Privacy Policy

Effective 22 August 2026

This policy explains how Aleksander Szczerbiński (“we”, “us”) processes personal data in connection with Inbox Analytics Sandbox, including data relating to customers who connect an Instagram Professional account and, where applicable, people who communicate with those customers through Instagram Direct Messages.

1. Who we are

Operator: Aleksander Szczerbiński
Registered address: Częstochowska 25/27/42, 02-350 Warszawa, Poland
Privacy contact: alek.szczerbinski@gmail.com

2. Our roles

For our own customer accounts, prospective customers, website administration, security, legal compliance, and service operations, we generally determine the purposes and means of processing and act as a data controller.

When a customer authorizes Inbox Analytics Sandbox to receive or analyze Instagram messaging data for that customer's own business purposes, we generally process that messaging data on the customer's documented instructions. In that context, the customer generally acts as controller and we act as processor/service provider. The customer's own privacy notice and lawful basis govern its processing of people who message it.

We do not treat a customer's authorization as permission to independently sell private message data, build unrelated cross-customer profiles of message participants, or reuse private messages for unrelated purposes.

3. Data we may process

CategoryExamples
Customer dataName, email, organization, account settings, subscription, support and administrative information.
Instagram account dataProfessional-account identifiers, Instagram-scoped identifiers, usernames, permissions, access status and token metadata.
Messaging dataConversation IDs, message IDs, message text/content made available through authorized Instagram APIs, timestamps, sender/recipient scoped IDs, reactions, edits, deletion events and messaging metadata.
Derived analyticsTopics, classifications, summaries, counts, trends, response metrics, search indexes and other customer-requested analytics.
Technical/security dataIP addresses, user agents, authentication events, request/webhook logs, errors and security signals.

4. Sources

5. Purposes

6. Legal bases when we act as controller

Where the GDPR applies, depending on the activity we may rely on performance of a contract, our legitimate interests in operating and securing the service where not overridden by individual rights, compliance with legal obligations, or consent where specifically requested and appropriate. Where we act solely as a processor, the customer/controller determines the applicable lawful basis.

7. AI and automated analytics

Inbox Analytics Sandbox may use automated text-processing or artificial-intelligence systems to generate classifications, summaries, semantic search results, topic groupings, or similar analytics requested by a customer.

Unless expressly disclosed and lawfully implemented, we do not use private Instagram message content to make decisions producing legal or similarly significant effects about message participants, and we do not intentionally infer highly sensitive traits such as race, religion, sexual orientation, political affiliation, or medical diagnosis for unrelated profiling.

Where external AI or infrastructure providers process customer data on our behalf, they are treated as service providers/subprocessors. See Subprocessors.

8. Sharing

We may disclose personal data to service providers supporting hosting, storage, security, authentication, observability, or AI processing; professional advisers; public authorities where legally required; and a successor entity in a lawful corporate transaction.

We do not sell or license private Instagram message content or Meta Platform Data.

9. International transfers

Where personal data is transferred outside the EEA, we use an applicable lawful transfer mechanism, such as an adequacy decision, EU Standard Contractual Clauses, or another mechanism permitted by data-protection law.

10. Retention

11. Deletion

We design the service to support deletion when a customer disconnects an account, requests deletion, or when source content is deleted and an applicable event is received. Instructions: Data Deletion.

12. Security

We use safeguards appropriate to private communications, including encryption in transit, access controls, credential protection, restricted administrative access, logging controls and customer-data separation. No system can guarantee absolute security.

13. Your rights

Depending on applicable law and our role, you may have rights to access, correct, erase, restrict, port or object to processing, and to withdraw consent where consent is the basis.

If your request concerns messages sent to a particular creator/business using Inbox Analytics Sandbox, that customer may be the controller responsible for your request. We will assist the customer where required.

Contact: alek.szczerbinski@gmail.com.

14. Complaints

If you are in the EEA, you may complain to a competent supervisory authority. Where applicable, our primary authority is President of the Personal Data Protection Office (UODO), Poland: https://uodo.gov.pl/.

15. Children

Inbox Analytics Sandbox is a business-facing service and is not directed to children. Customers may nevertheless receive messages from people of different ages. Customers remain responsible for ensuring that their use complies with laws applicable to minors, and we process such data only under appropriate instructions and safeguards.

16. Changes

We may update this policy when our service, vendors or legal obligations change. The current version will be published here with a revised effective date.

17. Contact

Aleksander Szczerbiński
Częstochowska 25/27/42, 02-350 Warszawa, Poland
alek.szczerbinski@gmail.com