Privacy Policy

Your mail stays on your Mac.

Inbox Sanity is a macOS app made by Poison Pen ("we", "us"). This policy tells you what data the app uses, where that data goes, and what control you have.

Effective October 7, 2026

The short version

Data the app uses

To do its work, the app uses this data on your Mac:

Where the app stores data

All data stays on your Mac:

Services the app connects to

The app connects directly from your Mac to these services. We are not in the middle. Each service has its own privacy policy.

ServiceWhenWhat is sent
Google (Gmail API, People API, Google sign-in)You connect a Gmail account Requests to read and change your mail, contacts, and Gmail settings
Your IMAP and SMTP serverYou connect an IMAP account Your credentials and requests to read, change, and send mail
AI providers that you turn on: Anthropic, OpenAI or an OpenAI-compatible service, TypeSafe (SystemOne), Cloudflare A rule uses that provider, or you use a feature that generates text with it Your rule question and the email's sender, subject, and part of its body
Apple Intelligence, Ollama, Osaurus, Tev1 on MLXA rule uses that model Nothing leaves your Mac when these run locally (the default). If you point Ollama or an OpenAI-compatible setting at another computer, email content goes there.
Hugging FaceYou download a local model or voiceA download request. No email data.
rdap.org A rule checks how old a sender's domain is The sender's domain name
The recipient's domain (OpenPGP Web Key Directory) You send encrypted email and the app looks up a public key A request for the recipient's public key, which includes a hash of the address
Links in an email's unsubscribe headerYou unsubscribe, or a rule does A standard unsubscribe request or email to the sender
One link that a rule names ("Click link" action)A rule with that action matches A visit to that link in a private web view with no saved cookies

Encrypted email and cloud AI

By default, the app does not send decrypted email text to AI models that do not run on your Mac. It does so only if you turn on that setting.

Mail sent as you

Inbox Sanity can send replies and unsubscribe emails from your account when a rule tells it to. New rules wait for your approval before they act.

Google user data

Inbox Sanity's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

How long data is kept

Data stays in the app's database until you delete it. Removing an account from the app deletes its sign-in tokens from the Keychain. To remove all data, quit the app and delete the app's data folder and its Keychain items.

To remove Inbox Sanity's access to your Google account, go to myaccount.google.com/permissions.

Security

Secrets are in the macOS Keychain. Connections to online services use HTTPS or TLS. Your Mac's security (FileVault, your login password) protects the app database.

Children

Inbox Sanity is not for children under 13.

Changes to this policy

If we change this policy, we will update the effective date above and publish the new version at https://inbox-sanity.ai/privacy-policy.

Contact

info@inbox-sanity.ai