Privacy Policy
Effective date: 25 August 2026
This Privacy Policy explains how Ironwood Software Inc. ("Ironwood," "we," "us," or "our"), a corporation based in Kitchener, Ontario, Canada, collects, uses, discloses, and safeguards personal information in connection with the Lockbox service, including the Lockbox website, web application, and any related services (collectively, the "Service").
Lockbox is an email-security service. To do its job it must read your email. This page explains exactly what that means, what we keep, who else processes it, and how to make us stop. By creating an account, accessing, or using the Service, you acknowledge that you have read and understood this Privacy Policy.
The short version. We scan your incoming mail to decide whether it is dangerous. We keep the verdict and a short excerpt so we can show you why. We do not sell your information, we do not advertise to you, and neither we nor our AI providers use the contents of your email to train models. You can disconnect a mailbox at any time, which revokes our access immediately.
1. Information We Collect
1.1 Information you provide directly
- Account information: name, email address, authentication credentials, and your account preferences.
- Mailbox credentials: OAuth tokens issued by Google or Microsoft, or an app-specific password if you connect a mailbox over IMAP. These are encrypted at rest.
- Communications: messages you send to our support team, feedback, and any other correspondence with us.
1.2 Information collected from your mailbox
- Message content: headers, sender and recipient addresses, subject lines, body text, links, and attachments of the messages we scan.
- Scan results: the verdict, a risk score, the reasons behind it, and a short excerpt of the message.
- Mailbox state: a synchronisation watermark and connection events, so we know which messages we have already examined.
1.3 Information collected automatically
- Device and usage data: IP address, browser type, operating system, pages viewed, and timestamps.
- Cookies and local storage: used to keep you signed in and remember your preferences.
- Security and audit logs: sign-in attempts, IP addresses, and other security-relevant events used to detect and prevent abuse.
2. How We Use Your Information
We use the information we collect to:
- provide, maintain, and improve the Service;
- authenticate you and secure your account;
- analyse incoming messages and assign a verdict;
- move dangerous messages out of your inbox and notify you;
- show you the reasons behind each verdict;
- communicate with you about updates, security alerts, and support;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- comply with our legal and regulatory obligations; and
- produce aggregate, anonymised analytics about how the Service is used.
3. Legal Basis for Processing (EU/UK Users)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract — to provide the Service you signed up for;
- Legitimate interests — to keep the Service secure, prevent abuse, and improve our product;
- Consent — where we ask for it; and
- Legal obligation — where required by applicable law.
4. Google User Data REQUIRED DISCLOSURE
If you connect a Gmail or Google Workspace mailbox, Lockbox requests the
gmail.modify scope. We use it to read incoming messages and
to move dangerous ones out of your inbox. We do not send email
as you, and we do not permanently delete your mail.
Lockbox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we do not:
- transfer Google user data to third parties except as necessary to provide the Service, for security purposes, or to comply with applicable law;
- use Google user data for advertising, or serve advertising at all;
- sell Google user data;
- use Google user data to develop, improve, or train generalised AI or machine-learning models; or
- allow humans to read Google user data, except with your explicit consent for a specific message, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.
You can revoke our access at any time from your Google account permissions page, or by disconnecting the mailbox inside Lockbox.
5. Microsoft and IMAP Mailboxes
If you connect an Outlook or Microsoft 365 mailbox, the same principles apply: we request only the permissions needed to read incoming mail and move dangerous messages, and you can revoke access at any time from your Microsoft account or by disconnecting the mailbox.
If you connect a mailbox over IMAP using an app-specific password, that password is encrypted at rest and used only to fetch mail. We recommend OAuth where your provider supports it, because it can be revoked independently and grants narrower access.
6. How We Share Your Information
We do not sell your personal information. We share it only as described below.
6.1 AI processing providers
Reaching a verdict on a borderline message may require analysis by an AI model. Where that model is operated by a third party, the content of that message is transmitted to the provider over an encrypted connection. This is the most consequential disclosure on this page, so we are stating it plainly rather than burying it.
| Provider | Role | Trains on your content? |
|---|---|---|
| Self-hosted model (our own hardware, Canada) |
First-pass analysis of every message | No — content never leaves our infrastructure |
| Anthropic, PBC | Escalated review of borderline messages | No — commercial API terms prohibit it |
| Google LLC (Gemini API) | Escalated review of borderline messages | No — paid API terms prohibit it |
These providers act as our service providers, process content solely on our behalf and on our instructions, and return a result to us. Most messages are resolved by the self-hosted model without any third-party transmission at all.
We do not use the contents of your email to train our own models.
6.2 Threat-intelligence lookups
To assess links and attachments we query third-party reputation services, including Google Safe Browsing, urlscan.io, DNS resolvers operated by Google and Cloudflare, and public domain-registration (RDAP) records. These lookups transmit domains and URLs found in messages — not the message body, and not your identity.
6.3 Infrastructure and business providers
| Provider | Purpose |
|---|---|
| Ironwood-operated infrastructure (Canada) | Application hosting, database, and scan storage |
| Resend | Delivery of notification and account email |
| Stripe / Helcim | Subscription billing and payment processing |
These vendors are contractually required to process information only on our instructions. We never see or store your full payment card details; those go directly to the payment processor.
6.4 Legal compliance and business transfers
We may disclose information where we believe in good faith that disclosure is required to comply with a legal obligation, court order, or lawful request from a government authority, or to protect the rights, property, or safety of Ironwood, our users, or others. If Ironwood is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, and we will notify you of any such change in ownership or control.
7. International Data Transfers
Ironwood Software Inc. is based in Canada, and your account data and scan results are stored in Canada. Certain providers listed in Section 6 may process data in the United States or elsewhere, which means it can be subject to the laws of those countries, including lawful access requests by foreign authorities. We use providers that offer appropriate contractual safeguards.
8. Data Retention
Full message bodies are processed in memory to reach a verdict and are not stored. What we retain depends on the verdict:
- Clean mail: the verdict only, with the sender and subject. The body is never written to disk.
- Suspicious mail: the same — verdict, sender, subject, and the reasons it was flagged. No body is stored.
- Malicious (quarantined) mail: a short encrypted excerpt of the body is kept so you can see what tripped the scanner and release the message if we got it wrong.
- When you file a report: if you click "investigate" or "report false positive", that request authorises us to retrieve a full copy of that one message from your mailbox for analysis. It is stored encrypted, visible only to our security team, used only for your report, and deleted within 30 days of the investigation closing.
- Clean results are kept for the period you choose in Settings, then deleted automatically.
- Flagged and held messages are kept longer so you can review and release them.
- Sender addresses are encrypted at rest and searched through a blind index rather than stored in readable form.
- You can clear your scan history at any time from Settings, which deletes those records immediately.
- When you delete your account we delete or anonymise your personal information within a reasonable timeframe, except where retention is required by law.
9. Security
- All traffic is encrypted in transit with TLS.
- Mailbox credentials and sender addresses are encrypted at rest.
- Passwords are hashed; we never store them in readable form.
- Two-factor authentication is available on every account.
- Access to production systems is limited and logged.
No method of transmission over the internet or electronic storage is fully secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and notifying us immediately of any unauthorised use of your account. If a breach affects your personal information and creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as required by PIPEDA.
10. Your Privacy Rights
Depending on where you live, you may have the following rights with respect to your personal information:
- Access — request a copy of what we hold about you;
- Correction — ask us to correct inaccurate or incomplete information;
- Deletion — ask us to delete it, subject to legal exceptions;
- Portability — request a copy in a structured, machine-readable format;
- Objection or restriction — object to, or ask us to restrict, certain processing;
- Explanation — ask how we reached an automated decision about a particular message; and
- Withdraw consent — at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, email [email protected]. We may need to verify your identity first. If you are in Canada and are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.
11. California Residents (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and not to be discriminated against for exercising your rights. We do not sell or "share" personal information for cross-context behavioural advertising as those terms are defined under California law.
12. Children's Privacy
Lockbox is a business tool and is not directed to children. We do not knowingly collect personal information from children. If you believe we have inadvertently done so, contact [email protected] and we will delete it.
13. Cookies and Tracking
The marketing site at www.getlockbox.ca sets no tracking cookies. The application at app.getlockbox.ca uses strictly necessary cookies and local storage to keep you signed in and remember preferences. You can configure your browser to refuse cookies, but some features may not work if you do. We do not use third-party advertising cookies.
14. Third-Party Links and Integrations
The Service integrates with third-party providers such as Google and Microsoft. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review their policies.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top of this page and, where the changes are material, provide additional notice by email or in-product notification. Your continued use of the Service after an update means you accept the revised policy.
16. Contact Us
Ironwood Software Inc.
Kitchener, Ontario, Canada
Email: [email protected]