Meridian Inbox

Privacy Policy

Last updated: July 28, 2026

Meridian Inbox is a private, internal tool operated by Meridian BFD to read, organize, and reply to the company’s Gmail inbox. This policy explains what data the app accesses — including data from your Google account — and how we use, store, share, and protect it.

Who this applies to

Meridian Inbox is used by authorized Meridian BFD staff to manage company mailboxes. It is not offered for public sign-up. “You” means a person who connects a mailbox or uses the app.

Google user data we access

With your explicit consent through Google’s OAuth screen, the app requests these Gmail scopes and accesses only the data they cover:
  • gmail.readonly — read access to the connected mailbox’s messages and metadata (sender/recipients, subject, date, labels, body, and attachments), used to sync, display, search, thread, and categorize mail in the dashboard.
  • gmail.send — permission to send email from the connected mailbox, used only to send replies and messages that a staff member composes and sends from the app.

The app does not request permission to permanently delete mail, and does not modify your Google account settings.

How we use the data

Google user data is used solely to provide the inbox features described above — syncing, displaying, organizing, searching, and sending mail on your behalf within the app. We do not use it for advertising, and we do not sell it or share it with third parties for their own purposes.

How we store and protect it

Synced messages are stored in a private, access-controlled PostgreSQL database (Amazon RDS) running in our Amazon Web Services account. Data is encrypted in transit (TLS), and OAuth connection tokens are stored encrypted at rest (AES-256-GCM). Access to the app is restricted to authorized Meridian BFD staff.

Sub-processors we share with

We do not sell or rent your data. It is processed only by the infrastructure providers that run the service on our behalf: Google (Gmail API) and Amazon Web Services (application hosting and the managed PostgreSQL database). It may also be disclosed if required by law.

Limited Use disclosure

Meridian Inbox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data retention and deletion

Synced email is retained while its mailbox is connected. Disconnecting a mailbox stops further syncing, and its stored messages can be purged from the app. You may revoke the app’s access at any time from your Google Account’s third-party access settings. To request deletion of stored data, contact us at the address below.

Changes to this policy

We may update this policy; material changes will be reflected by the “Last updated” date above.

Contact

Questions or data requests: brad@meridianbfd.com.