Legal
Privacy policy
This website is run by 1337-Software LLC. This policy explains what we collect, why, where it is stored, and how to get it deleted. It covers this website and the products we operate, currently Inbox. Our App Store apps have their own policies: Ringception and KeyPeek (both collect nothing).
The short version
- Browsing this website does not require an account, and we do not run analytics, advertising, or tracking cookies on it.
- Inbox accesses your Gmail only to show and triage your mail, on your instruction, using access you grant through Google and can revoke at any time.
- We do not sell your personal data, share it with advertisers, or use your email content to train machine-learning models.
- You can ask us to delete your account and data at any time and we will do it.
Who we are
This website, 1337-software.com, is owned and operated by 1337-Software LLC, a limited liability company founded and run by Nick Ratliff. 1337-Software LLC also publishes the Inbox application described in this policy. "We", "us", "our", and "1337 Software" throughout this policy mean 1337-Software LLC.
For the purposes of data protection law — including the GDPR and the CCPA — 1337-Software LLC is the controller of the personal data described in this policy, and is the party responsible for how that data is collected and used. Privacy contact: legal@1337-software.com.
Information we collect
This website
This site is a set of static pages. It has no accounts, no comment forms, and no advertising or analytics scripts, and it does not set cookies. Our hosting provider records standard server request logs — IP address, requested URL, timestamp, referrer, and browser user-agent — which are used to serve the site, defend against abuse, and diagnose faults. We do not use those logs to build profiles of visitors.
Inbox
Inbox is pre-release. When you use it, we process:
- Account identity. The name, email address, and Google account identifier returned when you sign in with Google, so we know whose data is whose.
- Authorisation tokens. The OAuth access and refresh tokens Google issues so the app can act on your mailbox on your behalf. These are stored encrypted, restricted at the database level so that only your account can reach them, and never written into our source code or logs.
- Mail data. Message headers, bodies, labels, and read state are
fetched from Gmail so the app can display and triage your mail. Inbox requests the
Gmail
gmail.modifypermission, which allows it to read messages and to trash, archive, label, and mark them read. Inbox cannot send mail as you. - Operational logs. Error and performance records that let us diagnose failures. We keep message content out of these logs.
How we use it
- To provide the product's core function: displaying your mail and carrying out the triage actions you take.
- To keep you signed in and to maintain your authorisation with Google.
- To diagnose and fix faults, and to protect the service against abuse.
- To answer you when you contact support.
We do not use your data for advertising or profiling. Where the law requires a legal basis, ours is your consent for access to your Google data, and our legitimate interest in operating and securing the service for logs and abuse prevention.
What we never do
- We do not sell or rent personal data, and we do not "share" it for cross-context behavioural advertising.
- We do not use your email content to train, retrain, or fine-tune machine-learning models.
- We do not transfer your Google user data to third parties except the service providers listed below, or where you direct us to, or where the law requires it.
- We do not read your mail for human review, except in the narrow case where you explicitly ask us to look at a specific message to resolve a support issue, or where required by law or to investigate a security incident.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Service providers
We keep this list short on purpose. These are the only third parties that process personal data on our behalf:
| Source of the mail data and the authentication provider, under your own Google account. | |
| YouTube (Google) | YouTube API Services for our own channel's uploads and statistics — see YouTube API Services. |
| Supabase | Authentication and database, including encrypted token storage. |
| Vercel | Website and application hosting; produces the server request logs described above. |
We may also disclose data if compelled by valid legal process, or where necessary to protect the rights and safety of our users or the public.
YouTube API Services
Our media scheduler (an internal, self-hosted instance of the open-source tool Postiz at encom.1337-software.com) uses YouTube API Services to upload videos to our own YouTube channel and read that channel's basic statistics. By using it you agree to be bound by the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
What we access and store
- Authorization tokens for the YouTube channel you connect (OAuth 2.0 access and refresh tokens), stored encrypted in the scheduler's database on hardware we control. Nothing else from your Google account is read.
- Channel identifiers (channel ID, title, avatar) so the scheduler can show which channel a post goes to.
- Video metadata we create (title, description, tags, thumbnail, privacy status, the video file until it has been uploaded) and the resulting video ID.
- Basic analytics for our own videos (views, watch time), fetched on demand and refreshed or discarded within 30 days as YouTube's policies require.
What we never do with YouTube data
We do not access, collect, or store data about any other YouTube user, viewer, or channel. We do not sell, share, or transfer YouTube data to third parties, use it for advertising, or combine it with other data sources. The scheduler is used only by 1337-Software LLC for its own channel; there are no external users.
Retention and deletion
Authorization tokens are kept only while the channel is connected. Disconnecting the channel in the scheduler deletes them immediately; revoking access from your Google account (below) makes them useless and they are purged on the next cleanup. Video files are deleted from the scheduler once YouTube has accepted the upload. Stored analytics are refreshed or deleted at least every 30 days. To have any remaining YouTube-related data deleted, email legal@1337-software.com with the subject "YouTube data deletion" — we complete it within 7 days.
Revoking access
You can revoke the scheduler's access to your YouTube data at any time from the Google security settings page (Third-party apps with account access).
Security
Traffic to the site and the app is encrypted in transit with TLS. Tokens and account data are encrypted at rest and protected by row-level access rules so that one account cannot read another's records. Secrets are held in managed secret stores and are never committed to source control. No system is perfect; if a breach affects your data we will tell you and the relevant regulator as required by law.
Retention
- Account records and authorisation tokens are kept while your account is active.
- Mail content is fetched from Gmail to serve your session and is not retained as a long-term archive by us; Gmail remains the system of record.
- Operational logs are kept for up to 90 days.
- After you delete your account, live data is removed within 30 days and backups containing it roll off within a further 30 days.
Your choices and rights
- Revoke access. Remove 1337 Software from your Google account permissions at any time. Access ends immediately.
- Delete your account and data. Email us with the subject "Account deletion request" — steps are on the support page.
- Access, correction, portability, objection, and restriction. If you are covered by the UK/EU GDPR or a similar law, you may exercise these rights by emailing us. We respond within 30 days and do not charge for it.
- California residents. You may request disclosure of the personal information we collect and ask us to delete it. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, so there is nothing to opt out of. We will not discriminate against you for exercising these rights.
- Complaints. If you are in the UK or EEA and we have not resolved your concern, you may complain to your local data protection authority.
International transfers
We operate from the United States and our service providers process data in the United States and other countries. Where data is transferred out of the UK or EEA, we rely on the transfer mechanisms our providers put in place, such as the European Commission's standard contractual clauses.
Children
Our products are not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, email us and we will delete it.
Changes to this policy
If we change this policy we will update the effective date at the top of this page. For changes that materially affect how we handle your data, we will notify account holders by email before the change takes effect.
Contact
Questions, requests, or complaints about privacy go to 1337-Software LLC at legal@1337-software.com. We answer within 2 business days.