How it works & privacy

The app talks to a small server on Cloudflare that works with your Gmail account. Here's what that server does, and what it keeps.

The pieces

What happens when mail arrives

  1. Gmail tells Google Cloud Pub/Sub your mailbox changed, and Pub/Sub notifies the server.
  2. The server fetches the new email from Gmail and asks the triage model to pick a tag.
  3. It adds the Gmail label, and archives the email if your triage mode allows it.
  4. It tells the open app to refresh.

Once a day the server renews its Gmail subscription for each account, so notifications keep flowing.

What the server stores

DataWhy
Your email address and Google refresh token, encrypted with AES-GCMSo it can work on your mailbox while the app is closed
Hashed session tokensTo recognize your signed-in app. Sessions expire after 90 days.
Triage decisions: tag, a one-line reason, confidence, and whether it archivedTo show the tag and let you correct it
Saved thread summariesSo a summary is still there when you reopen the thread
Your settings: triage mode, custom tags, signature, AI providers (API keys encrypted)To apply your preferences
Embeddings for threads in tags you marked for AI searchTo run AI search. These are numeric vectors, not message text.

Message bodies are fetched from Gmail when needed and aren't stored on the server.

Where your mail goes for AI

Removing access

Sign out from the account menu to end your session. To cut off the server completely, remove its access in your Google account permissions. Its stored refresh token stops working immediately.