Privacy
Last updated 28 Aug 2026
faxit is a private, invite-only email client run by Victor Gyllenberg in Marbella, Spain. It is not a commercial product. This page says what it does with your data, in plain terms.
What faxit accesses
When you link a Google account, faxit asks for permission to read, modify, send and draft Gmail messages, and to read your send-as settings. It uses this to show your inbox, archive and label threads, send replies you write, and detect your aliases. It does not touch Drive, Calendar, Contacts or anything outside Gmail.
What faxit stores
On its server: your sign-in email, your linked account addresses, your aliases and their labels, and an encrypted refresh token per linked account (AES-256-GCM, key held outside the database). Message content is fetched live from Gmail on each request and is not stored on the server. Verification codes detected for push notifications are kept for at most ten minutes.
On your device: a session cookie, and a local cache of recent threads so the app opens instantly.
AI features
Triage labels, summaries and reply drafts are produced by sending message text to Anthropic’s Claude API. Anthropic does not train on API data. Drafts are never sent without you pressing send.
Google API Services
faxit’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Gmail is used only to provide the client features above, is never sold, and is never used for advertising.
Deleting your data
Unlink an account in Settings and its token and aliases are deleted immediately. Revoking faxit at myaccount.google.com/permissions has the same effect on Google’s side. To delete your user entirely, email the address below.
Contact
victor@jocy.co