Spanbox
Why Spanbox Features Pricing Enterprise Blogs Contact
Legal

Privacy Policy

Last updated: 23 June 2026

Spanbox is built privacy-first. The app keeps your messages and logins on your own device, and we run no servers that can read them. This policy explains exactly what we do and don't collect, across both the Spanbox desktop app and the spanbox.co website.

Heads up: "Spanbox", "we", "us" and "our" refer to the team that builds and operates the Spanbox app and website. You can reach us any time at contact@spanbox.co. Spanbox is an independent product and is not affiliated with, endorsed by, or sponsored by WhatsApp, Slack, Google, Telegram, Discord, Meta, Microsoft or any other service you connect.

On this page
  1. Our core principle
  2. What we collect
  3. How we use it
  4. Cookies & analytics
  5. Third-party processors
  6. Payments
  7. Sharing & disclosure
  8. Data retention
  9. Security
  10. International transfers
  11. Your rights
  12. Children
  13. Connected services
  14. Changes
  15. Contact

1. Our core principle: local-first

Spanbox is a desktop app that brings your messaging and email services into one window. When you connect a service, you sign in to it inside the app, exactly as you would in a web browser. That session lives in an isolated container on your own computer.

As a result, your message content, contacts, attachments, and the credentials you use to sign in to each service stay on your device. We do not operate servers that receive, store, proxy, or read your conversations, and we cannot see them. There is nothing for us to lose, sell, or be compelled to hand over.

2. Information we collect

a) The desktop app

The app stores its working data locally on your device, for example which services you've added, your workspace and notification settings, themes, and the per-service login sessions. This data is yours and is not transmitted to us.

The app may make direct connections to (i) the services you choose to connect, and (ii) our software-update and download endpoints (e.g. GitHub Releases) to check for and fetch new versions. We do not attach personal identifiers to update checks beyond what is technically required to serve the file.

We do not collect your messages, contacts, files, or service passwords. Any optional, anonymous product telemetry (if and when offered) is off unless you turn it on, and can be disabled at any time.

b) The website (spanbox.co)

When you visit our website we use analytics and measurement tools to understand traffic and improve the site. Depending on your cookie choice, this may include your IP address (often truncated/anonymized by the tool), device and browser type, pages viewed, referring source, approximate location, and on-page interactions. See Cookies & analytics below.

c) Information you give us

  • Contact & sales forms: your name, email, company, team size, and the message you send when you contact us, request a demo, or enquire about Enterprise.
  • Purchases & licensing: the email address you provide to receive a Pro, Lifetime, or Enterprise license key, and the record of your plan.
  • Support: anything you include when you email us for help.

3. How we use information

  • To deliver and support the service, including emailing your license key and responding to enquiries.
  • To operate, secure, and improve the website and the app.
  • To process payments and manage your plan (via our payment provider, see Payments).
  • To send you service or transactional messages (e.g. license, billing, important updates).
  • With your consent, to measure marketing and show relevant ads, and to send product news you can unsubscribe from at any time.
  • To comply with legal obligations and enforce our Terms & Conditions.

We do not sell your personal information.

4. Cookies & analytics

On your first visit we show a consent banner. Non-essential cookies and analytics/marketing scripts load only after you choose Accept; if you Decline, they are not loaded. You can change your mind by clearing the site's stored choice in your browser.

Subject to your consent, we may use:

  • Google Tag Manager, to manage the tags below.
  • Google Analytics 4, website traffic and engagement.
  • Microsoft Clarity, aggregate heatmaps and session insights.
  • PostHog, product and conversion analytics.
  • Meta Pixel, advertising measurement and retargeting (only if enabled).

Essential cookies needed to remember your consent choice are always set, as they are strictly necessary for the site to function.

5. Third-party processors

We rely on a small number of reputable service providers who process limited data on our behalf, under their own terms and privacy policies:

  • Google (Tag Manager, Analytics, and Google Sheets, which receives form submissions).
  • Microsoft (Clarity).
  • PostHog (product analytics).
  • Meta (advertising, if enabled).
  • Our payment provider / merchant of record (see below).
  • Our email and code-distribution providers (e.g. for sending license keys, and GitHub for downloads).

6. Payments

Paid plans are processed by a third-party payment provider acting as merchant of record. When you pay, your card details are entered with that provider and handled under their security standards, we never see or store your full card number. We receive only what we need to fulfil your order and provide receipts and support (such as your email, plan, country for tax, and the last digits/brand of your card).

7. Sharing & disclosure

We share personal information only: with the processors listed above to run the service; where required by law, regulation, or valid legal process; to protect our rights, users, or the public; or in connection with a merger, acquisition, or sale of assets (you will be notified of any such change). Because the app is local-first, your message content is not part of any of this, we don't have it.

8. Data retention

We keep form, support, and billing records only as long as needed for the purpose collected and to meet legal, tax, and accounting obligations, then delete or anonymize them. Analytics data is retained according to each tool's configured retention period. App data lives on your device and is removed when you delete it or uninstall the app.

9. Security

We use reasonable technical and organizational measures to protect the information we hold, and we minimize what we collect in the first place. The local-first design is itself a security measure: there is no central store of your messages to breach. No method of transmission or storage is 100% secure, but we work to protect your data and to keep the app trustworthy.

10. International transfers

Our processors may store and process data in countries other than yours, including the United States. Where required, transfers are covered by appropriate safeguards such as Standard Contractual Clauses or an equivalent mechanism.

11. Your rights

Depending on where you live (for example under GDPR or the CCPA/CPRA), you may have the right to access, correct, delete, or port your personal information; to object to or restrict certain processing; to withdraw consent; and to opt out of targeted advertising or the "sale/sharing" of personal information. We do not sell personal information. To exercise any right, email us at contact@spanbox.co and we'll respond within the time required by law. You also have the right to complain to your local data-protection authority.

12. Children's privacy

Spanbox is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.

13. Connected services

When you connect WhatsApp, Slack, Gmail, Telegram, Discord, or any other service, your use of that service remains governed by that provider's own terms and privacy policy. Spanbox simply gives those services a window on your device; it does not change how they handle your data.

How Spanbox reads unread counts and previews

To show unread counts and message previews in the unified inbox, Spanbox reads the page you are already signed in to, inside that service's own window on your device. This is the same information you would see on screen. It is processed on your machine and is never sent to Spanbox or any third party.

For Slack specifically, the message text is not present in the sidebar, so Spanbox uses your existing Slack session, within Slack's own window, to ask Slack's API for the latest message in each unread conversation. This is the same call Slack's own client makes. Your Slack session token is used only inside Slack's window to make that request. It is never copied out of that window, never stored by Spanbox, and never transmitted to us or anyone else. If the request is unavailable, Spanbox falls back to showing an unread count with no preview.

You can switch off previews and notifications at any time in Settings.

14. Changes to this policy

We may update this policy from time to time. We'll change the "Last updated" date above and, for material changes, provide a more prominent notice. Continuing to use Spanbox after an update means you accept the revised policy.

15. Contact us

Questions about privacy or your data? Email contact@spanbox.co or use our contact page.

Spanbox

One calm window for every message, WhatsApp, Slack, Gmail, Telegram and 60 more, in a single inbox.

Product
Why Spanbox Features Pricing Enterprise Blogs
Company
Home Contact Help center
Connect
X (Twitter) LinkedIn Reddit Facebook Instagram
Compare
Beeper
Legal
Privacy Terms
© 2026 Spanbox. All rights reserved.