- Inbox Sanity runs on your Mac. We do not operate servers for it.
- We do not receive, collect, store, or sell your email, contacts, or any other personal data.
- The app has no analytics, no advertising, and no tracking.
- Your data leaves your Mac only to go to services that you connect or turn on, such as your email provider or an AI provider that you choose.
Data the app uses
To do its work, the app uses this data on your Mac:
- Email. Messages, headers, labels, and folders in the accounts that you connect. The app reads new email to evaluate it against your rules, and it acts on your instructions: reply, archive, label, mark read, trash, report spam, or unsubscribe.
- Contacts. For Gmail accounts, your Google contacts and "other contacts". The app uses them to not act on email from people you know.
- Gmail settings. Your send-as addresses and Gmail filters, so that replies come from the correct address and so that you can manage filters from the app.
- Your rules, templates, and settings. Data that you create in the app.
- OpenPGP keys. Your secret keys and the public keys of your contacts, if you use encryption.
- Voice. If you use the voice assistant, your speech is converted to text on your Mac with Apple's on-device speech recognition. Spoken answers are made on your Mac.
Where the app stores data
All data stays on your Mac:
- App database (SQLite, on your Mac): account names and addresses, message metadata (sender, subject, date, labels, and a short snippet), your rules and templates, a log of each decision and action with its reason, cached domain registration dates, and screenshots taken when the "Click link" action opens a link. The app does not store full message bodies, except for the sample emails that you save to test a rule.
- macOS Keychain: Google sign-in tokens, IMAP and SMTP passwords, AI provider API keys, and OpenPGP secret keys.
- Decrypted email stays in memory only. The app does not write it to disk, except for attachments that you tell it to save.
Services the app connects to
The app connects directly from your Mac to these services. We are not in the middle. Each service has its own privacy policy.
| Service | When | What is sent |
|---|---|---|
| Google (Gmail API, People API, Google sign-in) | You connect a Gmail account | Requests to read and change your mail, contacts, and Gmail settings |
| Your IMAP and SMTP server | You connect an IMAP account | Your credentials and requests to read, change, and send mail |
| AI providers that you turn on: Anthropic, OpenAI or an OpenAI-compatible service, TypeSafe (SystemOne), Cloudflare | A rule uses that provider, or you use a feature that generates text with it | Your rule question and the email's sender, subject, and part of its body |
| Apple Intelligence, Ollama, Osaurus, Tev1 on MLX | A rule uses that model | Nothing leaves your Mac when these run locally (the default). If you point Ollama or an OpenAI-compatible setting at another computer, email content goes there. |
| Hugging Face | You download a local model or voice | A download request. No email data. |
| rdap.org | A rule checks how old a sender's domain is | The sender's domain name |
| The recipient's domain (OpenPGP Web Key Directory) | You send encrypted email and the app looks up a public key | A request for the recipient's public key, which includes a hash of the address |
| Links in an email's unsubscribe header | You unsubscribe, or a rule does | A standard unsubscribe request or email to the sender |
| One link that a rule names ("Click link" action) | A rule with that action matches | A visit to that link in a private web view with no saved cookies |
Encrypted email and cloud AI
By default, the app does not send decrypted email text to AI models that do not run on your Mac. It does so only if you turn on that setting.
Mail sent as you
Inbox Sanity can send replies and unsubscribe emails from your account when a rule tells it to. New rules wait for your approval before they act.
Google user data
Inbox Sanity's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- The app uses Google user data only to provide the features that you see in the app: evaluate, organize, reply to, and unsubscribe from your email.
- Google user data goes from Google directly to your Mac. We do not receive it.
- Google user data goes to a third-party AI provider only when you turn that provider on for a rule, and only to answer that rule's question.
- We do not use Google user data for advertising, and we do not sell it.
- No person reads your Google user data. We do not have access to it.
- We do not use Google user data to train AI models.
How long data is kept
Data stays in the app's database until you delete it. Removing an account from the app deletes its sign-in tokens from the Keychain. To remove all data, quit the app and delete the app's data folder and its Keychain items.
To remove Inbox Sanity's access to your Google account, go to myaccount.google.com/permissions.
Security
Secrets are in the macOS Keychain. Connections to online services use HTTPS or TLS. Your Mac's security (FileVault, your login password) protects the app database.
Children
Inbox Sanity is not for children under 13.
Changes to this policy
If we change this policy, we will update the effective date above and publish the new version at https://inbox-sanity.ai/privacy-policy.
