01 · Scope and identity
What this policy covers
This Privacy Policy explains how Naoki Kiyohara, maintainer of the Corresync open-source project, and project contributors (“Corresync”, “we”, or “the project”) handle information in the official Corresync application, its project-operated OAuth identities, and this website. It covers every supported route: Google, Outlook Web, Microsoft Graph, JMAP, IMAP/SMTP, CalDAV, and approved local imports. It does not govern independent forks, third-party builds, your email or calendar provider, operating system, package manager, MCP client, AI provider, or optional runner; those parties apply their own terms and privacy policies.
Corresync has no user-account database. You install and run it on a device you control. Provider account data is processed locally at your direction to provide the mail and calendar features you invoke.
02 · Provider account data and Google scopes
What Corresync can access and why
Depending on the mail and calendar routes you enable, Corresync can process account identity, folder and calendar metadata, messages, attachments, drafts, sent mail, events, attendees, recurrence, reminders, conferencing properties, and provider capabilities needed for the operation you request. It does not combine provider identities or enable a route you did not select.
Google and Microsoft Graph permissions are derived from the enabled services and shown in the provider consent screen before a grant is issued. Outlook Web remains browser-owned. Standards routes use only the explicitly configured account and endpoint credentials.
Guided connection through the project’s official Google OAuth application is not generally available while that application is prepared and verified. The practices below apply both to that official application when available and to the same local Google route when you explicitly configure a public client you are authorized to use.
| Google scope | Data accessed | Purpose and actions |
|---|---|---|
https://mail.google.com/ |
Gmail folders and labels; message identifiers, headers, participants, subjects, timestamps, bodies, attachments, state, drafts, and sent mail. | Search, list, read, download an attachment you request, draft, send, mark read or unread, and move or organize mail. Gmail IMAP/SMTP XOAUTH2 requires this broad scope. Corresync’s Google route does not expose permanent message deletion even though the scope itself is capable of broader mailbox access. |
https://www.googleapis.com/auth/calendar.calendarlist.readonly
|
The names, identifiers, access roles, and metadata of calendars in your calendar list. | Show and select the calendars already available to your Google account. |
https://www.googleapis.com/auth/calendar.events |
Event identifiers, titles, descriptions, locations, times, attendees, recurrence, reminders, status, and conferencing properties. | List, read, create, update, and cancel events you select, including requesting a Google Meet link as a property of an event when Google supports it. |
Corresync uses Google data only to provide the user-facing mail, calendar, monitoring, and automation features that you explicitly invoke or configure. It does not access Google Contacts, Drive, advertising profiles, passwords, browser cookies, or undocumented Google APIs.
03 · Other providers and local imports
Route-specific access, the same local boundary
These routes process only the data required for the capabilities you select and the operations you invoke:
| Route | Authentication and data | Purpose and actions |
|---|---|---|
| Outlook Web | A dedicated local browser profile retains Microsoft sign-in and site data. Corresync reads the visible mailbox and calendar data needed for the selected account. | Search, read, compose, send, organize, and perform separately approved destructive mail actions; list, read, create, update, and cancel supported calendar events. |
| Microsoft Graph |
Delegated OAuth scopes offline_access and
User.Read, plus Mail.ReadWrite and
Mail.Send for mail or Calendars.ReadWrite for
calendar, only when that service is enabled.
|
Confirm the signed-in account; read and organize mail, drafts, attachments, and sent messages; send mail; and list, read, create, update, or cancel selected events, including supported Teams meeting properties. |
| JMAP | The configured JMAP session, account capabilities, mailbox and message objects, bodies, attachments, drafts, and submission state. | Search, read, draft, submit when advertised, change state, move, and perform separately approved deletion through the selected JMAP account. |
| IMAP/SMTP | The configured IMAP mailbox and SMTP submission endpoints, folders, MIME message data, attachments, drafts, flags, and delivery outcomes. | Search, read, draft, send, mark, move, and organize mail where the server advertises the required safety capabilities. |
| CalDAV | The configured CalDAV collections, calendar metadata, events, attendees, recurrence, reminders, ETags, and scheduling capabilities. | Discover and select calendars, list and read events, and create, update, or cancel events with conditional writes and scheduling only when supported. |
| Local import | Only the archive, Maildir tree, Thunderbird profile, or supported export you explicitly select after a read preview. | Create bounded, account-local staging for review. Imports do not authenticate, upload, send, alter, or delete the source. |
Microsoft Graph grants stay in the OS keyring. Standards-provider passwords or tokens remain behind an OS-keyring reference or a credential helper that you explicitly approve; helper output is used transiently and is not copied into configuration. Outlook Web sign-in and site data remain in a dedicated local browser profile.
Across all routes, provider data travels between your device and the selected provider. The Corresync project does not receive it.
04 · How processing works
Direct connections, explicit actions
The official Google route opens Google’s authorization page in your system browser using OAuth 2.0 with PKCE and a loopback redirect. Corresync then connects directly from your device to Google’s fixed Gmail IMAP, Gmail SMTP, and Calendar API endpoints over TLS. The project does not receive your password, OAuth grant, email, attachment, or calendar content.
Microsoft Graph uses the same local public-client OAuth pattern against Microsoft’s authorization and Graph endpoints. Outlook Web keeps provider authentication and site data in its visible, dedicated local profile. JMAP, IMAP/SMTP, and CalDAV connect from your device to the explicit TLS endpoints you configure or select from credential-free discovery evidence.
CLI and MCP requests enter the same typed application operations. Reads are metadata-first where possible. A consequential write—such as sending mail or inviting attendees—presents an exact preview and requires a separate, short-lived approval bound to the selected account and payload. Corresync does not silently fall back to another provider route.
05 · Local storage and retention
What remains on your device
- OAuth grant: access and refresh tokens are stored under an opaque account-specific handle in your operating system keyring, not in Corresync configuration.
- Browser-owned session: a web route can retain cookies, session material, and provider site data inside a dedicated, account-local browser profile. Those values are not copied into Corresync configuration, audit, feedback, or MCP output.
- Standards credential: a JMAP, IMAP/SMTP, or CalDAV password or token remains in your OS keyring or approved helper. Configuration retains only the external reference.
- Configuration: your account address, local alias, enabled routes, public OAuth client identifier, loopback redirect, and keyring handle.
- Content-free audit: bounded operation type, outcome, time, caller, opaque account and target/provider identifiers, and policy context. Audit records exclude addresses, recipients, subjects, bodies, attachment names, event text, queries, credential references, tokens, and approval values.
- Optional monitoring: only after you enable durable queueing, account/event identifiers and selected fields such as sender, subject, received time, importance, and attachment presence may be stored locally. Message bodies and attachments are not placed in that queue.
- Optional import staging: after explicit read approval, a bounded account-local record can retain metadata and content from the one local source you selected until you purge it or remove the account.
- Transient data: requested mail and calendar values may exist in process memory and local stdio while an operation runs. Corresync does not maintain a general persistent copy of any connected mailbox or calendar.
Local records remain until you remove the account, purge the applicable queue or staging area, or delete the protected Corresync data yourself. Content-free security audit records remain until you delete the local audit file. Mail and calendar data remains at the selected provider according to that provider’s settings and your actions.
07 · Google Limited Use
A purpose-bound commitment
Corresync’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Access is limited to providing or improving the prominent user-facing features described in this Policy. Corresync does not permit human reading of Google user data except with the user’s affirmative agreement for a specific item, when necessary for security investigation, to comply with applicable law, or when data has been aggregated and anonymized for internal operation; the official local-first project does not ordinarily receive such data at all.
08 · Website, updates, and feedback
No project analytics or telemetry
This static website sets no Corresync cookies and loads no analytics, advertising, or third-party scripts. It is delivered by GitHub Pages, which logs visitor IP addresses for security and may process other ordinary request data under GitHub’s privacy statement.
Eligible interactive CLI starts may ask GitHub’s public Releases API whether a newer stable Corresync release exists. The request contains the current Corresync version in its user agent, not your account address, mailbox data, or a persistent device identifier. The result is cached locally. Package-manager update paths are handled by their respective providers. If a standalone user explicitly enables automatic installation, Corresync also downloads the public release artifact, checksums, and provenance needed to verify and replace that executable; this never runs during an MCP tool call.
corr feedback creates an allowlisted, redacted report locally and never
submits it automatically. You decide whether to copy, save, or open a prefilled GitHub
page after reviewing every field.
If you choose to submit a GitHub issue or private advisory, the project receives the GitHub identity and report content you provide and uses them to answer the question, maintain the project, or investigate the concern. Public issues are public; private advisories remain restricted to authorized repository participants. GitHub stores these records under its own privacy terms, and the project retains them only as reasonably needed for support, security, legal, and project-history purposes. Never include live provider account data or credentials.
09 · Security
Controls and unavoidable risk
Corresync uses provider-pinned Google and Microsoft API endpoints, explicit TLS endpoints for standards routes, visible browser-owned Outlook sessions, normal system-browser OAuth, PKCE and state validation, OS-keyring grant storage, account-isolated sessions, authenticated local IPC, MCP over stdio, bounded parsing, and preview-before-commit controls. No method of local storage or transmission is completely secure. Protect your device, keyring, MCP configuration, selected model, and backups, and install only releases whose provenance you trust.
Report a suspected vulnerability through GitHub private vulnerability reporting; never put secrets or private account data in a public report.
10 · Your choices and deletion
Disconnect and remove access at any time
-
Run
corr account remove ALIAS --approveto remove that account’s Corresync configuration and account-local profile, import, cursor, and queue state. An unshared OAuth grant owned by Corresync is also removed from the OS keyring. This does not delete mail or calendar data held by the provider. - Revoke provider-side authorization in the connected-app or security settings for that account. For Google, visit Google Account connections, select Corresync, and remove its access. For Microsoft Graph or another OAuth provider, use that provider’s application-consent controls.
-
Use
corr events purge --account ALIAS --approvefor a retained local monitor queue, and delete any local audit or explicitly created import staging records you no longer want. - Uninstall Corresync and delete its local configuration/data directories if you want to remove the application completely. Your provider retains its own data until you change or delete it there.
corr auth logout closes local sessions but intentionally preserves
keyring grants for later sign-in. Use account removal and provider-side revocation
when you want the authorization deleted.
Depending on where you live, applicable law may provide rights to access, correct, delete, restrict, object to, or obtain a copy of personal information. Corresync does not operate an account database or hold the provider data processed only on your device, so use the local and provider controls above for that data. Contact the project about information you deliberately submitted through a project channel.
11 · Children
Not directed to children
Corresync is a technical mail and calendar tool and is not directed to children under 13. The project does not knowingly operate a service that collects personal information from children.
12 · Changes
Material changes remain visible
We may update this Policy as Corresync changes. The effective date appears at the top, and material changes are published on this page and in project release notes. If a change would use provider account data for a new purpose, Corresync will provide notice and obtain consent before that new use. Earlier versions remain available in the public source history.
13 · Contact
Questions and concerns
For a policy question that contains no private data, open a Corresync GitHub issue. For a security or privacy concern that requires private details, use private vulnerability reporting. The project is maintained by Naoki Kiyohara and contributors. Because the project does not host user accounts, mailboxes, or calendars, maintainers cannot retrieve or delete data stored only on your device or at a provider.