Local
- Works in your open Gmail tab. No Gmail API OAuth, no Google cookies.
- Index, drafts, rules and settings stay in your browser.
- On-device models and Ollama keep AI on your machine.
- Add your own provider key, and that provider sees what you send it.
Cloud
- Opt-in, private beta.
- Requests go over TLS to PigeonBox Cloud and one configured model.
- Request bodies are never logged.
- If Cloud fails, you get an error. Nothing reroutes.
- Connecting Google is a separate step, scope by scope.
What Cloud keeps
- Metadata: senders, recipients, subjects, IDs, times.
- Derived data: summaries, drafts, search text. Encrypted.
- Fast Recall: opt-in encrypted excerpts, for as long as you choose.
- Usage: counts and timing. No content.
- Account: sign-in and subscription status. Stripe handles cards.
Not message bodies, by default. Every row is locked to your account.
Tracking
Optional. A tracker keeps the subject, sender, recipients and send time, plus each open or click with a hashed IP. Never the body.
An open is a signal, not proof of a read.
Analytics
No ads. No analytics provider. Optional usage counters stay in your browser. This site sets no cookies.
Deleting data
Clear the local index in Settings, or uninstall. Deleting a Cloud account is designed to remove its Cloud data.
Describes the current architecture, not a final legal notice. Details: privacy policy, privacy model, security.