MailHandled

Trust & safety

Built so it can't betray you

An assistant that reads your email has to earn more trust than any other software you use. These aren't policies we promise to follow, they're constraints built into how MailHandled works.

1. No reply is ever sent without you

MailHandled writes drafts. Every reply it prepares waits in your own Drafts folder and in your approval queue, where you read it, edit it, and press Send. Pressing Send is what sends it, whether you press it here or in your own mail app. Nothing goes out on a schedule, on the assistant's own judgement, or in the background: no code path reaches a send without a press, and the words that leave are the words you approved, read back from the draft and compared against them in the moment before it goes. Service notices are a separate matter, and they go only to you: an urgent alert to you about your own mail, to your own inbox (and your phone, if you turn that on), a note when one of your mailboxes stops being readable, and a weekly summary you can switch off in Settings. Reading does not wait for a button either: your mail is fetched, screened, and the part that needs an answer is sent to the model that drafts it. That processing is the work. The gate is on replying, not on reading.

2. Nothing is ever deleted

MailHandled labels and organizes; it never deletes or archives your email. Mail it screens out is labeled "Screened" and stays exactly where it was, and every screened email appears in your Emails handled ledger, where one tap re-files it (here and in your mailbox) and tells the assistant never to screen that sender again.

3. Your mail is never training data

Your email is processed to do your work and for nothing else. We don't train models on your mail, we don't sell or share it, and the AI models we use are run with training on inputs disabled.

Processed, though, means it is read by a computer somewhere, and you should know where. Our app runs on Vercel and our database on Neon, which hold what the privacy page lists as stored. Beyond them, two companies read the content of your mail and no others: Anthropic sorts your mail, writes your drafts and reads scanned pages, and DeepInfra turns passages of your filed documents into the numerical form that lets you search them by meaning. A third, Resend, carries notices about your account when none of your own channels can: it sees the address you sign in with and the account the notice is about, and for an urgent alert the sender and subject line of the email, never its contents. Your documents themselves stay in your own Google Drive; we keep a link, not a copy. The privacy page lists exactly what we store.

We would rather say this plainly than claim your data never leaves your account. An assistant that reads your mail has to read your mail. What we can promise is that the list of who sees it is short, named, and shorter than you would expect.

4. Minimal access, revocable in one click

Each connection asks only for the scopes its job needs: reading your mail and labelling it, marking as read what it has screened out as noise, writing drafts and sending the ones you approve, reading your signature so a draft carries it, seeing your calendars and adding the events you approve, and filing attachments into a folder it created in your Drive. For Drive it asks for the narrow scope that reaches only its own folder, never the rest of your files. Disconnect any account on the Accounts section of Settings and access ends immediately; you can also revoke MailHandled from your Google or Microsoft security settings at any time, and we honor deletion requests completely.

5. Billing that respects you

No credit card to try it. Cancel from your account page, with no email and no call: one question about why, which you can leave blank, and one offer to pause instead, which you can decline. You keep everything until the end of the period you have paid for, and you are not charged again. Pause it for a while and nothing is billed until you come back. No credit meters that burn on failed tasks. One flat price for an assistant that works all day.

The keys you keep

Urgent detection, triage decisions, and every lesson MailHandled learns from your corrections are visible in the product. Never a black box. If MailHandled ever gets something wrong, the audit trail shows you exactly what happened to every email, and your correction outranks every heuristic we have.

Why not just use ChatGPT or Claude with your Gmail?

A fair question, and for some things those are the better tool. If you want to ask what a thread said, find an invoice from June, or draft one reply while you are sitting there, an assistant with access to your mailbox will do it well, right now, inside a subscription you already pay for. MailHandled does not try to win that argument.

The difference is that an assistant answers when you ask. MailHandled works when you do not. Google and Microsoft push new mail to it as it lands, it sweeps your accounts on a schedule you set, and it pushes to your phone when something cannot wait. A chat window has no idea anything happened until you open it. A bank declining your card at two in the morning is not a question anyone thinks to ask.

The rest follows from that. It keeps a record of every email it touched and why, so it can tell you what it did while you were away, and so an urgent alert is sent once and never twice. It reads every mailbox you have, Gmail and Outlook together, and merges every calendar into one view. And it is built to refuse: no reply is sent without your press, a reply is rebuilt from the words on your screen at the moment you press, and a send fails rather than go out without an attachment you ticked. An assistant with permission to write to your mailbox is one confident paragraph away from sending the wrong thing to a client.

If you only want answers about your mail, use the chat assistant. If you want something watching the mail when you are not, that is what this is for.

MailHandled is built by Hoshmand AI. It is in private beta and has not yet completed Google's OAuth verification, so signing in still shows Google's unverified app screen. Questions: support@hoshmand.ai.