← Help

Why we don't offer Single Sign-On with Apple, Google, Meta, etc.

inboxy doesn't offer one-click sign-in with Google, Apple, Microsoft, or other big-tech platforms. This page explains why.

The short version

Those platforms place tracking cookies on inboxy.net. Using their login would mean you trade a small convenience (one-click signup) for a large privacy downside (giving Google, Apple, or Meta visibility into your inboxy activity).

inboxy exists to keep your email out of the hands of data brokers. We're not going to hand the inboxy domain itself over to them.

How SSO tracking works

When you sign in via "Sign in with Google," you're not just proving you own a Google account. Google's servers talk to inboxy's servers. Google places a cookie on the inboxy.net domain that tracks your activity across the web. Even if you never come back to inboxy, Google knows you were here.

Over time, Google and others have access to:

  • How often you visit
  • Whether you signed up or just looked around
  • When you're active
  • What features you use
  • (Indirectly) what you're emailing about — the classification labels on messages leak category via referrer and timing

This isn't a conspiracy — it's how the tracking cookie network is designed. Google's Terms of Service explicitly allow them to place tracking pixels on partner sites. The cookie isn't optional; it's the trade-off for the sign-in convenience.

Why we can't accept this

inboxy's core value is privacy. We give you an inbox that big-tech companies can't see into. We don't sell your data, we don't target ads against your email habits, we don't share with data brokers.

If we let Google and Meta log in your users, we'd be letting them see which inboxy account visited when, for how long, and on what. That visibility is the exact opposite of the privacy we promise.

What we do instead

Passkey (WebAuthn) sign-in. It's device-bound, phish-resistant, and doesn't phone home to Apple or Google. You set it up once (30 seconds) and every sign-in after that is just a Face ID / Touch ID / Windows Hello biometric, or a hardware key tap.

If you lose your device, there's an TOTP (authenticator app) fallback so you're not locked out. And if you lose both, recovery codes get you back in.

It's a small one-time setup cost for something much more private than any SSO. See Why we ask for three sign-in factors for the reasoning.

What about email signup?

You don't need a Google account, Apple ID, or Microsoft account to sign up for inboxy. We ask for an email address — any email — and send you a verification link. It's a one-time thing; the email doesn't need to be from a specific provider.

This means you can:

  • Use a privacy-focused email provider (Proton, StartMail, etc.)
  • Use your own domain if you have one
  • Use a temporary address if you want (then change it later in Account settings)

The point is: you control where inboxy sends things. We don't.

Stuck?

If you have a different perspective or use case, we'd like to hear it — support@inboxy.net.


Still need help? support@inboxy.net

Add Inboxy to your Home Screen

  1. Tap the Share button in Safari’s toolbar.
  2. Scroll and tap Add to Home Screen.
  3. Tap Add in the top-right corner.