Mailbox Alert
← Back to home
Privacy Policy

We watch the mailbox. Not your mail.

Mailbox Alert tells you when your mail arrives and when someone visits your mailbox, using the Ring cameras you already own. It recognizes postal and delivery carriers only by their uniform, equipment, or vehicle livery — never by who they are — and it never reads addresses, names, or anything written on your mail. This policy explains exactly what we collect, how we use it, and the control you keep.

Last updated: July 10, 2026
This service is available only to U.S. residents.
No facial recognition, no biometrics, no identifying individuals
We never read addresses, names, or mail contents
Event records and snapshots auto-purged after 90 days
Never sold or shared for advertising · CCPA / CPRA compliant

What we collect

How we use it

Solely to operate Mailbox Alert: detect mail and package delivery at your own mailbox, tell you when your mailbox is visited, keep your delivery timeline, and send the notifications you configure. We do not sell or share your data with third parties for advertising, and we do not use your data to train AI models.

Mailbox activity detection, explained

Mailbox Alert classifies what is happening around your mailbox. This is non-identifying activity information.

What we detect. When your Ring camera reports a motion event, a snapshot is analyzed to determine whether a postal or delivery carrier is present (recognized only by uniform, equipment such as a mail satchel, or vehicle livery), whether mail or a package is being delivered, or whether a person is at the mailbox. The result is an event category with a confidence score.

What we do NOT do. We perform no facial recognition and no biometric analysis of any kind. We do not attempt to identify, name, or track any individual — including delivery drivers. We do not read license plates. We do not read addresses, names, barcodes, or any text on mail or packages; the AI model is explicitly instructed not to read text in the image.

How the analysis works. Detection is inference-only. Each snapshot is classified by a first-party open-weights vision model — Qwen 3.5 (9B, q8_0) served through Ollama on a GPU workstation owned and operated by Erbacci LLC in Dubai, United Arab Emirates. The image reaches it over TLS via an Erbacci-managed relay server in Germany, which terminates TLS and forwards over an encrypted tunnel but performs no analysis and stores nothing; on the workstation the image is held in memory only, is never written to disk, and only a short text label is returned. If that model cannot answer — an error, a timeout, or a reply that fails validation — the snapshot is analyzed instead by Anthropic Claude Haiku 4.5 through Amazon Bedrock inside Amazon Web Services (United States), so that no event is lost. Both engines are inference-only: your snapshots are never used to train any AI model, and no third party beyond the processors listed below ever receives your media.

Snapshot storage. For events that generate an alert, we store the single analyzed still image in a private, encrypted storage bucket so your timeline can show you what happened. Snapshots are automatically deleted after 90 days, and immediately when you unlink your Ring account or delete your account. Continuous video is never stored.

Third-party processors

Amazon Web Services
Backend hosting (Lambda, DynamoDB, S3, SQS, API Gateway) and push routing (Simple Notification Service) in the United States.
Anthropic (via Amazon Bedrock)
Fallback AI vision analysis of event snapshots, used only when our own model cannot answer. Runs inside AWS; inference-only, no training on your data.
Ring LLC
Source of camera events and media via the official Ring Partner API.
Resend
Email delivery for sign-in codes and alerts (receives your email address and the message text — never any camera media).
Contabo GmbH (Germany)
Hosts an Erbacci-managed relay used only to terminate TLS and forward vision requests over an encrypted tunnel. It performs no analysis and retains no image.
Apple Inc.
Push notification delivery to iPhone (receives your device push token and the alert text — never any camera media).
Google LLC
Push notification delivery to Android via Firebase Cloud Messaging (receives your device push token and the alert text — never any camera media).

Data retention

Event records and alert snapshots are retained for 90 days, then automatically purged. Account data (Ring link, email, settings) is retained until you unlink or delete your account. Unlinking your Ring account immediately removes your Ring tokens and purges your event history and snapshots. Account deletion takes effect within 30 days.

Your California rights (CCPA/CPRA)

If you are a California resident, you have the right to:

Children

Mailbox Alert is not directed to children under 13. We do not knowingly collect data from children.

Security

Data is encrypted in transit (TLS 1.2+) and at rest. OAuth refresh tokens are stored encrypted in DynamoDB. Snapshot storage is a private bucket with public access blocked. Access is restricted via IAM least-privilege policies. No human reviews your camera media.

Changes

We may update this policy. Material changes will be communicated via in-app notice at least 30 days before taking effect.

Contact

Erbacci LLC — info@erbacciltd.com