Skip to content

Privacy & data handling

InboxCRM is local-first. This page explains what the extension handles, where it is stored, and the limited circumstances in which any of it leaves your device.

Last updated September 2026

Summary

  • Your CRM data — pipelines, notes, tags, templates, schedules, orders and reports — is stored in Chrome's local extension storage (chrome.storage.local) on your own computer.
  • No server operated by us receives your CRM records. If you turn on the optional cloud chat backup, chats are encrypted on your device before upload, with a key that stays in your browser.
  • Information leaves your device only when you choose a feature that requires it: the optional AI assistant, webhooks you configure, the optional cloud chat backup, an optional self-hosted bridge server you run, and — when account sign-in is enabled — the account and subscription service.
  • We do not sell your data, use it for advertising, or run analytics or telemetry inside the extension.

Data stored locally on your device

The following stays in local extension storage and is not transmitted by us:

  • Contact names and phone numbers attached to CRM records you create
  • Kanban boards, stages, deal values, tags, categories and custom tabs
  • Notes about contacts, and custom contact profile fields
  • Quick-reply templates and the media you attach to them
  • Scheduled messages, appointments, follow-up rules, chatbot flows and auto-reply rules
  • Order and delivery records, campaign recipient lists and send logs
  • Sending-safety settings and the counters that enforce your limits
  • Interface preferences and the backups you export or schedule

WhatsApp message content

To work, the extension reads content from the WhatsApp Web page you have open — the selected conversation, its participants and recent message text. This is used to show the panel, evaluate the automation rules you set up and, if you use the AI assistant, give the AI model context. The extension only keeps a copy of your chat history if you use Chat backup (see below).

When information leaves your device

AI assistant (optional)

When you ask for an AI draft or improvement, the extension sends a prompt to the provider you selected — OpenRouter, OpenAI, Google Gemini or Groq. The prompt contains recent message text from the open conversation, the contact or group name and anything you typed. Each provider processes it under its own terms. We do not receive a copy. If you never use an AI feature, no message content is sent to an AI provider. If you enable AI rewording in campaigns, each recipient's message text is likewise sent to your provider.

Chat backup (optional)

Chat backup can save a copy of your chats, contacts, messages and media in your browser. If you also turn on the cloud copy and sign in, those records are encrypted on your computer (AES-256-GCM) before they are uploaded to the Extino backup service. The encryption key is created and stored only in your browser and shown to you once as a recovery key; the service never receives it. Keep the recovery key safe — without it, the cloud copy can't be decrypted or restored.

Account and subscription

When account sign-in is enabled, the extension communicates with the Extino account service to sign you in, check your subscription status and open billing pages. This may involve your user ID, email address, display name, profile image, session token and subscription state. No CRM record and no readable message content is sent to this service; cloud chat backup uploads only data that was encrypted on your device. Payment details are collected by Stripe and never pass through the extension.

Webhooks you configure

The extension can send event notifications to URLs you enter. Depending on the events and fields you enable, a payload may include a contact's phone number, name and message text. You choose the destination and are responsible for its security. We never receive these payloads.

Self-hosted bridge server (optional)

If you run the optional bridge server and enable it, the extension connects to the address you enter. That server runs on infrastructure you control; we do not operate it or receive anything from it.

Your choices

  • Use InboxCRM without configuring AI, webhooks or the bridge server
  • Remove a saved API key, or turn off individual automations and the AI assistant
  • Export, import or delete your data from the Backup screen
  • Uninstall the extension, which removes its local storage — export a backup first if you want to keep your records

Security

No method of storage or transmission is completely secure. Keep AI provider keys private and prefer keys with a spending limit, send webhooks only to endpoints you trust, and store exported backup files somewhere safe — they contain your CRM data.

Contact

Questions about privacy or account data? Contact support.

InboxCRM is an independent product and is not affiliated with, authorized by, endorsed by, or sponsored by WhatsApp or Meta Platforms, Inc. WhatsApp is a trademark of Meta Platforms, Inc.