Unibox
SECURITY WITHOUT MYSTERY

Know where access lives and where your email goes.

Unibox is designed to minimize credential exposure, keep mailbox content out of its subscription service, and give you clear control over provider access and optional AI.

Provider OAuth

Google and Microsoft authentication happens on the provider’s sign-in page. Unibox stores the resulting revocable authorization token, not the provider password.

macOS Keychain

OAuth tokens, Yahoo app passwords, IMAP/SMTP passwords, optional OpenAI keys, and sensitive subscription access state are stored in Apple Keychain.

Encrypted connections

Provider traffic uses HTTPS, TLS, or STARTTLS as applicable. Generic mail accounts require compatible secure server settings supplied by the email host.

No central mailbox archive

The Unibox subscription service does not store your messages or attachments. Mail remains with the provider and a bounded working cache remains on your Mac.

Optional AI boundary

AI stays off until you add your own key. Message text is sent only for an invoked action or enabled triage; attachments are excluded.

Revocable access

Disconnect an account inside Unibox, remove its saved access, and revoke Google or Microsoft authorization from the provider’s security controls when needed.

THREAT MODEL

Practical safeguards, not impossible promises.

No email software can eliminate every risk. A compromised Mac account, malicious attachment, weak provider password, unsafe app password, or social-engineering attack can still expose email.

Unibox focuses on reducing avoidable exposure: no plaintext secrets in preferences, no server-side mailbox-content warehouse, no LinkedIn credential collection or automated sending, and no attachment uploads to AI.

Read the complete data-handling policy or review the public security contact file.

SECURITY QUESTIONS

Direct answers about account access

Does Unibox store my email on its subscription server?

No. The subscription service stores account, entitlement, and email-preference information, but it does not store mailbox content. Unibox keeps a bounded working cache locally on the Mac.

Can Unibox guarantee that an email account will never be hacked?

No responsible software can promise zero risk. Unibox reduces exposure through provider OAuth where supported, macOS Keychain, encrypted connections, local caching, and clear revocation paths.

What email content is sent to OpenAI?

Nothing is sent until you enable AI with your own API key and invoke an AI action or enable limited automatic triage. Only the message text needed for that action is sent; attachments are not sent.

SECURE BY DESIGN

Bring your inboxes together without handing them to another mailbox server.

Try Unibox for 30 days with no credit card.

Start free