Skip to content

Legal

Terms of Service

Last updated 20 September 2026

These terms govern your use of Humainbox, a service that receives your website contact form submissions by email, decides whether each one is a genuine enquiry or automated spam, and forwards the genuine ones to the people you nominate. By creating an account or using the service you agree to these terms.

1. Who you are contracting with

The service is operated under the name Humainbox. In this document “Humainbox”, “we” and “us” mean the operator of the service; “you” and “your” mean the account holder.

The operating legal entity is Reaktör Teknoloji Tic. Ltd. Şti., a limited liability company incorporated in the Republic of Türkiye, trading as Humainbox. Its registered address is Şahkulu Mah. Serdar-ı Ekrem Cad. No:15/A, Beyoğlu/İstanbul 34430, Türkiye. That is the company you are contracting with, the company that holds your data, and the company a claim would be made against.

Registered for tax at Beyoğlu tax office under number 7342091024.

Entered in the Türkiye trade registry under MERSİS number 0734209102400001, registry file number 298746-5.

2. What the service does

Humainbox gives you an email address. You set that address as the recipient of your website’s contact form. From then on, submissions from your form arrive at Humainbox rather than in your mailbox.

For each message we:

  • store the raw email message, compressed, on object storage;
  • parse it into fields — sender name, sender email address, subject, message body, arrival time, message size, character set and attachment count;
  • resolve a reply address, and record which source it came from: the Reply-To header, the message body, or the From header;
  • copy the authentication results written by the receiving mail server, and record which server wrote them;
  • run a sequence of filtering rules, recording one row per rule that ran;
  • forward messages that pass to the recipients you have configured — an individual or a team — and record the outcome of each delivery attempt.

Everything we receive is visible to you in the panel, whether it was forwarded or held back.

Attachments

Attachments are forwarded with the mail. We copy the file out of the stored original into the message we send, and we do not open it: nothing unpacks an archive, parses a document or reads an image, and no attachment is ever included in what we send for classification — that receives the message text only.

Our mail provider carries at most ten files totalling ten megabytes in a single message. Where a submission exceeds that, the message is still delivered and the files that did not travel with it are named in it; they remain in the stored original, downloadable from your account, until that message is purged.

Where the mail provider's own scanning flags a submission as carrying a virus, its files are neither stored nor forwarded. That check happens at the provider before the message reaches us. We do not scan attachments ourselves, and you should not treat Humainbox as the security layer in front of your mailbox.

3. Your account

You must be able to enter into a binding contract, and you must give accurate account details. You are responsible for everything done under your account, for keeping credentials secure, and for the people you invite into it. Tell us promptly if you believe an account has been compromised.

Accounts are strictly isolated from one another at the data layer. Queries carry an account scope and fail loudly rather than returning another account’s data. This is a design property of the system, not a policy we ask people to observe.

4. Your role and your responsibilities

The personal data flowing through Humainbox is submitted by third parties — visitors to your website — into a form that you publish. In data protection terms you are the controller of that data and we are a processor acting on your documented instructions. The Privacy Policy sets this out in full.

Practically, that means you are responsible for:

  • having a lawful basis for collecting submissions through your form;
  • telling your visitors, in your own privacy notice, that submissions are processed by a third-party filtering service on your behalf;
  • choosing which recipients receive forwarded mail, and keeping that list current;
  • choosing your filtering threshold and your retention period;
  • deciding whether external classification is enabled for your account (see section 11);
  • responding to requests from your visitors about their own data, with our assistance.

5. Acceptable use

You may not use Humainbox to:

  • receive mail at an address you are not entitled to publish;
  • process data you have no lawful basis to process;
  • collect payment card numbers, health records, or other special-category data through a contact form — the service is not designed or hardened for it;
  • send bulk or marketing mail of any kind; Humainbox forwards enquiries, it is not a sending platform;
  • relay mail on behalf of someone else, or resell raw forwarding capacity;
  • probe, load-test or attempt to circumvent the isolation between accounts;
  • break the law, or infringe anyone’s rights.

We may throttle an account that generates volume far outside its plan, and we will tell you when we do.

6. How filtering works

Each message runs through a sequence of rules. Cheap deterministic checks run first: header authentication results, structural signals, known patterns. Every rule that runs leaves a record holding the rule name, a numeric weight, a short human-readable reason and its timing.

Those weights combine into a score. You choose the threshold at which a message is held back rather than forwarded. Messages the deterministic rules cannot decide may be passed to a large language model for classification — see section 11 and the Privacy Policy.

The reason recorded against each rule is written to be read by a person. When you disagree with a decision, you can see which rules fired and why.

7. The limits of classification

This section matters more than most of the ones around it, so we will be blunt about it.

Classification is probabilistic and it will sometimes be wrong, in both directions. Some spam will be forwarded to you. Some genuine enquiries will be held back. No threshold removes both errors at once: tightening the threshold to catch more spam will hold back more real enquiries, and loosening it does the reverse.

Because you choose the threshold, you own that trade-off. We give you the decision record for every message so the choice is an informed one, and we do not promise an accuracy rate. If your business would be materially harmed by a single missed enquiry, you should review the held-back queue rather than rely on forwarding alone.

8. Fail-open delivery

The service is deliberately designed to fail open. If a rule errors, a classification call fails, or an internal component is unavailable, the message is delivered rather than lost. We would rather send you spam than lose an enquiry.

A consequence worth stating plainly: during an internal failure your mailbox may receive messages that would ordinarily have been held back.

9. Nothing is discarded silently

Humainbox does not delete messages as part of filtering. A message classified as spam is held back from forwarding, not thrown away. It stays retrievable in the panel for the whole of its retention period, with the reasons that produced the decision attached to it.

The only thing that removes message content is the retention schedule described in the next section, or a deletion you ask for.

10. Retention and purging

Message content is cleared when your retention window runs out — the same window for held and for delivered mail, and the same limit on every plan: 30 days unless you choose otherwise, and never more than 90. You can always shorten it. A message still waiting on a decision from you is left alone until you have made it.

After a purge, the per-rule decision records survive. They hold no message content and no extracted personal details — only rule names, numeric weights, short reasons and timings. Keeping them lets us keep improving the filtering without keeping the personal data. The Privacy Policy explains this in more detail.

Retention is a ceiling, not a promise of availability. Do not use Humainbox as your archive of record for enquiries you need to keep.

11. External classification

Messages that the deterministic rules cannot decide may be sent to a third-party large language model provider for classification. This means message content may leave our infrastructure and be processed by that provider. We think you should know that in the terms as well as in the privacy policy.

There is an account-level option to switch external classification off entirely. With it off, messages are decided by the deterministic rules only. Filtering is less accurate in that mode; that is the trade you are making, and it is yours to make.

12. Availability and support

We aim for continuous availability but we do not currently offer a contractual uptime commitment or service credits. If you need one, talk to us before you commit — we would rather agree something specific with you than have you assume a guarantee that is not here.

Support is provided by email. We may take the service down for maintenance and will give notice for anything planned that is likely to be noticed.

We hold no formal security certification. We have not completed SOC 2, ISO 27001 or any equivalent audit, and we make no HIPAA claims. A formal certification programme is not yet in place. The concrete security measures we do have are listed in the Privacy Policy.

13. Fees and billing

Nothing is charged today. The free tier is permanent, needs no card, and the paid plans are not yet billed — when that changes we will tell every account holder before the first charge, and these are the terms that will apply.

  • Prices are the ones published on our pricing page, per workspace, in euro (EUR).
  • Billing period is monthly, in advance. A plan starts when you choose it and renews each month until you stop it.
  • Tax. Prices are exclusive of VAT and any other applicable tax, which is added where the law requires it. Business customers in the EU with a valid VAT number are invoiced under the reverse charge.
  • Stopping. You can stop a plan at any time from Settings. It runs to the end of the period you have paid for and does not renew. Part months are not refunded, because the service was available for them.
  • Consumers. If you are buying as an individual rather than for a business, your statutory cancellation and refund rights apply in full and nothing above reduces them.
  • Price changes take effect no sooner than 30 days after we tell you, and never inside a period you have already paid for.
  • Late or failed payment. We will write to you before anything is suspended, and suspension stops forwarding — it does not delete what is stored.

Whatever those terms end up being, non-payment will not cause your stored messages to be deleted without notice. We will tell you before anything is removed.

14. Suspension and termination

You can close your account at any time. We may suspend or close an account for a material breach of these terms, for non-payment, or where continuing would expose us or other customers to legal risk. Except where the law or an urgent risk prevents it, we will tell you why and give you a chance to put it right.

15. Your data when you leave

You can export everything at any time from Settings → Data & privacy: every message still within its retention window, the decision behind each one, what was forwarded and to whom, and your inboxes, recipients and team — as spreadsheets plus the original emails with their attachments. You do not need to ask us and you do not need to be closing your account. After a grace period we delete account data, stored messages and configuration. The per-rule decision records — rule names, weights, reasons, timings, with no message content and no personal details — are retained, as described in section 10.

Closing a workspace is done from Settings → General, by the person who opened it. Mail stops arriving straight away and nothing more is forwarded. The grace period is 30 days, during which any owner can stop it and everyone can still read and export everything. After that the messages, the inboxes, the recipients and the workspace are deleted, and that cannot be undone.

16. Intellectual property

We own the service, its software, its rules and its interface. You own your content — the messages sent to your address and the configuration you create. You grant us only the permission we need to run the service for you: to receive, store, classify, forward and display that content, and to purge it on schedule.

We do not use your message content to train models for other customers. That commitment is repeated, with the one narrow exception that applies to it, in the Privacy Policy.

If you send us feedback or suggestions, we may use them freely and without obligation to you.

17. Warranties and disclaimers

The service is provided as it is. To the extent the law allows, we exclude implied warranties of merchantability, fitness for a particular purpose and non-infringement.

In particular, and consistent with section 7, we do not warrant that classification will be accurate, that every genuine enquiry will be forwarded, or that no spam will reach you. We do not warrant uninterrupted or error-free operation.

Nothing in these terms excludes liability that cannot lawfully be excluded, and nothing here limits statutory rights you may have as a consumer.

18. Limitation of liability

The intended position is that neither party is liable for indirect or consequential loss, and that our total liability is capped at the fees you paid in a defined preceding period.

  • Neither of us is liable to the other for indirect or consequential loss, for loss of profit, revenue, business, contracts, goodwill or anticipated savings, however it arises.
  • Our total liability to you, taken together across everything arising out of these terms, is limited to the greater of the fees you paid us in the twelve months before the claim, or €100.
  • Nothing here limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot be limited under the applicable law.
  • Our obligations as a processor of your message data, and liability arising from them, are governed by the Privacy Policy and by any data processing agreement we sign with you. Where one of those says something different from this section, it wins.

A cap on liability is not a cap on what we owe you in practice. If we lose or mishandle your mail we will tell you, explain what happened, and say what we are doing about it — section 18 covers that, and no limit above changes it.

19. Changes to the service and these terms

We will keep developing the service, and rules will change as spam changes. Where a change materially reduces what you get, or materially changes how your data is handled — including a change to the sub-processors we use — we will notify you in advance. Continuing to use the service after a change takes effect means you accept the revised terms.

20. Governing law and disputes

These terms are governed by the laws of the Republic of Türkiye, and the courts and enforcement offices of İstanbul (Çağlayan), Türkiye have exclusive jurisdiction over any dispute arising from them.

If you are a consumer rather than a business, this does not remove the protections of the mandatory consumer law of the country you live in, and it does not stop you bringing a claim in your own local courts where that law gives you the right to.

21. Contact

Questions about these terms, about a filtering decision, or about a data processing agreement can go through our contact page.

Related documents

We would like to count visits with Google Analytics, which sets two cookies. Decline and nothing is loaded and nothing is sent. What these are.