LeakCheck (as a one-way SHA-256 hash) solely to check for credential leaks on your behalf. No other Google user data is transferred to anyone, and none of it is used for advertising.

Google Ads conversion tracking

We advertise InboxGuards on Google. To measure whether those ads work, our public website and sign-up flow include a Google Ads conversion tracking tag. If you arrive from a Google ad and later create an account, start checkout, or begin a paid subscription, a conversion event is recorded.

What the tag collects. A Google click identifier (GCLID) set when you clicked the ad, the time of the conversion, and for billing events the subscription amount. It does not collect your name, email address, or anything from your Microsoft 365 or Google Workspace tenant. Tenant and audit-log data is never used for advertising.

Google’s role. Google uses this data to report conversions to us and to optimize how it delivers our ads. Google’s own handling of it is described at policies.google.com/technologies/ads.

Your control. You can opt out of personalized advertising from Google at google.com/settings/ads. Blocking third-party scripts in your browser also prevents the tag from loading; InboxGuards works the same either way.

Sharing

We share data only with the services needed to run InboxGuards: Base44 and its hosting/email infrastructure, Microsoft or Google when you authorize the relevant connection, Base44 Payments (Wix) for billing, Slack when you enable Slack alerts, Really Free Geo IP or ipwho.is for IP geolocation (they receive only the IP address being looked up, not the related account identity), and — for the daily dark-web check — Have I Been Pwned (which receives each user email address in plain form, as its API accepts nothing else) and LeakCheck (which receives a one-way SHA-256 hash of each address, plus each email domain your users have). Neither breach service receives account identity, audit-log contents, or anything beyond the address or domain being checked. The weekly lookalike-domain check sends generated misspellings of your domain to Cloudflare's public DNS-over-HTTPS resolver; that is an ordinary DNS query and carries no customer data. We may disclose information if required by law. We never sell or rent your data.

Retention and deletion

Alert and account data is kept while your account is active. When an organization is deleted, stored Google and Slack credentials are deleted immediately, monitoring access is disconnected, and organization-linked records are moved to an operator-only archive for nine months for dispute and recovery purposes and then automatically purged; dark-web check records follow the same nine-month archive and purge. Operational IP-geolocation cache entries and monitor-run summaries are retained for no more than 90 days. You can request account deletion at any time by emailing hello@inboxguards.com. Disconnecting your Microsoft 365 or Google Workspace tenant (revoking our access in your admin console) immediately stops all collection.

Security

InboxGuards uses TLS for supported provider and browser connections. Application access controls restrict organization-linked records by organization and role. Operator access is limited to authorized administrative functions. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify affected customers as required by applicable law.

Your rights

You may request a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Email hello@inboxguards.com and we will respond within 30 days.

Changes

If we make material changes to this policy, we will update the date above and notify active customers by email. See also our terms of service, disclaimer, and refund policy.

Arm your inbox

Add bounded monitoring to supported audit records.