This Privacy Policy explains how Where Beagles Dare Ltd (“we”, “us”, “our”) collects, uses, and protects personal data when you use Vidual Inbox (“the Service”), accessible at vidualinbox.com and inbox.vidual.app.
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Where Beagles Dare Ltd is the data controller for personal data processed through Vidual Inbox. We are based in Oxford, England.
We use personal data to:
We do not sell your personal data. We do not use your data for advertising purposes. We do not share your data with third parties for their own marketing.
We share data only with trusted third-party service providers who process data on our behalf:
All processors are subject to data processing agreements and required to handle data in accordance with UK GDPR. Where we process personal data on a customer’s behalf, that processing is governed by our Data Processing Agreement. The current list of sub-processors, with their location and transfer safeguards, is published on our sub-processors page.
By default, we retain your account data for as long as your account is active. Conversation history, attachments, customer context records, and internal notes are kept for the lifetime of your Inbox account so your team has a continuous record of every customer interaction.
This retention default does not override data-subject erasure rights or a controller’s deletion instruction. Where you are the controller of customer data held in your inbox, you may direct deletion of that data at any time, and we will honour it — subject only to any legal and accounting retention we are required to observe. You can delete a conversation or a customer record from Inbox yourself, which removes the associated data.
If you close your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or accounting purposes. Anonymised, aggregated data may be retained for analytics.
Under UK GDPR you have the right to:
To exercise any of these rights, please contact us at hello@vidualapp.com. We will respond within 30 days.
You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
We take data security seriously. All data is transmitted over HTTPS. We use passwordless authentication via passkeys and magic links — passwords are never stored. Database access is restricted and encrypted at rest. OAuth tokens for connected integrations are encrypted at rest using AES-256-GCM. We conduct regular security reviews of our infrastructure.
However, no method of transmission over the internet is 100% secure. If you believe your account has been compromised, please contact us immediately.
In the event of a personal data breach, we notify affected customers (acting as controllers) without undue delay after becoming aware of it, and we report the breach to the Information Commissioner’s Office (ICO) within 72 hours where we are legally required to do so. We cooperate with affected customers in their own regulator and data-subject notifications.
Our service is hosted on infrastructure primarily located within the UK and European Economic Area. Where data is processed outside the UK/EEA (for example by Anthropic in the USA), we ensure an appropriate safeguard is in place under UK GDPR — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or reliance on the EU–US Data Privacy Framework (UK extension) or a UK adequacy decision where applicable. The safeguard for each sub-processor is identified on our sub-processors page.
The Vidual Inbox app itself uses essential cookies and local storage only — for authentication tokens and user preferences — and sets no tracking, analytics or advertising cookies. Our marketing pages additionally use Google Ads conversion tracking, which sets cookies from Google to record that an enquiry followed one of our ads; it records the event, not who you are, and no name, message or contact detail is sent to Google. Our marketing pages also load fonts from Google Fonts (fonts.googleapis.com / fonts.gstatic.com); Google receives the visitor’s IP address to deliver those fonts, and no cookies are set in doing so. Cloudflare Turnstile, which protects our signup form, may set a strictly necessary cookie — see section 14 below. See our Cookie Policy for the full list.
Vidual Inbox is a business tool and is not directed at children under 16. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.
When a brand connects their Instagram Professional account to Vidual Inbox, we process Instagram Direct Message data on behalf of that brand to provide customer communication services.
This data is processed solely to display conversations in Vidual Inbox and enable the brand to reply. It is never used for advertising, profiling, analytics beyond basic conversation metrics, AI training, or any purpose beyond the inbox service.
Message data is retained until the brand deletes the conversation, disconnects the Instagram integration, or deletes their Vidual Inbox account. Upon any of these events, all associated Instagram message data is deleted without undue delay.
Vidual Inbox only enables replying to existing conversations initiated by the customer. We never initiate outbound messaging to Instagram users who have not messaged the brand first.
When a brand receives an erasure request from a customer, they can delete the customer record from Inbox, which removes all conversation data including Instagram messages. Instagram users can also block the brand on Instagram at any time, which prevents further communication.
When a brand connects their Gmail account to Vidual Inbox, Vidual receives an OAuth access and refresh token from Google. Depending on the boxes the brand ticks on Google’s consent screen, the connection does one or both of two things: sends the brand’s replies from their own Gmail address, and reads the brand’s Gmail mailbox so that customer emails arrive in Vidual Inbox without a forwarding rule. This section explains exactly what we access and how we use it.
Vidual Inbox requests up to two Google API scopes:
https://www.googleapis.com/auth/gmail.send — permission to send mail through the connected Gmail account on the brand’s behalfhttps://www.googleapis.com/auth/gmail.readonly — permission to read the connected Gmail mailbox. Requested only where the brand chooses to have Vidual Inbox read their mailbox instead of forwarding; a brand can decline it and keep a send-only connectionWe additionally request the standard openid and email scopes solely to identify which Gmail address has been connected, so we can display it in Settings.
With the read permission, we read:
We do not read, modify or store:
The read permission is read-only: Vidual Inbox never changes, moves, labels or deletes anything in the Gmail mailbox.
Sending. When the brand types a reply in Vidual Inbox and clicks send, Vidual passes that reply to the Gmail API, which delivers it to the customer from the brand’s connected Gmail address. The reply appears in the brand’s Gmail Sent folder, exactly as if they had sent it from Gmail directly.
Reading. A new email in the connected Inbox becomes a conversation in Vidual Inbox, exactly as a forwarded email would: it is shown to the brand’s team, matched to the customer’s existing conversations, and handled by the same features that apply to every email in Vidual Inbox (assignment, notes, notifications, the sorting of newsletters and sales pitches out of the main list, an auto-response outside opening hours if the brand has set one, and the summaries and reply drafts described in section 5). A reply the brand writes in Gmail to an existing customer is added to that customer’s conversation so the team sees the whole thread. Email we read is stored in Vidual Inbox as part of the brand’s conversation history, in the same way as forwarded email, and is the brand’s data under this policy.
The connected Gmail address itself (e.g. support@yourbrand.com) is shown in Settings so the brand can confirm which account is connected.
Vidual Inbox’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
OAuth access and refresh tokens are encrypted at rest using AES-256-GCM with keys held in our hosting environment’s secure secret store. Tokens are never logged, never transmitted to third parties, and never exposed in our application’s frontend or API responses. All calls to Gmail go over HTTPS to Google’s official Gmail API endpoints.
Outbound replies and any attachments the brand attaches are processed transiently to build the message that is delivered to Gmail. Email we read from the mailbox is stored as conversations in our database (hosted in the EU) and its attachments in Backblaze B2, under the same retention and deletion terms as every other conversation in Vidual Inbox. We do not keep a separate copy of the mailbox; the mailbox itself remains the brand’s and Google’s.
OAuth tokens are retained for as long as the Gmail integration is connected. When a brand disconnects Gmail in Vidual Inbox Settings, we immediately revoke the refresh token at Google, delete all stored tokens from our database, and stop reading the mailbox. When a brand deletes their Vidual Inbox account, all OAuth tokens and all conversations, including those read from Gmail, are deleted as part of the account deletion process.
Disconnecting Gmail does not remove conversations already in Vidual Inbox, and does not affect the brand’s mailbox: everything remains in Gmail exactly as it was.
Brands can revoke Vidual Inbox’s access to their Gmail account at any time, either by clicking Disconnect in Vidual Inbox Settings, or directly at myaccount.google.com/permissions.
Our signup form is protected by Cloudflare Turnstile, which distinguishes real people from automated scripts. We added it so that automated signups can be turned away without asking genuine customers to solve puzzles or identify traffic lights.
When you load the signup form, Cloudflare receives:
Cloudflare analyses these signals and returns a simple pass or fail to us; we receive that verdict, not Cloudflare’s underlying analysis. Your IP address is also visible to us in the ordinary course of serving the page, and we pass it to Cloudflare with the check. Cloudflare acts as our data processor for this and states that it cannot identify individuals from the signals Turnstile collects, and does not use them for advertising or to track visitors between websites.
Our legal basis is legitimate interests (Article 6(1)(f) UK GDPR): keeping our service secure and free of fraudulent and automated accounts. Turnstile runs only on the signup form — not on the rest of the app, and not on our marketing pages. It is not used in our iOS app.
Turnstile may set a strictly necessary cookie in your browser to record that the check has been passed. It is not an advertising or analytics cookie. Cloudflare’s Turnstile Privacy Policy explains its processing in full.
We may update this Privacy Policy from time to time. We will notify account holders of material changes by email or in-app notification. The current version is always available at vidualinbox.com/privacy.html.
Questions about this policy?
Contact us at hello@vidualapp.com or write to Where Beagles Dare Ltd, Unit 6 Heritage Business Centre, Belper, Derbyshire DE56 1SW.