
What Happens to Your Invoice Data After It's Processed?
Connecting an email account to any third-party tool means trusting it with some level of access. Here's exactly what InboxDoc does with your invoice data, step by step, no vague language.
What gets accessed
InboxDoc connects to Gmail or Outlook using a read-only OAuth scope. It can read mail. It cannot send, delete, or modify anything in your inbox, by design, not just by policy.
What gets extracted
From each invoice email, InboxDoc pulls out a specific set of fields: vendor name, invoice number, total amount, due date, and tax amount. These are the same five fields covered in our checklist of invoice fields worth automating.
What gets stored, and what doesn't
The extracted fields are stored, encrypted, in InboxDoc's database so they can be exported or reviewed later. The original PDF attachment and the email content itself are not retained after processing. Once the data is pulled out, the source document is gone.
Who can access it
Each account's data is isolated at the database level. Every query the app makes is scoped to the signed-in user, and row-level security policies on the database enforce that same isolation independently of the application code. Your extracted invoice data is tied to your account only, nothing is shared across accounts.
If you want it gone
Account deletion is self-serve: from Account settings, the "Delete account" option permanently deletes your extracted invoice data, disconnects your email accounts and revokes their access, deletes your notifications and account settings, cancels any active subscription, and deletes your login and profile information. No support ticket needed.
This is the whole process. No hidden steps. Try it yourself with a free trial, no credit card required.