Skip to content
corresync
Home Getting started Providers Features Safety
EN日本語简中繁中한국어

Privacy Policy

Your correspondence stays under your control.

Corresync is a local-first open-source application. It connects your device directly to providers you authorize; the Corresync project does not operate a hosted mailbox, calendar, token relay, analytics service, or remote MCP server. Its optional website checker receives only a domain and reads public DNS—never your full address or account.

Effective and last updated: 11 August 2026

Scope Provider data Route details Local storage Sharing Website checker Your choices Contact

At a glance

No Corresync cloud holds your mailbox.

  • Authentication stays with the provider route you explicitly select.
  • OAuth grants and standards credentials stay behind local protected storage.
  • Mail and calendar requests go directly from your device to the provider over TLS.
  • No advertising, sale of data, analytics, or general-purpose model training.

01 · Scope and identity

What this policy covers

This Privacy Policy explains how Naoki Kiyohara, maintainer of the Corresync open-source project, and project contributors (“Corresync”, “we”, or “the project”) handle information in the official Corresync application, its project-operated OAuth identities, and this website. It covers every available or staged route: Google, Outlook Web, Microsoft Graph, JMAP, IMAP/SMTP, CalDAV, and approved local imports. It does not govern independent forks, third-party builds, your email or calendar provider, operating system, package manager, MCP client, AI provider, or optional runner; those parties apply their own terms and privacy policies.

Corresync has no user-account database. You install and run it on a device you control. Provider account data is processed locally at your direction to provide the mail and calendar features you invoke.

02 · Provider account data and Google scopes

What Corresync can access and why

Depending on the mail and calendar routes you enable, Corresync can process account identity, folder and calendar metadata, messages, attachments, drafts, sent mail, events, attendees, recurrence, reminders, conferencing properties, and provider capabilities needed for the operation you request. It does not combine provider identities or enable a route you did not select.

Google and Microsoft Graph permissions are derived from the enabled services and shown in the provider consent screen before a grant is issued. Outlook Web remains browser-owned. Standards routes use only the explicitly configured account and endpoint credentials.

Gmail, Google Calendar, and Google Tasks use a Desktop OAuth client in a Google Cloud project you control. Guided setup validates the downloaded client, stores its generated credential in the OS keyring, and records only opaque references in configuration. Corresync-managed Google OAuth remains disabled. The practices below apply when you explicitly configure and sign in to your own client.

Google scope Data accessed Purpose and actions
https://www.googleapis.com/auth/gmail.modify Gmail folders and labels; message identifiers, headers, participants, subjects, timestamps, bodies, attachments, state, drafts, and sent mail. Search, list, read, download an attachment you request, draft, send, mark read or unread, apply labels, move, and organize mail through the Gmail API. Corresync does not request permanent-delete authority and does not expose permanent message deletion; its destructive operation moves mail to Trash.
https://www.googleapis.com/auth/calendar.calendarlist.readonly The names, identifiers, access roles, and metadata of calendars in your calendar list. Show and select the calendars already available to your Google account.
https://www.googleapis.com/auth/calendar.events Event identifiers, titles, descriptions, locations, times, attendees, recurrence, reminders, status, and conferencing properties. List, read, create, update, and cancel events you select, including requesting a Google Meet link as a property of an event when Google supports it.
https://www.googleapis.com/auth/tasks.readonly
or https://www.googleapis.com/auth/tasks
Task-list names and identifiers; task titles, notes, status, date-only due values, completion, hierarchy, ordering, assignment metadata, and source links. The read-only route lists and reads tasks. The writable route can create, update, complete, reopen, move, and delete tasks after Corresync preview and approval. Assigned-task restrictions are enforced before a write.

Corresync uses Google data only to provide the user-facing mail, calendar, task, monitoring, and automation features that you explicitly invoke or configure. It does not access Google Contacts, Drive, advertising profiles, passwords, browser cookies, or undocumented Google APIs.

03 · Other providers and local imports

Route-specific access, the same local boundary

These routes process only the data required for the capabilities you select and the operations you invoke:

Route Authentication and data Purpose and actions
Outlook Web A dedicated local browser profile retains Microsoft sign-in and site data. Corresync reads the visible mailbox and calendar data needed for the selected account. Search, read, compose, send, organize, and perform separately approved destructive mail actions; list, read, create, update, and cancel supported calendar events.
Microsoft Graph Delegated OAuth scopes offline_access and User.Read, plus Mail.ReadWrite and Mail.Send for mail, Calendars.ReadWrite for calendar, or Tasks.Read/Tasks.ReadWrite for Microsoft To Do, only when that service is enabled. Confirm the signed-in account; read and organize mail, drafts, attachments, and sent messages; send mail; and list, read, create, update, or cancel selected events, including supported Teams meeting properties; or list, read, and perform reviewed writes and delta sync for Microsoft To Do.
JMAP The configured JMAP session, account capabilities, mailbox and message objects, bodies, attachments, drafts, and submission state. Search, read, draft, submit when advertised, change state, move, and perform separately approved deletion through the selected JMAP account.
IMAP/SMTP The configured IMAP mailbox and SMTP submission endpoints, folders, MIME message data, attachments, drafts, flags, and delivery outcomes. Search, read, draft, send, mark, move, and organize mail where the server advertises the required safety capabilities.
Todoist A separately selected public OAuth client requests data:read, or data:read_write and data:delete. Corresync processes the task projects, content, scheduling, metadata, plan limits, and sync state needed for your request. List and read tasks, or perform previewed task writes, state changes, and bounded synchronization when the signed-in account exposes them.
TickTick A separately selected confidential OAuth client requests tasks:read or tasks:write. Its client secret remains behind an approved external credential handle; Corresync processes task projects, content, dates, recurrence, checklists, labels, assignment, and bounded polling state. List, search, and read tasks, or perform previewed create, update, complete, and delete operations. Unsupported reopen and reminder changes stay unavailable.
CalDAV The configured CalDAV calendar and VTODO collections, events, tasks, attendees, recurrence, reminders, ETags, and scheduling capabilities. Discover calendars and task lists; read events and tasks; and perform conditional, previewed writes only where the selected collection supports them.
Local import Only the archive, Maildir tree, Thunderbird profile, or supported export you explicitly select after a read preview. Create bounded, account-local staging for review. Imports do not authenticate, upload, send, alter, or delete the source.

Microsoft Graph grants stay in the OS keyring. Standards-provider passwords or tokens remain behind an OS-keyring reference or a credential helper that you explicitly approve; helper output is used transiently and is not copied into configuration. Outlook Web sign-in and site data remain in a dedicated local browser profile.

Across all routes, provider data travels between your device and the selected provider. The Corresync project does not receive it.

04 · How processing works

Direct connections, explicit actions

After you explicitly configure a user-owned Desktop client, the Google route opens Google’s authorization page in your system browser using OAuth 2.0 with PKCE and a loopback redirect, then connect directly from your device to Google’s fixed Gmail, Calendar, and Tasks API endpoints over TLS. The project does not receive your password, OAuth grant, email, attachment, or calendar content.

Microsoft Graph uses the same local public-client OAuth pattern against Microsoft’s authorization and Graph endpoints. Outlook Web keeps provider authentication and site data in its visible, dedicated local profile. JMAP, IMAP/SMTP, and CalDAV connect from your device to the explicit TLS endpoints you configure or select from credential-free discovery evidence.

CLI and MCP requests enter the same typed application operations. Reads are metadata-first where possible. A consequential write—such as sending mail or inviting attendees—presents an exact preview and requires a separate, short-lived approval bound to the selected account and payload. Corresync does not silently fall back to another provider route.

05 · Local storage and retention

What remains on your device

  • OAuth grant: access tokens and, where the provider issues one, refresh tokens are stored under an opaque account-specific handle in your operating system keyring, not in Corresync configuration.
  • Browser-owned session: a web route can retain cookies, session material, and provider site data inside a dedicated, account-local browser profile. Those values are not copied into Corresync configuration, audit, feedback, or MCP output.
  • Standards credential: a JMAP, IMAP/SMTP, or CalDAV password or token remains in your OS keyring or approved helper. Configuration retains only the external reference.
  • Configuration: your account address, local alias, enabled routes, OAuth client identifier, loopback redirect, and consented credential handles. It cannot contain a client secret or token.
  • TickTick client credential: the client secret is resolved from your approved OS credential store or helper only when login requires a new authorization code exchange. Reusing a valid grant does not open that secret store. Mutable owner buffers are overwritten after the exchange, and the value is not stored in configuration, the OAuth grant, audit, feedback, MCP output, or browser URLs.
  • Google Desktop client credential: when Google requires this value at token exchange, it is supplied only through the local Corresync process environment. It is not stored in configuration, the OAuth grant, audit, feedback, MCP output, or browser URLs.
  • Content-free audit: bounded operation type, outcome, time, caller, opaque account and target/provider identifiers, and policy context. Audit records exclude addresses, recipients, subjects, bodies, attachment names, event text, queries, credential references, tokens, and approval values.
  • Optional monitoring: only after you enable durable queueing, account/event identifiers and selected fields such as sender, subject, received time, importance, and attachment presence may be stored locally. Message bodies and attachments are not placed in that queue.
  • Optional import staging: after explicit read approval, a bounded account-local record can retain metadata and content from the one local source you selected until you purge it or remove the account.
  • Transient data: requested mail and calendar values may exist in process memory and local stdio while an operation runs. Corresync does not maintain a general persistent copy of any connected mailbox or calendar.

Local records remain until you remove the account, purge the applicable queue or staging area, or delete the protected Corresync data yourself. Content-free security audit records remain until you delete the local audit file. Mail and calendar data remains at the selected provider according to that provider’s settings and your actions.

06 · Disclosure and transfers

Who can receive data

The Corresync project does not collect or share your provider account data because it has no service that receives it. On your device, data may be disclosed only as needed to:

  • Google or another provider you select, to authenticate and perform the provider operation you requested;
  • your chosen local CLI output or MCP client when you ask it to retrieve or act on data;
  • an AI service selected and configured by you if that MCP client sends tool results to a remote model, under that service’s own privacy terms; or
  • an optional no-shell monitor runner and destination that you separately enable, with a separate opt-in for remote egress.

Corresync does not sell provider account data, use it for advertising, provide it to data brokers, use it for credit or lending decisions, conduct surveillance, or use it to train general-purpose AI or machine-learning models. Project maintainers do not read it. Do not send live mailbox, calendar, token, or account data in public issues or support reports.

07 · Google Limited Use

A purpose-bound commitment

Corresync’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Access is limited to providing or improving the prominent user-facing features described in this Policy. Corresync does not permit human reading of Google user data except with the user’s affirmative agreement for a specific item, when necessary for security investigation, to comply with applicable law, or when data has been aggregated and anonymized for internal operation; the official local-first project does not ordinarily receive such data at all.

08 · Website, updates, and feedback

No default analytics or telemetry

This static website sets no Corresync cookies and loads no analytics, advertising, or third-party scripts. It is delivered by GitHub Pages, which logs visitor IP addresses for security and may process other ordinary request data under GitHub’s privacy statement.

The optional provider compatibility checker separates your address in your browser, immediately clears the address field, and sends only the normalized domain—the part after the @—in a JSON POST body to discover.corresync.org. It never sends or stores the part before the @, puts either value in the address bar, sets a cookie, uses browser storage, starts sign-in, or contacts your mail provider. You can skip the checker entirely and run local credential-free discovery after installation.

That endpoint is a single-purpose Cloudflare Worker. It asks Cloudflare’s fixed public DNS-over-HTTPS resolver for bounded MX, Autodiscover CNAME, and service records, then returns categories and possible Corresync routes rather than raw DNS records. It does not fetch a domain-supplied URL, retain an application record, use an application cache, or enable Workers logs or analytics. Responses are marked no-store. As the network operator, Cloudflare necessarily processes ordinary connection metadata such as an IP address under its privacy policy, even though Corresync does not inspect or use the address for its rate-limit key.

Eligible interactive CLI starts may ask GitHub’s public Releases API whether a newer Corresync release exists in the stable or user-selected preview channel. The request contains the current Corresync version in its user agent, not your account address, mailbox data, or a persistent device identifier. The result is cached locally by channel. Package-manager update paths are handled by their respective providers. If a standalone user explicitly enables automatic installation, Corresync also downloads the public release artifact, checksums, and provenance needed to verify and replace that executable; this never runs during an MCP tool call.

corr feedback creates an allowlisted, redacted report locally and never submits it automatically. You decide whether to copy, save, or open a prefilled GitHub page after reviewing every field.

Automatic error feedback is a separate choice that is off by default. If you explicitly enable feedback.auto_submit, an eligible failed interactive CLI command may use your authenticated external GitHub CLI to create a public Corresync issue. The submitted categories are limited to validated Corresync version/build and OS/CPU values, enumerated installation method, command and flag names without values, a content-free error fingerprint, and fixed error classes. The automatic schema has no field for raw errors, arguments or values, paths, configuration, provider or account data, credentials, authorization, mail, attachments, or calendar data. Corresync never reads or stores your GitHub token. MCP, machine-output, configuration-management, and non-interactive commands do not submit. A private local marker containing no issue content, identity, or time prevents another attempt for the same build/error fingerprint.

Enabling this choice is consent to disclose those listed categories together with your GitHub identity to GitHub and the public. The purpose is debugging, support, and improvement of Corresync preview releases. Disable it at any time with corr config set feedback.auto_submit false; withdrawal stops future attempts but cannot retract disclosure that already occurred. A submitted public issue and GitHub identity are public; a private advisory remains restricted to authorized repository participants. GitHub stores its records under its own privacy terms. The project retains public issues only as reasonably needed for support, security, legal, abuse-prevention, and project-history purposes. You can edit or close an issue through GitHub and may contact the maintainer to request removal where appropriate. Never add live provider account data or credentials to a public issue.

09 · Security

Controls and unavoidable risk

Corresync uses provider-pinned Google and Microsoft API endpoints, a fixed public DNS resolver for the optional domain-only website checker, explicit TLS endpoints for standards routes, visible browser-owned Outlook sessions, normal system-browser OAuth, PKCE and state validation, OS-keyring grant storage, account-isolated sessions, authenticated local IPC, MCP over stdio, bounded parsing, and preview-before-commit controls. No method of local storage or transmission is completely secure. Protect your device, keyring, MCP configuration, selected model, and backups, and install only releases whose provenance you trust.

Report a suspected vulnerability through GitHub private vulnerability reporting; never put secrets or private account data in a public report.

10 · Your choices and deletion

Disconnect and remove access at any time

  1. Skip the optional website checker whenever you prefer; it has no account, cookie, or application record to delete. Clearing or leaving the form ends its browser-only handling of the full address.
  2. Run corr account remove ALIAS --approve to remove that account’s Corresync configuration and account-local profile, import, cursor, and queue state. An unshared OAuth grant owned by Corresync is also removed from the OS keyring. This does not delete mail or calendar data held by the provider.
  3. Revoke provider-side authorization in the connected-app or security settings for that account. For Google, visit Google Account connections, select Corresync, and remove its access. For Microsoft Graph or another OAuth provider, use that provider’s application-consent controls.
  4. Use corr events purge --account ALIAS --approve for a retained local monitor queue, and delete any local audit or explicitly created import staging records you no longer want.
  5. Uninstall Corresync and delete its local configuration/data directories if you want to remove the application completely. Your provider retains its own data until you change or delete it there.

corr auth logout closes local sessions but intentionally preserves keyring grants for later sign-in. Use account removal and provider-side revocation when you want the authorization deleted.

Depending on where you live, applicable law may provide rights to access, correct, delete, restrict, object to, or obtain a copy of personal information. Corresync does not operate an account database or hold the provider data processed only on your device, so use the local and provider controls above for that data. Contact the project about information you deliberately submitted through a project channel.

11 · Children

Not directed to children

Corresync is a technical mail and calendar tool and is not directed to children under 13. The project does not knowingly operate a service that collects personal information from children.

12 · Changes

Material changes remain visible

We may update this Policy as Corresync changes. The effective date appears at the top, and material changes are published on this page and in project release notes. If a change would use provider account data for a new purpose, Corresync will provide notice and obtain consent before that new use. Earlier versions remain available in the public source history.

13 · Contact

Questions and concerns

For a policy question that contains no private data, open a Corresync GitHub issue. For a security or privacy concern that requires private details, use private vulnerability reporting. The project is maintained by Naoki Kiyohara and contributors. Because the project does not host user accounts, mailboxes, or calendars, maintainers cannot retrieve or delete data stored only on your device or at a provider.

corresync

Independent local-first mail and calendar tooling. Not affiliated with or endorsed by Google, Microsoft, or any provider or agent vendor named here.

Getting started Providers Features Safety Privacy Terms GitHub source Security Releases Apache-2.0