Privacy policy | RooMail
RooMail RooMail

Privacy policy

Last updated 12 September 2026

Who we are

IN4M AI PTY LTD (“we”, “our”, “us”) is an Australian company. RooMail is our AI inbox manager: it connects to mailboxes you authorise, reads the mail in them, sorts it into your categories, drafts or sends replies from your own material, archives what isn't important and escalates the rest to a person. This policy explains how we collect, use and protect personal information.

Two different things: the website and the product

Data is handled differently depending on which one you are using, so we separate them throughout this policy.

The website
A public marketing site at roomail.au. It is served through Cloudflare and measured with Google Analytics, both of which process data overseas. The only thing you can submit is your email address and the plan you are interested in.
The product (your RooMail account)
Where your connected mailboxes, knowledge base, drafts and audit log live, and how long each is kept.

Information we collect

On the website: what you give us directly

The only personal information we collect through the website is your email address, and the plan you say you are interested in, when you book a pilot or register interest. We use it to reply to you, gauge how much interest there is, and get your first mailbox connected. We do not add you to a marketing list without telling you, and you can ask us to delete it at any time.

On the website: collected automatically

Like most websites, our hosting and analytics providers process standard technical data such as IP address, browser and device type, pages visited and referring URLs. We use it to keep the site secure and to understand how it is used. It is processed by those providers under their own privacy policies and is not linked to your registration of interest.

In the product: what your account holds

Once you have an account we hold what the product needs to work. The categories below describe the kinds of information involved rather than every field, because what is collected depends on your rules and which mailboxes and systems you connect.

Account information. Names, email addresses, business name, roles and login records.
Mailbox content. The messages in the mailboxes you connect, including sender and recipient addresses, subjects, bodies, attachments and thread history.
Knowledge base material. The website pages, PDFs, Word and text documents, price lists and past replies you give RooMail to answer from.
Derived data. Categories, summaries, drafts, confidence signals, and the audit log of what was done with each message and who approved it.
Usage data. Volumes processed, categories used, response times, who approved what, and counts used for billing.
Connected systems. The mailbox credentials or tokens you authorise, and the records we read or write when actions are pushed out through MCP or the API.

A mailbox almost always contains personal information about other people, most of whom have never dealt with us. There, you decide what is processed and why, and we handle it on your instructions.

How we use your information

Reply to you about your interest in RooMail and get your first mailbox connected
Run the service you asked for: reading, categorising, drafting, sending and archiving
Index your website and documents so replies come from your own material
Escalate the emails your rules reserve for a person, and route them where you say
Keep the audit log, so you can check what was sent and who approved it
Bill you where you are on a paid plan, and support you when you raise a request
Keep the service secure, and understand how the website is used so we can improve it

We do not sell, rent or trade personal information, and being on a free pilot does not change that.

Where your data is stored and processed

Mail content, knowledge base material, drafts, categories, audit logs and account records are kept for as long as your account is active, subject to the retention settings below.

The website is different. It is delivered through Cloudflare’s global network and measured with Google Analytics, both of which process data overseas. Billing is handled by Stripe, which operates partly overseas and receives your billing details only, never mail content.

Cookies and analytics

The website uses Google Analytics 4 (measurement ID G-20JQDPGR6P) to collect anonymous usage data through cookies, so we can see which pages people visit and how they arrived. You can control cookies through your browser settings, or opt out with Google’s Analytics Opt-out Browser Add-on, and the site will keep working. The product itself does not run advertising or third-party tracking.

Third-party services

The services below may process data on our behalf:

Cloudflare
Website hosting, CDN, security and performance. Processes standard web traffic data including IP addresses and server access logs. Website only.
Google Analytics
Anonymous website usage analytics, measurement ID G-20JQDPGR6P. Website only.
Mail providers
Microsoft Outlook and Microsoft 365, Google Workspace, IMAP hosts and any custom connection you arrange. RooMail reads and sends only what you authorise, and those providers hold the mailbox itself under their own policies.
Stripe
Subscription billing and card processing on paid plans. Receives your billing details only, never mail content, and operates in Australia and the United States.
Systems you connect yourself
Service desks, CRMs, trackers and anything linked through MCP or the API. Where these sit, and what they do with data you send them, is governed by your agreement with that provider.

Cross-border data transfers

Some website and billing services are based outside Australia, primarily in the United States:

Cloudflare (website hosting, CDN, security): United States and global edge network
Google (Google Analytics and Google Fonts): United States
Stripe (billing only): Australia and United States

If your mailbox is hosted overseas by your own provider, that mail already sits with them before RooMail sees it. If you connect a system of your own that is hosted overseas, records RooMail sends there will leave on your instruction. While these countries may not have the same privacy protections as Australia, each provider is bound by their own privacy policy and, where applicable, contractual obligations. By using the website and the service, you consent to these transfers in accordance with Australian Privacy Principle 8.

Data security

Data is encrypted in transit and at rest. Access by our own staff is restricted, logged, and only ever for a support request you have raised. Our staff do not browse customer mail. Enterprise plans support single sign-on, enforced MFA, roles across mailboxes, and an exportable audit log of every action taken. Mailbox credentials and tokens are stored encrypted and used only for the actions you have authorised, and you can revoke them from your provider at any time without asking us.

Data retention

Processed mail, drafts and knowledge base material are kept for as long as your account is active, or for the retention period you set, which Enterprise can set per category. Delete an item and it goes from the live service straight away. Disconnect a mailbox and we stop processing it immediately. Close your account and everything is removed within thirty days. Registration of interest emails are kept until you ask us to delete them. Business and billing records are retained as required by Australian tax law.

Mailbox access, sending and consent

RooMail only ever reads a mailbox you have authorised, and it is your call whether a shared or staff mailbox is connected. If you are processing staff mail, your own workplace and privacy obligations apply, including telling your team about it.

Replies sent by RooMail are sent by you, from your address, and you are responsible for them. Autosend is off until you turn it on for a category. If someone who emailed you asks what happened to their message, or asks you to delete it, the audit log shows what was done and you can remove it yourself, or ask us.

Your rights

Under the Australian Privacy Act 1988, you have the right to:

Access the personal information we hold about you
Request correction of anything inaccurate
Request deletion of processed mail, a mailbox, your account, or your registration of interest
Ask for a full export of your data, including the audit log
Opt out of any marketing communications

To exercise any of these rights, contact us at support@in4m.au. If you are not satisfied with how we handle a privacy issue, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Data breaches

If a breach happens that is likely to cause serious harm, we will notify affected customers and the Commissioner as required by the Notifiable Data Breaches scheme, and we will tell you what we know as we know it.

Changes to this policy

We may update this privacy policy from time to time. Changes are posted on this page with an updated “Last updated” date, and if a change materially affects you we will tell you by email before it takes effect.

Contact us

Questions about this policy or how we handle data: support@in4m.au.

See also our terms of use.