Privacy Policy
Effective Date: February 25, 2026
At Armorstack, we are committed to protecting your privacy and securing your personal information. As an AI-powered Managed Intelligence Provider specializing in cybersecurity, IT operations, strategic advisory, and physical security, we prioritize data protection in all our interactions, including on our website, social media pages, and related services.
This Privacy Policy explains how Armorstack, LLC (hereinafter “Armorstack,” “we,” “us,” or “our”) collects, uses, discloses, retains, and safeguards your personal information. It also describes your rights under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the California Online Privacy Protection Act (CalOPPA).
By engaging with our website, social media pages (including Facebook and Instagram), or related services, you acknowledge that you have read and understand this Privacy Policy. Where required by law, we will obtain your consent before processing your personal data.
Armorstack – The Standard of Truth in Technology.
Unifying security for a resilient future.
InboxSentry Privacy Addendum
Effective: April 28, 2026 — Supplements the Privacy Policy above for the InboxSentry desktop application and related services.
Why a separate section? Most Armorstack services (advisory, managed security, vCIO/vCISO, CITADEL physical security) are professional services where Armorstack personnel access client systems under contract. InboxSentry is materially different. InboxSentry is a desktop application engineered for local-first processing and minimal data egress. Where the master Privacy Policy and this addendum address the same topic, the more protective provision controls.
Variance Summary
| Topic | Other Armorstack Services | InboxSentry |
|---|---|---|
| Email content storage | May be reviewed by Armorstack personnel under MSA | On-device only, encrypted at rest, never transmitted to Armorstack |
| Mailbox credentials | May be provisioned for service technicians | OAuth-only; tokens never stored on device in plaintext |
| AI processing | Generally not applicable | Email metadata sent to Anthropic Claude for triage; full bodies only on user-requested reply drafts |
| Data residency | United States (Armorstack infrastructure) | On-device for email content; minimal metadata in U.S. infrastructure |
| Data subject access | Per MSA | Self-serve via the application; uninstall = full deletion of local data |
1. Information InboxSentry Collects
Account & licensing. Email address used for license issuance, Stripe customer ID (Stripe processes payment cards; Armorstack never receives card data), a non-reversible hardware device fingerprint used to enforce per-license device limits, and license heartbeat metadata (last-active timestamp, app version, OS version).
OAuth authorization. InboxSentry uses Google OAuth for Gmail and Microsoft OAuth for Outlook/M365 with minimum-necessary scopes. Refresh tokens are stored only in encrypted server-side connector storage at our serverless backend provider; tokens are not stored on user devices in plaintext and are not exposed through any application API.
Email metadata for AI triage. For each scanned message, InboxSentry sends the following to Anthropic Claude: sender address, sender name, subject line, timestamp, and a short content snippet (typically the first 500 characters). Full message bodies are NOT sent for standard triage. Under our enterprise terms with Anthropic, prompts and outputs are not used to train Anthropic models.
AI reply drafting (v2.1+). Full message thread context is sent to Anthropic only when the user explicitly requests a draft.
Local content. Email bodies, attachments, sender history, and triage results live in an encrypted SQLite database on the user device. This content is never transmitted to Armorstack, our backend provider, or any third party. Uninstalling InboxSentry deletes the local database.
2. InboxSentry Sub-Processors
| Sub-Processor | Purpose | Data Handled | Region |
|---|---|---|---|
| Stripe, Inc. | Payment processing | Email, billing details | United States |
| Anthropic, PBC | AI inference (Claude API) | Email metadata; reply context on user request | United States |
| Google LLC | OAuth provider (Gmail) | OAuth grant | United States |
| Microsoft Corporation | OAuth provider (Outlook/M365) | OAuth grant | United States |
| Cloudflare, Inc. | CDN delivery of installer + manifest | IP address (transient) | Global edge |
| Base44 | Serverless backend hosting | License + token data | United States |
3. Your Rights for InboxSentry Data
All rights set forth in the master Privacy Policy above (access, rectification, erasure, portability, objection) apply to InboxSentry data. Exercise them by emailing [email protected]. Note that uninstalling the application also deletes all on-device email data — no Armorstack action required.
4. Data Retention
- License records: active period + 7 years (tax compliance)
- OAuth refresh tokens: until you disconnect the account or revoke at Google/Microsoft
- Email metadata sent to Anthropic: not retained by Armorstack; Anthropic retains per their stated policy
- Local on-device data: until you uninstall or delete manually
5. Security Posture
InboxSentry has been audited and hardened against eleven specific findings, each remediated and mapped to NIST 800-53 Rev. 5 controls and (where applicable) DISA STIG requirements. The full Security Audit & Hardening Report is available to enterprise customers under NDA via [email protected]. See also the Security & Vulnerability Disclosure Policy.
6. Brand Separation Notice
The InboxSentry product, the inboxsentry.ai domain, and product-specific marks are owned by Armorstack, LLC and may be transferred independently of the broader Armorstack business. In the event of such a transfer, this addendum will be updated and active license holders will receive thirty (30) days advance notice. The master Privacy Policy above governs all other Armorstack services and is unaffected by such a transfer.
7. Contact for InboxSentry-specific Privacy Inquiries
Email: [email protected] (subject line: “InboxSentry Privacy”)
Mailing: Armorstack, LLC, Waukesha, Wisconsin