Privacy & security
This service connects one mail account to each signed-in ChatGPT user.
What is stored
Your email address, server settings, usernames and passwords are encrypted together with AES-256-GCM before being saved. The encryption key is a hosting secret, separate from the database. Each encrypted record is bound to its owner’s identity. Passwords are not returned to the browser or ChatGPT after saving.
What is processed
The server decrypts your settings in memory only to connect to your mail provider over verified TLS. The service operator controls the running application and encryption key; this is not end-to-end encryption. Email content is returned to ChatGPT when you request it but is not stored in this service’s database. Your provider’s and ChatGPT’s data policies also apply.
Sending and access
The plugin can search and read email without marking it read, and send plain-text email when you authorize it. It cannot delete or move messages. Access is isolated by your signed-in identity. Request counters and send request IDs are stored to limit abuse and duplicate sending; message bodies and recipient lists are not stored there.
Disconnecting
Disconnect removes the active encrypted mail record and stored send request IDs immediately. Rate-limit counters remain. Historical database backups may retain prior encrypted records according to the hosting platform’s retention. To revoke access at the provider immediately, revoke your app password there too. A request already in progress may finish after disconnecting.
Compatibility
Use public mail hostnames and standard encrypted ports. OAuth-only providers and private network mail servers are not supported. Read limits are 1 MB per message and 50,000 body characters. Outgoing mail is limited to 20 recipients and five send attempts per hour. Sent-folder copies are not created.
Use responsibly
Connect only accounts you own or are authorized to access. Do not use this service for unsolicited bulk email. Provider policies and delivery restrictions apply.