SISenseInbox

Clean the noise. Keep what matters.

SenseInbox 1.1 Alpha 2 development access

Use a local development identity to test the product. Production authentication is deliberately disabled until a real identity provider is wired.

Sign in or create an account to get started.

● Mailbox changes require explicit approval, preflight, and remain reversible. Permanent delete does not exist.
SISenseInbox
Reversible modeNo permanent delete

Inbox intelligence

Overview

✦

Start safely

Connect your first mailbox

We request read-only scan access first. Initial connection is read-only. Cleanup permission is requested separately and every mutation requires human approval + live preflight.

RC17 founding release

Founding customer access

Production admission is controlled. If public GA is not open yet, claim your private founding invite before connecting a mailbox.

Scanning mailboxBuilding your mailbox map safely.

Mailbox health

—/100

Connect and scan a mailbox to calculate its health.

Potential cleanup

—

Messages identified as safe review candidates. Nothing is executed automatically.

Analyzed—messages
Protected—important items
Receipts & invoices—organized candidates
Known size—classified data

What is in your inbox

Categories

AI + rules

Highest volume

Top senders

Sender intelligence

Decide once at sender level instead of reviewing thousands of individual messages.

Protected mail

Low confidence and high-value categories stay protected by default.

Retention winswhen confidence is low

Preview only

Your cleanup plan

Review recommendations, save decisions, then build a live preflight batch. Execution is always a separate explicit action and can be undone.

Candidate messages—

By category

Human approved
Ready to preflight?Save Cleanup decisions first. We will verify every message against the live mailbox before anything changes.

Sender decisions

0 saved

Unsubscribe intelligence

Detected from standards-based mail headers. SenseInbox 1.0 RC can execute only explicitly approved RFC 8058 one-click HTTPS requests after re-reading and validating the original message headers.

Safe executionRFC 8058 only · no redirects

Subscription control

Subscription senders

Keep · Unsubscribe · Mute

Header-level actions

Unsubscribe candidates

0 detected

Audit trail

Unsubscribe executions

No silent actions

Receipt Vault

Search receipts, invoices, orders, and recurring-payment signals extracted from mailbox metadata and message previews.

Vault items—documents detected
Receipts—payment records
Invoices—invoice records
Recurring signals—possible subscriptions

Searchable history

Receipts & invoices

Recurring intelligence

Possible recurring charges

Review signal

Reversible execution

Every batch moves through preflight, explicit approval, execution, ledger, and undo. Permanent delete is not implemented.

Undo window7 days
Choose or create a cleanup batch to inspect it.

Audit trail

Cleanup batches

Smart cleanup automation

Turn repeated cleanup decisions into explicit policies. Simulate first, then choose report-only, preflight-only, or reversible execution.

Policy gatedNo permanent delete

New policy

Create automation rule

Simulate before execute

Learning layer

Sender reputation

Learns only from your explicit Protect/Cleanup decisions. It never overrides protected mail.

Policies

Automation rules

Audit trail

Automation runs

Scheduled + manual

AI Mail Intelligence 2.0

Explainable mailbox understanding built from semantic signals, thread depth, relationships, retention reasoning, and your explicit decisions. Recommendations are advisory only.

Derived signalsNo second body archive
Analyzed—messages with advanced signals
Important relationships—inferred from history + decisions
Repetitive groups—repeating mail patterns
Recommendations—advisory policy suggestions

Learning refresh

Inbox intelligence map

Refresh recomputes relationship profiles, thread importance, repetitive groups, and policy recommendations from the mailbox data already scanned.

Explainability

Why this mail matters

Highest importance

Learned suggestions

Policy recommendations

Never auto-executes

One-Time Inbox Rescue

Clean up to ten years of one mailbox for a single $19 payment. No subscription is started. SenseInbox analyzes first, protects important mail, then uses the same review, live preflight, reversible execution, ledger, and undo controls as the rest of the product.

$19 onceNo recurring renewal

One-time product

$19

1 mailbox · up to 10 years of indexed history · one rescue entitlement.

Safety promise

Understand before changing

Payment unlocks the rescue workflow, not blind deletion. Permanent delete does not exist. Cleanup execution remains reversible and requires review/preflight.

Analyzed—messages in rescue window
Cleanup candidates—review before action
Protected—retained by safety policy
Receipts—kept and organized

Rescue workflow

Check your entitlement

Not purchased

Purchase the one-time Rescue or refresh an existing entitlement.

Plans & billing

Choose ongoing SenseInbox protection separately from the one-time Inbox Rescue.

Clear billingTrials and recurring plans are explicit

Payment history

Invoices & status

Admin settings

Choose billing routes and prepare alternate payment providers without storing provider secrets in D1.

SecretsCloudflare only

Payment routing

Billing provider strategy

Provider neutral

Subscription catalog

Plan prices & trials

Admin configurable

Operations

Provider health & recent subscriptions

Incident center

OAuth, billing & reconciliation

Deployment control

Pilot, maintenance & promotion

Pilot is the default RC16 release mode. Maintenance blocks user write operations but keeps billing webhooks and status endpoints available.

First deployment operations

Staging certification

Deployment verification

RC16 verifies the deployed staging domain, D1 migration ledger, security headers, OAuth/encryption prerequisites, billing routes, a real deployment-queue round trip, Cloudflare resource presence, OAuth callback construction, unsigned billing-webhook rejection, and the deployed Worker/source/environment provenance. After that infrastructure proof passes, run the live Gmail/payment pilot below. Production promotion requires the signed RC16 proof for the exact ZIP, Worker version, live evidence, and passed pilot.

Live staging pilot

Gmail + billing pilot certification

Evidence-driven RC16 pilot. Select a connected Gmail staging mailbox, then prove initial scan, incremental sync, intelligence safety, explicit organize permission, a small reversible execution and complete undo, $19 test Rescue entitlement, disconnect/reconnect, privacy export and support snapshot. RFC 8058 unsubscribe is tested when the mailbox contains an eligible one-click candidate.

RC16 production pilot

First production customer certification

Bind the exact deployed Worker, signed staging provenance, passed production Gmail certification, verified D1 backup, health verification, a real 1–20 item reversible production workflow with full undo, commercial entitlement, and zero unresolved critical incidents before deployed-fixed finalization.

1.1 alpha Microsoft gate

Microsoft Production Certification

Keep Outlook/Microsoft 365 public admission closed until the exact deployed alpha artifact proves Microsoft Graph scan + delta sync, protected-mail invariants, delegated Mail.ReadWrite, a 1–20 item reversible move/archive/trash batch with complete undo, reconnect recovery, privacy export, support evidence and zero unresolved critical incidents.

1.1 Alpha 9 connector gate

MCP & AI Connector Staging Certification

Certify a dedicated staging user against the exact Alpha 9 Worker. A passed run can issue a short-lived signed Ed25519 connector attestation for production promotion.

1.1 Alpha 9 production connector gate

Connector Production Canary

Production MCP/AI stays closed until a signed Alpha 9 staging connector attestation is verified. Admit only explicit canary users, observe real MCP/AI activity, and automatically close on provenance drift, privacy violations, provider failures, or critical incidents.

1.1 Alpha 9 controlled expansion

Connector Limited Rollout & Quotas

Expand only after a passed production canary. Limited users remain explicitly enrolled and are protected by atomic daily MCP/AI call quotas, AI payload-byte caps, error-rate containment and evidence-driven observation.

1.1 Alpha 9 connector GA

Connector GA Readiness & Public Open

Public MCP/AI admission remains closed until the exact Alpha 9 promotion has a passed limited-rollout observation, enough distinct real users and connector activity, MCP/AI success and p95 latency SLOs, zero privacy violations, zero unresolved critical incidents, and explicit operator sign-off. Limited-rollout quotas remain active after public open.

1.1 Beta 2 release gate

Release Candidate Readiness

Freeze the exact Beta 2 production artifact, bind the passed Beta 1 field evidence, then prove provider parity, portfolio regression, billing/Google readiness, recovery/support and optional connector readiness before authorizing RC1.

1.1 Beta 1 field validation

External Beta Cohort

Observe real Beta 1 users across Gmail, Microsoft, sync, reversible execution/undo, portfolio, billing and feedback before authorizing Beta 2.

1.1 Alpha 9 release gate

Unified Beta Readiness

Qualify the exact deployed-fixed Alpha 9 artifact for the 1.1 beta branch. Gmail production certification, Microsoft parity, real multi-mailbox portfolio evidence, billing/Google readiness, resilience/support proof and zero critical incidents are mandatory. MCP/AI connector GA + account governance are required only when optional connectors are enabled.

RC20 stable release

1.0 Release Freeze & Launch Handoff

Freeze the exact RC20 artifact only after current GA and resilience proof. Stable eligibility additionally requires an elapsed GA-open observation window, enough real SLO samples, current migration ledger, live billing/Google gates, recent support evidence and zero unresolved critical incidents.

RC20 resilience

Backup, Restore & Disaster Recovery

Certify the exact RC20 production baseline with a real verified backup, controlled restore rehearsal, measured RTO/RPO, rollback, queue recovery, OAuth continuity, billing reconciliation, undo continuity, privacy export and incident-response evidence.

RC20 general availability

GA Certification & Public Canary

Public admission stays closed until the exact RC20 deployed-fixed baseline, normal rollout, founding graduates, production Gmail/Google gates, live billing routes and SLO evidence pass. Open GA additionally requires a passed public canary.

RC20 founding release

Founding Customer Program

Issue single-use invite codes, review active founding access, and graduate only journeys backed by real scan, intelligence, reversible cleanup + undo, commercial and support evidence.

RC16 controlled rollout

Production Safety Observatory

Enroll only approved mailboxes, keep execution/unsubscribe/automation/billing behind policy and kill switches, record observation samples, automatically contain critical safety breaches, and widen pilot → limited → expanded → normal only from passed evidence.

Release operations

Launch readiness & Gmail certification

Production release stays blocked until required configuration and external Google verification are complete. A certification run records the real Gmail connect → scan → sync → reversible cleanup → undo → unsubscribe → billing → privacy path.

Credential policy

Secrets are never saved here

API keys, seller keys and webhook secrets must be installed as Cloudflare Worker secrets. Admin Settings stores only enablement, routing, test/live mode and non-secret provider identifiers.

Mailbox portfolio

See all connected mailboxes as one operating picture without creating cross-mailbox mutation authority.

Planning onlyExecute per mailbox with review + preflight + undo
Plan—mailbox capacity
Analyzed—across active mailboxes
Protected—retained by safety rules
Approved cleanup—planning candidates only

Account map

Mailbox health & capacity

Cross-mailbox signal

Overlapping senders

Read-only insight

Plan-aware review

Portfolio review plan

Allocates already-approved reversible candidates against your remaining monthly action allowance. It never creates or executes a mailbox batch.

Evidence

Snapshots & review-plan history

Optional MCP & AI connectors

Connect SenseInbox to AI clients only when you choose. MCP is scope-limited and exposes no mailbox mutation tools. External AI receives privacy-reduced derived counts only.

Off by defaultBYOK · encrypted · advisory only

Alpha 9 account governance

Connector policy & monthly budgets

derived-only enforced

Tighten connector access for your account. These limits sit inside the platform daily quotas and can never expand mailbox or AI authority.

Model Context Protocol

MCP access

checking

Create revocable personal MCP tokens. Available tools are limited to portfolio/mailbox reading, planning evidence, and optional AI advice. There is no execution, unsubscribe, permanent-delete or automation-mutation MCP tool.

Bring your own model

AI connector

checking

Supported adapters: Cloudflare Workers AI, OpenAI Responses API, Anthropic Messages API, and Gemini Interactions API. API keys are AES-GCM encrypted with the Worker token-encryption key and are never returned after save.

Connected mailboxes

Each account starts read-only. Organize permission is an explicit upgrade required only when you choose to execute a reviewed cleanup batch.

Privacy & account operations

Disconnect mailboxes, recover expired authorization, export SenseInbox-derived data, or permanently remove your SenseInbox account data.

Mailbox-safeDisconnect never deletes provider mail

Data portability

Export derived data

No OAuth tokens

Creates a 24-hour paged JSON export of SenseInbox metadata, classifications, intelligence, rules, decisions and receipt-vault metadata. Full message bodies and provider credentials are excluded.

Danger zone

Delete SenseInbox account

Deletes mailbox-derived/user-profile data from SenseInbox. Billing records are pseudonymized for accounting/audit retention. Active subscriptions must be cancelled first.

Authorization recovery

Connected mailbox status