What mailsort is
mailsort is a personal tool of the owner of this website. It labels the owner's own Gmail, is not offered to anyone else, and its dashboard is open to the owner only.
What it can do in Gmail
- It asks Google for the
gmail.readonlyscope first andgmail.modifylater, never for the fullhttps://mail.google.com/scope. - Through a closed list of Gmail API operations it reads messages, their labels, the mailbox's list of labels and its change history; creates the label 分拣 (“sorting”) and labels under it, and renames them; adds one of those labels to a message and may remove the message from the inbox (archive). An undo removes that label and puts the message back in the inbox.
- It never sends, deletes or trashes mail and never marks mail read or unread. The only labels it renames or adds to mail are under 分拣/, including ones the owner made there; the only other label it changes on a message is the inbox.
- Every change it makes to a message is recorded in its ledger first and, while the entry is kept (180 days), can be undone from there, unless the owner has since moved the mail to another label or the label was deleted.
How mail is processed
A new message is decided by the owner's rules, the nearest examples the owner has confirmed or corrected (or left alone for three days), compared through embeddings from the bge-m3 model, and a decision model (Clef on Cloudflare Workers AI). All of this runs in the owner's own Cloudflare account. The models are called directly, without AI Gateway, which would log request bodies.
The models read masked text only: the sender's display name and domain, the subject (up to 200 characters), Gmail's snippet (300), the first text part of the body (2,000), Gmail's category, whether the message came from a mailing list, a short code derived from the address it was delivered to (never the address), and the masked summaries of similar examples, together with the owner's label names and descriptions. Email addresses and numbers of six or more digits are masked, and links are cut to their domain, before a model sees them.
What is stored, and for how long
Everything is stored in the owner's own Cloudflare account and cleared daily:
- A decision's content (masked subject, sender and summary, and the exact sender address, domain, List-Id and delivered-to address): 14 days.
- The review queue (masked subject and sender): 14 days after the message arrived.
- Decisions and the ledger of changes, without content: 180 days.
- Examples (a masked summary of at most 200 characters and its embedding): until the owner deletes them, at most 2,000.
- Rules (a sender address, domain, List-Id or delivered-to address, subject words and the owner's evidence and notes): until the owner deletes them, at most 500.
- Labels (their names under 分拣/, some read from Gmail, and the owner's descriptions): until the owner deletes them, at most 24.
- Answers to the owner's own changes in the dashboard, kept so that a retried request is not applied twice (they can hold a masked subject and sender or a rule's values): 1 day.
- Daily counters without content: 400 days.
Logs hold counts and codes only, never subjects, senders, addresses or label names. Google's authorization is kept only as encrypted secrets in the owner's own Cloudflare account, never in source code or on GitHub.
How the data is used
The data is used only to label the owner's own mailbox and is read by no one but the owner. It is not sold, not used for advertising, not used to train generalized AI models and not shared with anyone; Cloudflare processes it only as the host and model provider (Workers AI) of the owner's own account.
mailsort's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access and deleting data
Access can be revoked at any time at https://myaccount.google.com/permissions. Revoking stops every Gmail read and write but does not delete what is stored: content expires as listed above, and examples, rules and labels stay until the owner deletes them in the mailsort dashboard (deleting a label also deletes its rules and examples).
Contact
Questions about this policy can go to the owner through the links on the home page.