Last updated: 2026-08-14

Privacy Policy for InboxHub

PaluHub (“we”, “us”) operates InboxHub, a customer-support CRM with built-in AI. This Privacy Policy explains what data we collect when you connect channels (WhatsApp, Instagram, Messenger, TikTok, email, and others) and optional integrations such as calendars, and how that data is used—especially when AI features are enabled.

1. Who we are

InboxHub is a product operated by PaluHub. It is an independent software platform that integrates official third-party APIs (including TikTok, Meta, and Google). We are not affiliated with, endorsed by, or sponsored by TikTok, Meta, Google, Microsoft, OpenAI, Anthropic, or other platform providers.

2. Data we collect

Depending on the channels and integrations you connect and the permissions you grant, we may collect and process:

  • Public profile information from connected platforms (for example display name, avatar, and public identifiers).
  • Direct messages and conversation content exchanged with your business through connected inboxes.
  • Comments and related public interaction data where the connected API exposes them for customer support.
  • Media metadata for images, audio, and video attached to conversations (and, where permitted, media content needed to display or process the message).
  • Account and workspace data for InboxHub users (name, email, organization, roles, billing-related records).
  • Technical logs needed to operate the service (timestamps, delivery status, webhook events, error diagnostics).
  • Calendar data when you connect a scheduling provider (see section 5).

3. How we use information

Data is processed to centralize business communication, reply to customers, and—if you enable it—book appointments. Specifically, we use information to:

  • Display conversations in a unified InboxHub dashboard for your agents.
  • Route, assign, label, and escalate conversations according to your configuration.
  • Power AI assistants that draft or send automated replies when you enable them.
  • Provide knowledge features (for example your company documents) that you configure.
  • Create or update calendar events and, if you enable it, video-meeting links, so appointments requested in chat can be booked.
  • Operate billing, security, abuse prevention, and support.

4. AI processing

When AI features are enabled for your organization, messages and related context may be processed by large language model providers (such as OpenAI, Anthropic, or other providers configured for your plan) to generate automated responses, suggestions, or actions (for example proposing a time slot).

We use provider APIs for inference. We do not use your conversation content or calendar data to train our own global foundation models, and we instruct production traffic to use provider API modes that do not opt customer content into the provider’s model-training programs where such controls exist.

You may disable AI or disconnect integrations at any time from InboxHub. Human agents remain responsible for supervising automation.

5. Calendars and scheduling (Google and Microsoft)

InboxHub can connect a work calendar so AI or your team can book appointments from a conversation. Google Calendar is available today. The same purpose applies to Microsoft 365 / Outlook when a workspace connects it.

If you authorize Google Calendar via OAuth, InboxHub may, according to the permissions you grant: read calendars and events to offer free/busy times; create, update, or cancel events on your behalf; and, if you enable it, include a Google Meet link.

We store OAuth tokens (access and, when Google issues it, refresh) to act on your behalf until you disconnect the integration. We do not sell calendar data. We do not use your calendar for advertising.

You can revoke access in InboxHub and also in your Google Account (or, when the integration exists, in Microsoft). Disconnecting stops new events; appointments already created in Google or Microsoft remain in those accounts unless you delete them there or request deletion under our Data Deletion Instructions.

6. Data transfers between systems

Message, profile, and calendar data travel between official platform APIs (for example TikTok API, WhatsApp Business / Meta APIs, Google Calendar) and InboxHub. When AI is enabled, relevant content may also be sent to the configured LLM provider, then returned to InboxHub for delivery on the original channel or written to the calendar.

Transfers occur over HTTPS and only for the purpose of operating the services you requested.

7. Retention

We retain conversation data, integration tokens, and account data for as long as your InboxHub account remains active and as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements.

After a verified deletion request (see our Data Deletion Instructions), we delete or anonymize applicable personal data from our systems within thirty (30) days, except where we must retain limited records for legitimate legal, security, or accounting reasons.

8. Sharing and sale of data

We do not sell personal data to third parties. We share data only with: (a) subprocessors needed to run InboxHub (hosting, email, LLM APIs) under contractual controls; (b) the channel and calendar platforms you connect, as required to send/receive messages or create events; and (c) authorities when legally required.

9. Your choices and rights

Workspace admins can disconnect channels and calendars, manage agent access, and disable AI features. End users of TikTok, Meta, or Google may also use those platforms’ privacy tools. To request deletion of data stored in InboxHub, email us as described in the Data Deletion Instructions.

10. Contact

Privacy and deletion requests: [email protected]. Commercial inquiries: [email protected].