Privacy policy
Personal-use application · Updated September 24, 2026
Personal Inbox Assistant is privately operated software for its owner's Gmail account. It uses Google user data to provide the Inbox triage the owner has requested. It is not a public service and does not offer accounts to other users.
Information accessed and its purpose
With the owner's Google authorization, the application accesses the Gmail account identity, message identifiers, labels, history records, relevant headers, MIME structure, and message text. These are used to identify new Inbox arrivals, check protections, classify eligible content, verify permitted changes, and detect messages restored by the owner.
The application does not fetch links, remote images, tracking pixels, or QR destinations in email. It does not open, execute, save, or send attachments to the AI classifier. Attachment-bearing or uncertain messages receive no Gmail changes. Reading through the Gmail API does not itself mark a message as read.
External classification
Only after local checks and the owner's explicit approval, eligible messages' bounded, sanitized plain text is sent to the OpenAI API. The selected headers, when present, are From, Subject, Date, Reply-To, In-Reply-To, References, List-ID, Precedence, and Auto-Submitted. Body text may itself contain personal information despite conversion to plain text.
Gmail access credentials and attachments are not supplied to OpenAI. The classifier receives no tools, browsing, shell, filesystem, or Gmail access. Requests use store:false; this does not mean zero retention. OpenAI's applicable account-level data and abuse-monitoring policies still govern its processing. This application makes no separate promise about a provider's training or retention practices.
Google receives the API requests necessary for Gmail access and label changes. The application does not sell email information, use it for advertising, or share it with other services for unrelated purposes.
Google API data is used only for the owner's requested, visible Inbox-triage features. The transfer of eligible text and selected headers to OpenAI is limited to that classification purpose and requires the owner's approval. This policy is a description of the application's data use, not a claim that Google has verified or endorsed it.
Local storage and retention
A SQLite database on the owner's virtual machine stores message identifiers, relevant label state, synchronization records, classification results, actions, audit events, and permanent restore overrides. Full email bodies and sanitized classification text are processed in memory and are not saved in that database. The saved explanations are bounded policy summaries rather than copies of email content.
The current default keeps detailed decisions and audit information for 365 days, after which details are removed or reduced. Compact handled-message identifiers and label-action records remain to prevent accidental reprocessing. Permanent overrides remain until the owner explicitly instructs their removal; routine retention cleanup never clears them.
Host-controlled backups contain consistent database snapshots, configuration, and overrides, encrypted with age. Current rotation retains 28 snapshots at six-hour intervals. Older information can remain in a retained backup until that backup rotates out. Backups currently stay on the same computer; no external backup destination is configured.
Credentials and security
OAuth credentials, API keys, and the backup encryption identity are held in protected files separate from the database, ordinary configuration, source code, logs, and backup archives. The host retains disk encryption. The worker runs without administrative privileges, with restricted filesystem and network access. There is no public application or database server.
The requested gmail.modify permission is broader than label editing and includes capabilities such as sending mail. The application's code does not send, reply, forward, automatically unsubscribe, edit mailbox filters, move messages to Gmail Trash, or permanently delete mail. A stolen OAuth token would retain the underlying scope's authority.
Owner control
The owner can pause processing, review local records, edit validated settings, use guarded undo, and revoke Google authorization through Google Account settings. Returning a moved message to Inbox permanently prevents this program from automatically processing that message again, even if the Auto-Trash label remains.
Revoking authorization stops future authorized access but does not automatically erase existing local records or backups. To remove those records, the owner must stop the application and arrange deliberate local-data and backup removal. Deleting permanent overrides removes an important protection, so lost state must never be treated as permission to process historical mail.
This information website
These static information pages contain no forms, analytics scripts, advertising, or external assets. When the pages are hosted, the hosting provider may process visitor IP addresses, request URLs, timestamps, browser information, and ordinary security or access logs to deliver and protect the site. If served through Cloudflare, Cloudflare's applicable data-handling policies govern that hosting activity. This policy does not promise that infrastructure request logging is absent.
The information website does not connect to the private Gmail application, receive Gmail credentials or email content, or provide remote access to the owner's computer.
Questions and updates
For questions, contact the owner or administrator who installed this private copy. There is no public support service. This policy should be reviewed whenever the application's purposes, providers, permissions, or retention settings change.