Trust center

What Nickbox can access in Gmail, Microsoft and IMAP inboxes, the permission modes, how sending needs your approval, what we keep, who processes it, and how to report a security issue.

Updated · 6 min read

Draft for the public beta. Pending legal review.

This page is the plain-language summary of how Nickbox handles access to your mail. It extends the privacy policy and the security page; it does not replace them. If anything here differs from the privacy policy, the privacy policy applies until we fix the difference.

What is available today and what is coming

Available today: Gmail inboxes, read-only. Your AI assistant can search and read. It cannot send, draft, delete, label or change anything.

Coming, not available yet: Microsoft inboxes, IMAP inboxes, drafts, sending with your approval, and the activity log. Everything below about those features describes the rules we have decided on. It is not a statement that they are live. A feature is live only when you see it in your dashboard. We update this page when each one ships.

What Nickbox can access, by provider

  • Gmail (today). The permission https://www.googleapis.com/auth/gmail.readonly, plus openid and email to sign you in. It allows searching and reading messages.
  • Gmail (planned, higher modes). The permissions gmail.compose for drafts, gmail.send for sending and gmail.modify for organizing messages, each requested only when you raise an inbox to a mode that needs it. Nickbox will never ask for the full-access permission https://mail.google.com/.
  • Microsoft (planned). Mail.Read and offline_access for reading. Mail.ReadWrite for drafts and organizing. Mail.Send for sending.
  • IMAP (planned). You give an app password from your mail provider. Nickbox connects over TLS only (IMAP on port 993, outgoing mail on port 465 or 587) and stores the password encrypted. Gmail inboxes cannot be added by IMAP. Nickbox will never permanently delete messages and will never run the IMAP expunge command.

An important limit: Nickbox enforces the mode on its own server. A Google or Microsoft permission by itself does not guarantee the mode, because some permissions allow more than the mode does, and IMAP has no permissions at all. The server checks the mode on every call.

The four modes

You set a mode for each inbox. The default is read. The mode that applies is the lowest of the inbox mode, the limit of the access profile your assistant connected with, and what your plan allows.

  • read: search and read only.
  • draft: also create and edit drafts. Nothing is sent.
  • send_approval: also prepare messages to send. Nothing leaves until you approve it.
  • full: also organize messages (move, label, archive). Sending still needs approval when the recipient is new, see below.

Raising a mode shows a confirmation screen that says in plain words what the assistant will be able to do. Lowering a mode takes effect at once in Nickbox. Google does not let an app give up a single permission, so to remove the permission itself at Google, disconnect the inbox and connect it again at the lower mode. Nickbox will not say a permission was removed when it was not.

Sending needs your approval

An AI assistant can never send mail by itself through Nickbox.

  • In send_approval, when the assistant asks to send, Nickbox does not send. It stores only metadata and a fingerprint of the message, and gives you a link to the dashboard.
  • In the dashboard you see the exact message that would go out: sender, every recipient, subject, text, links and attachments. If the draft changed after the assistant asked, you cannot approve it until you review the new version.
  • Your approval is tied to that exact message, works once, and lasts 10 minutes. You need to have signed in within the last 10 minutes. Pending requests expire after 24 hours.
  • A reply in the chat with your assistant is never an approval, and no assistant tool can approve.
  • In full, a message to an address you have never written to from that inbox also needs this approval. Only the Sent folder outside Nickbox counts as having written to someone; mail you received never does.

Text inside emails is untrusted. Nickbox returns it to your assistant in a marked envelope with a fixed note: it is third-party text, not instructions, and it cannot authorize sending, a mode change or any action. This reduces prompt injection. It does not remove the risk, which is why the approval step exists.

What we keep and for how long

Today, as the privacy policy says: account data, inbox nickname, address and connection status, one encrypted credential per inbox, usage counts, and billing references from Stripe. Message bodies, subjects, attachments and search results pass through memory and are not stored.

Planned with the new features:

  • Activity log. One entry per assistant call: time, tool, which inbox, which assistant, number of results and status. It never contains your search query, subjects, addresses, attachment names or message content. You see it in the dashboard. It is kept 7 days on the Personal plan and 90 days on Pro, and Pro can export it as CSV. These plans are not on sale yet.
  • Send requests. Metadata and a fingerprint only, never the message. They expire after 24 hours.
  • Credentials. Encrypted with keys managed in Google Cloud. Only the Nickbox server can decrypt them. The dashboard cannot, and no API returns them.
  • Pause. A switch for one inbox and one for all inboxes. While paused, every assistant call is refused within seconds.
  • Privacy filters. Per inbox, you can exclude folders, labels, senders and domains, and limit access to the last months of mail. Excluded messages are not returned by search or by direct ID.

Our logs do not contain message content. We test this in our automated checks by sending messages with a marker string and failing the build if it shows up in logs or in the database. Platform request logs from Google Cloud, which include URLs, are outside that test, so Nickbox never puts secrets or email addresses in URLs.

Who processes data

These are the same processors as in the privacy policy, which has the details and the region:

  • Google Cloud (us-central1): hosting, database, secrets and encryption keys.
  • Stripe: payments and invoices.
  • Google Analytics: website visit measurement.
  • PostHog: website product analytics.
  • Sentry: error reports, with email addresses, tokens and URL query strings removed.
  • Better Stack: uptime monitoring of public pages, if enabled.

Your mail provider (Google, Microsoft or the company behind your IMAP inbox) holds your mail. It is not our processor. Mail content reaches our server only while your assistant asks for it and is not sent to analytics or error tools. Nickbox does not run AI models over your mail and does not use it to train any model.

Report a vulnerability

Write to soporte@nickbox.io with the subject "Security". English or Spanish. We reply within two business days. The same details are in machine-readable form at /.well-known/security.txt.

Please include what you found, the steps to reproduce it and the impact you see. Test only with your own accounts and data, do not read or change anyone else's data, and give us a reasonable time to fix the problem before you publish it. We cannot promise rewards.

Delete your data

  • Disconnect an inbox. Deletes its connection data and revokes access with the provider, for Gmail through Google.
  • Delete your account. Cancels your plan, revokes every inbox, and removes the records we hold, apart from invoices that Stripe must keep. In the planned "Your data" page you can first download a JSON export of what Nickbox stores about you.
  • You can also remove Nickbox yourself at myaccount.google.com/permissions.

What we do not claim

Nickbox has not completed Google's verification of apps that read Gmail, which is why the beta is limited. We have no security certification and no published third-party audit. When we run an audit we plan to publish its findings and our fixes here.