Privacy & data handling

Last updated 12 June 2026.

What mailai stores

mailai syncs your mailboxes over IMAP and stores message headers, a short text snippet and a search excerpt (up to 8 KB) in its database (Neon Postgres, EU region). Full message bodies are fetched live when you open an email and cached so reopening is fast. Attachments are never stored — they are streamed on demand.

Your mailbox credentials

App-specific passwords are encrypted at rest with AES-256-GCM; the key lives only in the server environment. Credentials are used solely to sync, send and move your own mail. Removing a mailbox deletes its credentials.

AI processing (LLM disclosure)

mailai uses large language models via OpenRouter (currently GPT-4o-mini for classification and Gemini 2.5 Flash for drafting) to categorise mail, extract parcels, trips and events, summarise messages and draft replies. For these features, the email's sender, subject and up to 8 KB of body text are sent to the model provider per request. Models are never trained on your mail; requests are processed and discarded per OpenRouter's and the providers' API terms. Reply drafting only runs when you press a button; classification runs automatically as mail syncs.

Tracking protection

Remote images and tracking pixels in emails are blocked by default; senders cannot see that you opened a message unless you choose "Load images".

Third parties

Hosting: Vercel (app) and GitHub Actions (sync worker). Database: Neon. AI: OpenRouter. Optional: Unsplash (city photos — no personal data) and Google Calendar (only if you connect it; scope is limited to creating events, tokens are AES-GCM encrypted and can be disconnected in Settings).

Deletion

Removing a mailbox stops its sync and deletes its credentials; synced messages can be removed on request. Deleting your account cascades to all stored messages, tasks, tokens and logs.

Questions: lgt@opfinder.ch · Back to sign in