← faxit

Privacy

Last updated 28 Aug 2026

faxit is a private, invite-only email client run by Victor Gyllenberg in Marbella, Spain. It is not a commercial product. This page says what it does with your data, in plain terms.

What faxit accesses

When you link a Google account, faxit asks for permission to read, modify, send and draft Gmail messages, and to read your send-as settings. It uses this to show your inbox, archive and label threads, send replies you write, and detect your aliases. It does not touch Drive, Calendar, Contacts or anything outside Gmail.

What faxit stores

On its server: your sign-in email, your linked account addresses, your aliases and their labels, and an encrypted refresh token per linked account (AES-256-GCM, key held outside the database). Message content is fetched live from Gmail on each request and is not stored on the server. Verification codes detected for push notifications are kept for at most ten minutes.

On your device: a session cookie, and a local cache of recent threads so the app opens instantly.

AI features

Triage labels, summaries and reply drafts are produced by sending message text to Anthropic’s Claude API. Anthropic does not train on API data. Drafts are never sent without you pressing send.

Google API Services

faxit’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Gmail is used only to provide the client features above, is never sold, and is never used for advertising.

Deleting your data

Unlink an account in Settings and its token and aliases are deleted immediately. Revoking faxit at myaccount.google.com/permissions has the same effect on Google’s side. To delete your user entirely, email the address below.

Contact

victor@jocy.co