Last updated: Dec 10, 2025
This Privacy Policy explains how bind.co ("bind," "we," "our," "us") collects, uses, processes, and retains information in connection with the bind.co platform.
bind.co provides infrastructure for user-authorized inbox data. This Policy explains our role, our data practices, and how responsibility is allocated among End Users, Developers, and bind.
bind.co operates as a neutral system of record for authorization and access to inbox-derived information.
This Privacy Policy applies to:
bind.co acts as:
When an End User authorizes access, bind.co may process:
Inbox data is processed as necessary to produce authorized Outputs. Applications do not receive direct access to the full inbox.
bind.co generates Outputs, which may include:
Outputs are generated artifacts of the bind.co service and are distinct from raw inbox content.
bind.co records:
These records are required to operate the service and preserve accountability.
bind.co also processes:
This data is used for security, reliability, and abuse prevention.
bind.co uses information to:
bind.co does not:
Where required by applicable law, bind.co processes personal information based on one or more of the following legal bases, as appropriate:
To produce authorized Outputs, bind.co may process inbox contents in full, including historical messages and attachments.
This processing enables:
Processing inbox data does not mean sharing it. Applications receive only Outputs within approved Scopes.
bind.co provides Outputs to Applications only within the Scope authorized by the End User. Applications control how Outputs are used once delivered and are solely responsible for their downstream processing activities and privacy practices.
bind.co uses trusted third-party service providers to operate the platform (e.g., cloud infrastructure, monitoring).
These providers process data only under bind's instructions and subject to confidentiality and security obligations.
bind.co may disclose information:
bind.co may use aggregated or anonymized data, which cannot reasonably be linked back to an End User, to:
This data does not identify individuals.
Outputs are retained:
When deletion is requested:
Authorization records, access logs, and audit data may be retained even after revocation or deletion requests where required to:
End Users may:
Depending on jurisdiction, End Users may have additional rights such as access, correction, erasure, restriction, portability, objection, or the right to withdraw consent. These rights may be exercised by contacting bind. bind.co will respond to verifiable requests within the timeframes required by applicable law.
Requests are handled subject to applicable law, reasonable timelines, and technical constraints.
Applications that receive Outputs are responsible for:
Developers act as independent controllers of any personal data they collect or process through their Applications. bind.co does not control how Applications use Outputs once delivered.
bind.co may use cookies or similar technologies for authentication, security, and service operation. bind.co does not use cookies for advertising or cross-site tracking.
bind.co maintains safeguards designed to be reasonable and appropriate to the nature of the service, including administrative, technical, and organizational measures consistent with industry-standard practices.
No system is completely secure, and bind.co does not guarantee absolute security.
bind.co operates globally and may process data in multiple jurisdictions. Where required, bind.co relies on appropriate cross-border transfer mechanisms. Additional details may be provided in a Data Processing Addendum or upon request.
bind.co is not intended for use by children under the age of 13 and does not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Material changes will be communicated where required by law.
For privacy inquiries or requests:
Email: privacy@bind.co