Privacy · September 11, 2026
Your mail, your context.
Boxie is an early personal-email experiment from DionLabs. This page describes the current design and its limits.
Accounts and email access
The browser inbox needs only Microsoft sign-in. Google sign-in identifies the owner of an optional cloud vault through Firebase Authentication; the current native apps use this cloud-vault flow. Microsoft sign-in authorizes read-only access to your personal Outlook mailbox, including received mail and Sent Items. Boxie starts processing from activation time; it does not automatically import every historical message. It does not send or delete Outlook mail.
What goes to the cloud
The default browser inbox stores encrypted mailbox records locally and does not upload them to Firebase Firestore. If you choose the separate cloud-vault setup, your device encrypts mailbox records before uploading them. Local inbox history and organization are not automatically migrated to a cloud vault. Decryption keys are held by your devices and transferred through an explicit device-pairing flow. The storage service receives encrypted records, account identifiers, device-registration information and operational metadata such as sizes, timestamps and sync activity. Encryption does not conceal all metadata.
Cloudflare serves the website and processes ordinary web-request metadata. Google/Firebase and Microsoft process sign-in and service requests under their own policies. This site does not add advertising trackers.
Feedback and optional diagnostics
Send private feedback or email support if sign-in fails. In-app feedback from an existing cloud account includes text, account identifier, app version, platform and timestamp readable by DionLabs for troubleshooting. Signed-out users can draft feedback and send it using their email app without Google sign-in; that email includes the sender address and normal email metadata. Do not include mail contents or credentials. Automatic browser diagnostics are off by default; you can enable or disable them on the feedback page. They contain only a fixed error category, version, platform and timestamp linked to your sign-in, never error text, stack traces, URLs or mailbox data. Reports are retained until Boxie account deletion or earlier manual removal. Deleting your Boxie cloud data also removes these reports. This is best-effort reporting, not guaranteed crash detection.
Android tester applications
The optional Android tester form collects a contact email, confirmation of the entry criteria, timestamps, consent version and review status for manual recruitment. These records are readable by DionLabs, stored separately from encrypted mailbox data in Cloudflare D1 in the EU, and expire after 30 days with daily cleanup. The private withdrawal link deletes the active record immediately; support can also process withdrawal. Recovery copies may persist for up to another 30 days. Temporary keyed network identifiers limit repeat submissions and expire after 24 hours, with daily cleanup. Applying creates no Boxie account, connects no mailbox and subscribes you to no marketing list. See the form for the full intake notice.
Optional AI
An assistant provider is configured by you. When you ask it to work with mail, relevant messages and context may be sent to that provider. Its privacy policy and pricing apply. Boxie does not silently choose a fallback provider. Reading mail does not require AI.
On your devices
Boxie keeps local mailbox data and credentials to support access and synchronization. Protect your devices and browser profiles. Clearing browser data removes a local inbox and its encryption key; it has no cloud backup unless you separately set up cloud storage. Android notifications can show message previews according to your system notification settings. Assistant chat history is currently local to each device.
Control and deletion
Boxie’s Junk, Trash and organization actions affect Boxie, not your source mailbox. Removing an app or signing out is not a promise that every cloud record has been deleted. Request deletion of your Boxie account and cloud data. Sign in with Google to confirm ownership; a paired device is not required. Submitting the signed-in request immediately blocks Boxie cloud access. DionLabs manually completes cloud deletion, normally within 7 days. Uninstall Boxie and clear its local data on every device; offline copies cannot be erased remotely. We retain your account identifier and request/completion timestamps indefinitely to prevent old devices from recreating deleted data; this record contains no mail contents or credentials. The shared Google/Firebase sign-in identity remains available to other DionLabs apps. You can revoke Microsoft and Google access from those accounts’ security settings.
For support, privacy questions or a deletion request, email support@dionlabs.ai. Include “Boxie” and a brief description of your request. Never send passwords, access tokens, or mailbox contents. If you cannot sign in, support can help verify ownership and process your deletion request.
Early-access status
Registration is open for experimental early access. New-user setup has not yet been independently verified with a second real account. Background updates may be delayed, and service quotas can temporarily pause synchronization. Boxie is not yet distributed through the Apple App Store.