Privacy

Mailbag connects to your Gmail account with your permission (Google Sign-In) to read, score, and act on messages in your inbox. For iCloud it uses an app-specific password you create. To sort machine mail its rules cannot place, Mailbag sends the sender, subject and a short preview of those messages to a language model running on Cloudflare, the same company that hosts Mailbag. Mail that shows no sign of a machine, which is how Mailbag recognises a person, is never sent to the model. Nothing else about your mail leaves Mailbag and your mail provider.

What Mailbag accesses

Message headers and bodies in your Gmail inbox, to score and display them. Labels and folders. When you press File, Mailbag creates a folder called Mailbag with seven folders under it (Gmail labels or iCloud folders) and moves mail there. It also archives or deletes when you ask. Deleting in Gmail moves mail to Trash. It never sends outbound mail on your behalf.

What Mailbag stores

An OAuth access/refresh token, encrypted at rest in Cloudflare KV, so you don't have to reconnect every visit. No message content is stored — inbox data is read live from Gmail each time you open the app and discarded after rendering. Mailbag keeps no copy of what it sends to the model.

What Mailbag never does

Sell or share your data with third parties. Use your mail for advertising. Run in the background without you opening the app.

Revoking access

Remove Mailbag's access anytime at myaccount.google.com/permissions.

Contact

Questions: heyitsmejosh.com.