Skip to content
corresync
Home Getting started Providers Features Safety

Terms of Use

Clear terms, without taking away open-source rights.

These Terms cover the official Corresync website, release distribution channels, and project-operated OAuth identity. They also explain your responsibilities when the software connects to Google, Microsoft, Outlook Web, JMAP, IMAP/SMTP, CalDAV, a local import, or a user-selected client. Your copy of the software remains governed by Apache License 2.0; these Terms do not add a condition to the rights that license grants.

Effective and last updated: 30 July 2026

Acceptance License Responsibilities Providers Disclaimers Contact

The important part

Use only accounts and authority that are yours.

  • Review previews before you approve a remote write.
  • Follow your provider, employer, school, and applicable-law requirements.
  • Do not use Corresync to bypass access controls, send abuse, or harm others.
  • Protect your device, keyring, MCP clients, models, and backups.

01 · Acceptance and scope

When these Terms apply

These Terms of Use (“Terms”) are an agreement between you and Naoki Kiyohara, maintainer of the Corresync open-source project (“Corresync”, “we”, or “the project”). They apply when you use the official Corresync website, official release distribution infrastructure, or a project-operated OAuth identity (currently the Corresync Google OAuth application). Together, these are “Project Services”. By using Project Services, you agree to these Terms. If you do not agree, do not use those Project Services.

These Terms do not govern your rights to possess, run, study, reproduce, modify, or distribute a copy of the software; the license below does. Independent forks, third-party builds, providers, package managers, MCP clients, models, and runners are not Project Services and may impose separate terms.

02 · Open-source license

Apache-2.0 remains the software license

Corresync source code and official software distributions are licensed under the Apache License, Version 2.0, except for third-party components identified with their own license notices. The Apache-2.0 license governs use, reproduction, modification, distribution, patent rights, notices, contributions, software warranties, and software liability.

Nothing in these Terms narrows, conditions, or revokes rights granted by Apache-2.0, and accepting these Terms is not a condition of receiving those software rights. If these Terms conflict with Apache-2.0 about a copy of the software, the license controls. Release archives and native packages include the project license and generated third-party license materials; release builds also publish software bills of materials.

03 · Eligibility and account authority

Connect only what you are allowed to control

You may use Project Services only if you can form a binding agreement and are legally permitted to do so. Corresync is intended for accounts that the signed-in human already controls. You are responsible for having all permissions required by the provider, account owner, employer, school, organization, and applicable law.

Corresync does not grant mailbox, calendar, tenant, delegated-user, or administrator authority. Provider authentication, MFA, Conditional Access, service availability, administrator consent, and mailbox permissions continue to apply.

04 · Your responsibilities

Keep human judgment at the boundary

  • Verify account, recipients, attachments, attendees, dates, recurrence, and other fields in each preview before approving a consequential action.
  • Treat email, attachments, links, calendar fields, imported files, and monitor events as untrusted content, not as instructions or authorization.
  • Secure your device, OS account, browser, keyring, configuration, local files, MCP client, selected model, runner, and backups.
  • Review the privacy and data-handling terms of any MCP client, AI service, monitor destination, credential helper, or provider that you configure to receive data.
  • Install trusted builds, keep supported versions current, and verify release provenance where appropriate.
  • Maintain your own backups and reconcile provider state after any outcome Corresync reports as unknown or partial.

05 · Acceptable use

Do not use Corresync to bypass or abuse

You must not use Project Services to:

  • access another person’s account or data without authorization, or bypass authentication, MFA, provider policy, administrator controls, disabled services, rate limits, or permissions;
  • send spam, phishing, malware, harassment, unlawful surveillance, deceptive communications, or content that violates another person’s rights;
  • interfere with, overload, probe, or damage Corresync, a provider, or another person’s systems, except for good-faith security research reported privately;
  • misrepresent Corresync as affiliated with or endorsed by Google, Microsoft, another provider, or an agent vendor; or
  • use Project Services in violation of applicable law or third-party terms.

06 · Providers and third parties

Other services keep their own rules

Corresync connects directly to the routes you select: Google, Outlook Web, Microsoft Graph, JMAP, IMAP/SMTP, CalDAV, and approved local imports. Your use of a provider or endpoint is governed by its own terms, privacy policy, acceptable-use rules, quotas, administrator policies, and fees. Google account access is also subject to the Google APIs Terms of Service and applicable Google product policies.

Outlook Web uses Microsoft’s live website; Microsoft Graph uses delegated API permissions from a public client you authorize; standards routes use the TLS endpoints and credential references you choose. Corresync does not control and is not responsible for a provider’s availability, data, security, policy decisions, authentication flow, API or website changes, delivery outcome, or account action. Links to third-party resources are provided for context, not endorsement.

07 · Privacy

Local-first data handling

The Corresync Privacy Policy explains what every supported provider route and local import can access, why Google and Microsoft scopes are requested, what browser, credential, content, audit, queue, and staging data can remain locally, when data can reach a user-selected client or model, and how to disconnect and delete authorization. It is incorporated into these Terms by reference.

08 · Changes, suspension, and termination

Project Services can change

The project may change, suspend, or discontinue Project Services, provider integrations, OAuth credentials, release channels, or support for a version at any time. We may block or revoke access to a project-operated OAuth identity when reasonably necessary for security, legal compliance, provider requirements, abuse prevention, or protection of users and the project.

You may stop using Corresync at any time. Remove local accounts and OAuth grants, revoke provider access, and uninstall the application as described in the Privacy Policy. Provisions that by their nature should survive—including license ownership, disclaimers, liability limits, and accrued obligations—continue after use ends.

09 · Disclaimers and liability

No promise of uninterrupted or error-free operation

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, PROJECT SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED. WE DO NOT WARRANT THAT PROJECT SERVICES WILL BE SECURE, AVAILABLE, ACCURATE, ERROR-FREE, OR COMPATIBLE WITH EVERY PROVIDER, ACCOUNT POLICY, CLIENT, MODEL, OR PLATFORM.

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE PROJECT, MAINTAINERS, AND CONTRIBUTORS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES, OR FOR LOSS OF DATA, MESSAGES, CALENDAR EVENTS, PROFITS, GOODWILL, OR ACCESS, ARISING FROM PROJECT SERVICES. Some jurisdictions do not allow particular exclusions or limitations, so they apply only to the extent lawful. Sections 7 and 8 of Apache-2.0 separately control warranty and liability for copies of the software.

10 · Updates to these Terms

The current version stays public

We may update these Terms to reflect Project Service, legal, or policy changes. The effective date appears at the top, material changes are published on this page and in project release notes, and earlier versions remain available in source history. Continuing to use Project Services after updated Terms take effect means you accept them, except where applicable law requires another form of notice or consent.

11 · Contact

Questions and security reports

For a terms question that contains no private data, open a Corresync GitHub issue. Report security vulnerabilities or concerns requiring private details through GitHub private vulnerability reporting. Do not include live credentials, messages, calendar data, or personal information in a public issue.

corresync

Independent local-first mail and calendar tooling. Not affiliated with or endorsed by Google, Microsoft, or any provider or agent vendor named here.

Getting started Providers Features Safety Privacy Terms GitHub source Security Releases Apache-2.0