Trust & privacy
Connecting your inbox is an act of trust.
We built everything around that.
These are architectural decisions, not policy afterthoughts. Plain language, no fine print.
We never train AI models on your email or calendar content. This is a hard commitment, not a settings toggle.
Everything is encrypted in transit and at rest.
Consent is per account, granted by you. We request only the minimum access each feature needs, and we never ask for organization-wide access.
Disconnect means delete. Remove any account at any time and its data is purged.
No third-party middleman. Your content flows directly between your providers and Inbox Cardinal.
It suggests, it never acts silently. Everything the assistant does is visible and controllable.
Marcus is a VIP in your Consulting Co entity. The thread is awaiting your reply, and the revised terms are due today.
Product view: every score explains itself.
How sign-in actually works
Google & Microsoft
You sign in with the provider directly and approve each account individually. We never see or store your password, and we never request access to anyone else's mailbox in your organization.
Workplace accounts
Some workplace Microsoft accounts require an administrator's approval for third-party apps. If that applies, the product guides you through the request. Your personal accounts are unaffected.
IMAP mailboxes
Custom-domain and other IMAP mailboxes connect with an app password: stored encrypted, used read-only (we never alter your mailbox), and revocable by you at any time.
Honest answers to the hard questions
Do you read my email?
Do you sell or share my data?
Are you SOC 2 certified?
What happens to my data if I leave?
What about this website?
Questions we did not answer here?
Security reviews and detailed documentation are part of beta onboarding, and we welcome hard questions.
Ask us directly