LocalInbox has no server of its own. Your Mac connects straight to your mail provider, AI runs on your Mac with Apple's on-device model, passwords are kept in the macOS Keychain, and there's no analytics or telemetry. Below is every connection the app can make, taken from its published network list.
Where your mail goes
Between your Mac and your mail provider, over TLS, and nowhere else. LocalInbox never receives, stores or reads your mail, because there is no LocalInbox server for it to go to.
Summaries, replies, Rewrite, Ask your mailbox, sorting, phishing checks and text recognition in attachments all run on your Mac. They open no connections of their own. macOS may download Apple's language assets for these system features itself.
Passwords and keys
- Account passwords and sign-in tokens live in the macOS Keychain, never in a file or on a server.
- Settings that follow you through iCloud are appearance and preferences only, never mail or passwords.
- An optional Touch ID lock keeps the app closed to anyone else at your Mac.
Reading mail safely
- Message HTML renders with JavaScript off and a content policy that blocks everything by default.
- Remote images, CSS and fonts load only when you click Load images for that message, or Always for this sender.
- Tracking pixels are removed and tracking parameters are cut from links.
- Links never open from inside the app: they open in your browser when you click them.
- Attachment previews read the downloaded file on your Mac and open no connections.
Every connection the app makes
This is the complete list. If LocalInbox ever connects anywhere else, that's a bug, and we'd like to hear about it.
| Connects to | When, and what it sends |
|---|---|
| Your mail servers (IMAP and SMTP) | Adding an account, syncing, push, downloading a message or attachment, and sending. Up to three connections per account. For Proton Mail, that's Proton Mail Bridge on your Mac. |
| Microsoft sign-in | Only for Outlook and Microsoft 365 accounts, when that sign-in is available: adding the account and refreshing its token. |
| A list's unsubscribe address | Only when you choose Unsubscribe. |
| An invitation's organiser, by email | Only when you answer Accept, Maybe or Decline. |
| Remote images in a message | Only after you choose to load them. |
| The sender's domain, for its logo | Only with Show company logos on (off by default), once per domain, cached for 30 days. Never for personal domains like gmail.com, and never through a third-party icon service. |
| Dodo Payments or Gumroad | Activating a licence key, and checking it every 14 days while online. Sends the key and, for Dodo, an activation id and the Mac's model with a random tag. Never your computer's name, and nothing about your mail. |
| localinbox.app update feed | Once a day with automatic checks on, or when you choose Check for Updates. A plain download with no cookies or identifiers. Updates are verified against LocalInbox's signing key before installing. |
Data handling for purchases, support and this website is in the privacy policy.
Questions
Does LocalInbox collect analytics?
No. There is no analytics, telemetry or crash reporting in the app, and the website sets no cookies.
Can LocalInbox's developer read my email?
No. Your mail never passes through anything LocalInbox runs. It goes between your Mac and your mail provider only.
Why isn't LocalInbox notarized by Apple?
Notarization needs an Apple Developer account, which LocalInbox doesn't have yet. Until then, macOS asks you to approve the app once. Updates are signed with LocalInbox's own release key, and the app checks that signature before installing anything.
Where can I report a security issue?
Write to support@localinbox.app. We reply within two business days.