Legal

Privacy Policy

Last updated: October 4, 2026

This policy explains what personal data InboxRampUp collects, how we use it, who we share it with and the choices you have. It applies to inboxrampup.com and the InboxRampUp app and API.

1. Who we are

InboxRampUp (inboxrampup.com) is operated by AI Ekip Inc. ("AI Ekip", "we", "us"). We are the controller of the personal data described in this policy. Questions or requests about your data go to support@inboxrampup.com.

2. Data we collect

We collect only what we need to run the service:

  • Account data: your name, email address, a hash of your password (never the password itself), and your two-factor authentication settings if you enable them. If you sign in with Google or Microsoft, we receive your name, email address and profile picture from that provider.
  • Workspace data: organization names, team memberships and roles, invitations you send, notification preferences, API keys (stored only as a hash) and an audit log of significant actions taken in your workspace.
  • Connected mailbox data: each connected mailbox's email address and provider, the connection settings you enter (such as IMAP/SMTP host, port and username), and the credential that lets us act on the mailbox (an OAuth refresh token, IMAP/SMTP password or SMTP relay API key). Credentials are encrypted at rest with AES-256-GCM.
  • Warmup data: the warmup messages our platform generates and sends between mailboxes in the warmup network (their subject and text, sender, recipient and timestamps), the engagement actions taken on them (opened, rescued from spam, marked important, starred, archived, replied), the folder they landed in, and the reputation scores and deliverability results we compute from that.
  • Domain health data: the DNS records (SPF, DKIM, DMARC, MX) of the domains your mailboxes use, and whether their sending IP addresses appear on public blocklists.
  • Billing data: your plan, billing cycle, subscription status and renewal date. Payments are handled by Lemon Squeezy (see "Who we share data with"); we never receive or store your card details.
  • Security and technical data: for each signed-in session, its IP address, browser user agent and expiry, which we use to keep your account secure.

3. How we access your mailboxes

Warmup works by sending messages between mailboxes in our network and interacting with the messages that arrive. To do that, InboxRampUp acts on each mailbox you connect, and only for warmup:

  • Sending: we send warmup messages from your mailbox, on the schedule and at the volume set in your warmup settings, to other mailboxes in the network. Every warmup message carries a hidden marker header (X-EW-Warmup) that identifies it as warmup traffic.
  • Finding warmup messages: we check recently received messages for that marker. With Gmail we request only the marker header, never the body, sender, subject or other headers. With IMAP the mailbox server does the filtering. With Microsoft we read message headers to look for the marker. Messages without the marker are ignored immediately; we never store, read or analyze their content.
  • Engaging: on warmup messages only, we mark them read, move them from spam to the inbox, mark them important, star or archive them and reply to them, because these are the signals mailbox providers use to judge sender reputation.

We do not read, index, store or use your personal email, contacts or calendar, and we never send anything from your mailbox other than warmup messages. Disconnecting a mailbox stops all activity on it immediately, and you can also revoke our access from your Google or Microsoft account settings at any time.

Other mailboxes in the warmup network, including those of other InboxRampUp customers and mailboxes operated by us, receive your warmup messages and therefore see your mailbox's email address as the sender, just as you see theirs. Warmup message content is generated by our platform; it never contains your own email content.

4. Google user data

When you connect a Gmail or Google Workspace mailbox, we request the gmail.modify permission. We use it only to send warmup messages from that mailbox, detect incoming warmup messages and perform the warmup engagement actions described above. We do not use Google user data to develop, improve or train AI or machine-learning models, we do not use it for advertising, and we do not sell it or transfer it to third parties except as needed to provide the service, to comply with law, or as part of a merger or acquisition with your notice.

InboxRampUp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. How we use data

  • To provide the service: run warmup, compute reputation and deliverability, check domain health, and show you the results.
  • To operate your account: sign-in, two-factor authentication, team invitations, billing and plan limits.
  • To send service email: email verification, password resets, invitations and the alerts you have switched on. We do not send marketing email without your consent.
  • To keep the service secure and reliable: detecting abuse, rate limiting, audit logging and troubleshooting.
  • To provide support. Our operators can open a workspace to help with a support request or investigate abuse; every such action is recorded in that workspace's audit log, and a banner shows on screen while it happens.
  • To meet legal obligations, such as tax and accounting records.

7. Who we share data with

We do not sell personal data. We share it only with service providers that help us run InboxRampUp:

  • Supabase, which hosts our database.
  • vps.tc, which hosts our application servers in Istanbul, Türkiye.
  • Cloudflare, which provides our DNS.
  • Lemon Squeezy, our payment provider and merchant of record, which processes payments, taxes and invoices under its own privacy policy.
  • Our transactional email provider, which delivers account and alert emails.
  • Google and Microsoft, when you connect mailboxes they host or sign in with them.
  • The mail servers and SMTP relays you configure for your mailboxes.
  • Public DNS blocklist operators (Spamhaus and Barracuda), which receive your mailbox's sending IP address when we check it against their lists.

We may also disclose data when the law requires it, to protect the rights, safety or property of our users or the public, or to a successor if InboxRampUp is sold or merged, in which case this policy continues to apply to your data.

8. International transfers

Our servers are in Türkiye, and some of our service providers process data in other countries, including the European Union and the United States. Where data leaves the country it was collected in, we rely on the safeguards the applicable law provides, such as standard contractual clauses.

9. How long we keep data

We keep your data for as long as your account is active. When you delete your account in Settings → Profile, we immediately delete your user account and every workspace you are the only member of, including its mailboxes, their encrypted credentials and all warmup data. In workspaces you share with others, your membership is removed and the workspace stays with its remaining members.

Deleted data may remain in our database provider's encrypted backups until they expire on their normal schedule. Billing records held by Lemon Squeezy are kept for as long as tax law requires.

10. Security

We encrypt data in transit with TLS and encrypt mailbox credentials at rest with AES-256-GCM. Passwords and API keys are stored only as hashes, two-factor authentication is available for every account, and access to production systems is restricted to authorized operators. No system is perfectly secure; if a breach affects your data, we will notify you and the relevant authorities as the law requires.

11. Your rights

Depending on where you live, you can ask to access, correct, export or delete your personal data, to restrict or object to how we process it, and to withdraw any consent you gave. You can do most of this yourself:

  • Export your data as JSON, or delete your account, in Settings → Profile.
  • Disconnect any mailbox from its mailbox page, or revoke our access in your Google or Microsoft account settings.
  • Change your name in Settings → Profile and your alerts in Settings → Notifications.

For anything else, email support@inboxrampup.com and we will respond within 30 days. You also have the right to complain to your local data protection authority; in Türkiye, that is the Personal Data Protection Authority (KVKK).

12. Cookies

We use only the cookies the service needs to work: a session cookie that keeps you signed in, and a cookie that remembers which workspace you last selected. We do not use analytics, advertising or tracking cookies, and we do not load third-party tracking scripts.

13. Children

InboxRampUp is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.

14. Changes to this policy

We may update this policy as the service changes. We will post the new version here with a new "Last updated" date, and if the changes are significant we will notify you by email or in the app before they take effect.

15. Contact

AI Ekip Inc., operator of InboxRampUp. Email: support@inboxrampup.com.