Skip to content

What leaves your device

Primail is network-connected. The destinations below are the ones the current client actually uses. This is not a guarantee that nothing else will ever appear, and it is not “exactly three hosts.”

New fetch and send talk directly to your IMAP (port 993) and SMTP (port 465) servers with implicit TLS. Plaintext and STARTTLS are not supported. Connections carry headers, bodies, attachments, flags, and the credentials needed to authenticate.

Cached reading, local search, and local drafts do not need a Primail cloud account. See System requirements.

sync_run / the in-app refresh are this same IMAP path, not a Primail configuration-sync service.

Settings → Privacy → Remote images keeps three separate current controls. None of them is a conversation-wide grant.

  • Load remote images automatically defaults to off and keeps the saved value. When off, remote <img> URLs are stripped before the body frame.
  • Show images on that message’s blocked-images banner unlocks this message only for the current session. The message id is held in memory and is not saved.
  • Always from a sender stores that address in this app profile’s localStorage. That trust persists until you Revoke or Clear all under Settings → Privacy. It is not a temporary grant.

Unlocking one message does not unlock the rest of the thread. There is no current verified-conversation image permission.

When images load, the request goes to whatever host is in the message — often the sender or a tracker.

Settings → Privacy → Load avatars from the network defaults to on (saved value is preserved). Candidates are Gravatar (www.gravatar.com/avatar/… from an email hash) and, for organization domains, Clearbit (logo.clearbit.com/…). Turn the control off to keep initials-only avatars.

Signing in with Google or Microsoft contacts that provider’s authorization and token endpoints. That is not IMAP, and it is not a Primail host.

If GEMINI_API_KEY is configured, MCP/CLI ai_* tools send message text to Gemini. The consumer GUI has no bundled AI control. Your MCP client may also send tool results to its own model provider.

  • sync.primail.app as a live preferences/pin/credential host
  • updates.primail.app as a fixed daily version-check host
  • A background Primail Cloud sync
  • An absolute TLS 1.3-only claim beyond “implicit TLS on 993/465”

Settings → Support → Updates can expose an auto-update preference; that is not documented here as a public CDN hostname.

Experimental primail-sync source is not a user-facing cloud you are signed into.

On this device, unless you opted into a network control above:

  • The SQLite cache and Tantivy index
  • Local drafts and the schedule/outbox tables
  • The daily primail.log.* activity file
  • Mail passwords in Keychain (used by local Primail processes)

See Credentials & Keychain and Mail and configuration sync.