Privacy
What Stillmail does with your mail, in plain terms.
What is stored
Sender address, sender name, subject, List-Id, and the date, for messages in the last 90 days. Plus the decision made about each one and the reason for it.
What is never stored
Message bodies. When sender history is not enough to route a message, the first 500 characters of its plain text are sent to Anthropic’s API for classification and discarded as soon as the answer comes back. Nothing is used to train any model.
What Stillmail can do to your mail
File messages — labels in Gmail, folders in Outlook — mark them read or unread, and move them to the trash when you have marked a sender as noise or black-holed it. Trashed mail stays recoverable: 30 days in Gmail, and in Deleted Items in Outlook until you empty it. Stillmail never permanently deletes mail and never empties the trash.
Stillmail never stars a message in Gmail or flags one in Outlook. That gesture is left to you alone, which is what lets it be read as you saying a message is yours to deal with.
Access
Stillmail holds an OAuth refresh token for each connected mailbox, encrypted at rest and never sent to the browser. Disconnecting a mailbox revokes the token with the provider that issued it, stops watching the mailbox, and deletes the credentials. You can delete all of the decision history at the same time.
Sharing
Nothing is sold or shared. The only third parties involved are your mail provider — Google or Microsoft, whichever you connected — Supabase (the database), Vercel (hosting), and Anthropic (classification).