Mailbox health
Connect and scan a mailbox to calculate its health.
SenseInbox 1.1 Alpha 2 development access
Use a local development identity to test the product. Production authentication is deliberately disabled until a real identity provider is wired.
Sign in or create an account to get started.
Inbox intelligence
Start safely
We request read-only scan access first. Initial connection is read-only. Cleanup permission is requested separately and every mutation requires human approval + live preflight.
RC17 founding release
Production admission is controlled. If public GA is not open yet, claim your private founding invite before connecting a mailbox.
Mailbox health
Connect and scan a mailbox to calculate its health.
Potential cleanup
—Messages identified as safe review candidates. Nothing is executed automatically.
What is in your inbox
Highest volume
Decide once at sender level instead of reviewing thousands of individual messages.
Low confidence and high-value categories stay protected by default.
Preview only
Review recommendations, save decisions, then build a live preflight batch. Execution is always a separate explicit action and can be undone.
Detected from standards-based mail headers. SenseInbox 1.0 RC can execute only explicitly approved RFC 8058 one-click HTTPS requests after re-reading and validating the original message headers.
Subscription control
Header-level actions
Audit trail
Search receipts, invoices, orders, and recurring-payment signals extracted from mailbox metadata and message previews.
Searchable history
Recurring intelligence
Every batch moves through preflight, explicit approval, execution, ledger, and undo. Permanent delete is not implemented.
Audit trail
Turn repeated cleanup decisions into explicit policies. Simulate first, then choose report-only, preflight-only, or reversible execution.
New policy
Learning layer
Learns only from your explicit Protect/Cleanup decisions. It never overrides protected mail.
Policies
Audit trail
Explainable mailbox understanding built from semantic signals, thread depth, relationships, retention reasoning, and your explicit decisions. Recommendations are advisory only.
Learning refresh
Refresh recomputes relationship profiles, thread importance, repetitive groups, and policy recommendations from the mailbox data already scanned.
Explainability
Learned suggestions
Clean up to ten years of one mailbox for a single $19 payment. No subscription is started. SenseInbox analyzes first, protects important mail, then uses the same review, live preflight, reversible execution, ledger, and undo controls as the rest of the product.
One-time product
$191 mailbox · up to 10 years of indexed history · one rescue entitlement.
Safety promise
Payment unlocks the rescue workflow, not blind deletion. Permanent delete does not exist. Cleanup execution remains reversible and requires review/preflight.
Rescue workflow
Purchase the one-time Rescue or refresh an existing entitlement.
Choose ongoing SenseInbox protection separately from the one-time Inbox Rescue.
Payment history
Choose billing routes and prepare alternate payment providers without storing provider secrets in D1.
Payment routing
Subscription catalog
Operations
Incident center
Deployment control
Pilot is the default RC16 release mode. Maintenance blocks user write operations but keeps billing webhooks and status endpoints available.
Staging certification
RC16 verifies the deployed staging domain, D1 migration ledger, security headers, OAuth/encryption prerequisites, billing routes, a real deployment-queue round trip, Cloudflare resource presence, OAuth callback construction, unsigned billing-webhook rejection, and the deployed Worker/source/environment provenance. After that infrastructure proof passes, run the live Gmail/payment pilot below. Production promotion requires the signed RC16 proof for the exact ZIP, Worker version, live evidence, and passed pilot.
Live staging pilot
Evidence-driven RC16 pilot. Select a connected Gmail staging mailbox, then prove initial scan, incremental sync, intelligence safety, explicit organize permission, a small reversible execution and complete undo, $19 test Rescue entitlement, disconnect/reconnect, privacy export and support snapshot. RFC 8058 unsubscribe is tested when the mailbox contains an eligible one-click candidate.
RC16 production pilot
Bind the exact deployed Worker, signed staging provenance, passed production Gmail certification, verified D1 backup, health verification, a real 1–20 item reversible production workflow with full undo, commercial entitlement, and zero unresolved critical incidents before deployed-fixed finalization.
1.1 alpha Microsoft gate
Keep Outlook/Microsoft 365 public admission closed until the exact deployed alpha artifact proves Microsoft Graph scan + delta sync, protected-mail invariants, delegated Mail.ReadWrite, a 1–20 item reversible move/archive/trash batch with complete undo, reconnect recovery, privacy export, support evidence and zero unresolved critical incidents.
1.1 Alpha 9 connector gate
Certify a dedicated staging user against the exact Alpha 9 Worker. A passed run can issue a short-lived signed Ed25519 connector attestation for production promotion.
1.1 Alpha 9 production connector gate
Production MCP/AI stays closed until a signed Alpha 9 staging connector attestation is verified. Admit only explicit canary users, observe real MCP/AI activity, and automatically close on provenance drift, privacy violations, provider failures, or critical incidents.
1.1 Alpha 9 controlled expansion
Expand only after a passed production canary. Limited users remain explicitly enrolled and are protected by atomic daily MCP/AI call quotas, AI payload-byte caps, error-rate containment and evidence-driven observation.
1.1 Alpha 9 connector GA
Public MCP/AI admission remains closed until the exact Alpha 9 promotion has a passed limited-rollout observation, enough distinct real users and connector activity, MCP/AI success and p95 latency SLOs, zero privacy violations, zero unresolved critical incidents, and explicit operator sign-off. Limited-rollout quotas remain active after public open.
1.1 Beta 2 release gate
Freeze the exact Beta 2 production artifact, bind the passed Beta 1 field evidence, then prove provider parity, portfolio regression, billing/Google readiness, recovery/support and optional connector readiness before authorizing RC1.
1.1 Beta 1 field validation
Observe real Beta 1 users across Gmail, Microsoft, sync, reversible execution/undo, portfolio, billing and feedback before authorizing Beta 2.
1.1 Alpha 9 release gate
Qualify the exact deployed-fixed Alpha 9 artifact for the 1.1 beta branch. Gmail production certification, Microsoft parity, real multi-mailbox portfolio evidence, billing/Google readiness, resilience/support proof and zero critical incidents are mandatory. MCP/AI connector GA + account governance are required only when optional connectors are enabled.
RC20 stable release
Freeze the exact RC20 artifact only after current GA and resilience proof. Stable eligibility additionally requires an elapsed GA-open observation window, enough real SLO samples, current migration ledger, live billing/Google gates, recent support evidence and zero unresolved critical incidents.
RC20 resilience
Certify the exact RC20 production baseline with a real verified backup, controlled restore rehearsal, measured RTO/RPO, rollback, queue recovery, OAuth continuity, billing reconciliation, undo continuity, privacy export and incident-response evidence.
RC20 general availability
Public admission stays closed until the exact RC20 deployed-fixed baseline, normal rollout, founding graduates, production Gmail/Google gates, live billing routes and SLO evidence pass. Open GA additionally requires a passed public canary.
RC20 founding release
Issue single-use invite codes, review active founding access, and graduate only journeys backed by real scan, intelligence, reversible cleanup + undo, commercial and support evidence.
RC16 controlled rollout
Enroll only approved mailboxes, keep execution/unsubscribe/automation/billing behind policy and kill switches, record observation samples, automatically contain critical safety breaches, and widen pilot → limited → expanded → normal only from passed evidence.
Release operations
Production release stays blocked until required configuration and external Google verification are complete. A certification run records the real Gmail connect → scan → sync → reversible cleanup → undo → unsubscribe → billing → privacy path.
Credential policy
API keys, seller keys and webhook secrets must be installed as Cloudflare Worker secrets. Admin Settings stores only enablement, routing, test/live mode and non-secret provider identifiers.
See all connected mailboxes as one operating picture without creating cross-mailbox mutation authority.
Account map
Cross-mailbox signal
Plan-aware review
Allocates already-approved reversible candidates against your remaining monthly action allowance. It never creates or executes a mailbox batch.
Evidence
Connect SenseInbox to AI clients only when you choose. MCP is scope-limited and exposes no mailbox mutation tools. External AI receives privacy-reduced derived counts only.
Alpha 9 account governance
Tighten connector access for your account. These limits sit inside the platform daily quotas and can never expand mailbox or AI authority.
Model Context Protocol
Create revocable personal MCP tokens. Available tools are limited to portfolio/mailbox reading, planning evidence, and optional AI advice. There is no execution, unsubscribe, permanent-delete or automation-mutation MCP tool.
Bring your own model
Supported adapters: Cloudflare Workers AI, OpenAI Responses API, Anthropic Messages API, and Gemini Interactions API. API keys are AES-GCM encrypted with the Worker token-encryption key and are never returned after save.
Each account starts read-only. Organize permission is an explicit upgrade required only when you choose to execute a reviewed cleanup batch.
Disconnect mailboxes, recover expired authorization, export SenseInbox-derived data, or permanently remove your SenseInbox account data.
Data portability
Creates a 24-hour paged JSON export of SenseInbox metadata, classifications, intelligence, rules, decisions and receipt-vault metadata. Full message bodies and provider credentials are excluded.
Danger zone
Deletes mailbox-derived/user-profile data from SenseInbox. Billing records are pseudonymized for accounting/audit retention. Active subscriptions must be cancelled first.
Authorization recovery