本机开发版本 · 2026-10-02

MailX 应用隐私说明

更新:2026-10-02。本开发版本的发行主体、支持邮箱及公开政策网址尚未配置,正式发布前必须补充;此说明不表示已通过 App Store 审核。

数据与服务

邮件、账号设置、收件人建议、待执行操作、草稿及附件保存于本机应用容器。密码和 OAuth 凭据保存在系统 Keychain。应用向你配置的邮件服务商发送认证与同步请求,发送邮件会把正文、地址及附件交给该服务商;其保留规则由服务商决定。Google 登录仅在构建已配置时可用,向 Google 请求授权并交换凭据。

远程图片默认阻止。选择加载或信任发件人后,图片服务器会收到请求及网络地址,可能用于追踪。Gravatar 默认关闭;开启后会向 gravatar.com 发送发件人邮箱的 SHA-256 摘要和网络请求,摘要不能保证匿名。通讯录权限仅用于本地收件人建议,可在系统设置撤回。

通知与本机性能诊断

通知默认只提示新邮件,不显示发件人和主题;你可在通用设置中主动开启内容预览,再关闭时清除本应用已有的通知预览。应用在前台时不弹横幅或播放通知声音。通知内容交给 macOS 通知中心显示。

窗口恢复保存邮箱及邮件的本机标识,不保存正文到系统偏好。性能区间由本机 Instruments 使用,不包含邮件地址、主题、正文或搜索词,也不上传给发行方。其他诊断日志仍可能含账号和错误信息,请分享前检查。

Codex 与其他代理工具

MCP 默认关闭,仅监听本机回环地址并要求访问 token。开启前单独确认:持 token 的工具可以读取全部已同步邮件、附件及诊断数据,且可能把数据交给第三方 AI 服务商。mailx 不替这些工具选择服务商或控制其保留规则,请先检查工具政策。代理发信必须另行确认。关闭 MCP 停止访问;重新生成 token 撤销旧 token,无法撤回工具已经取得的数据。

保留、删除与控制

本地邮件、附件和草稿保留至你删除相应数据;移除账号清理其本地邮件缓存、凭据及账号草稿,不删除服务商的远程邮箱。失败会显示并允许重试。收件人建议与头像缓存跨账号共享,可在隐私设置单独清除。头像缓存采用 30 天有效期,过期文件可能保留至清理。草稿可在恢复提示中恢复或丢弃。诊断日志可包含邮件地址、账号与错误信息,不记录密码、token 或授权码;向他人分享日志前请检查内容。卸载后如需完全清理,请按 Help 说明检查应用容器和 Keychain。第三方工具已取得的数据需向相应提供商申请删除。

English

Notification previews are off by default. You can opt in to sender and subject previews in General settings; turning previews off clears existing app notifications. Foreground notifications do not show banners or play sounds. macOS Notification Center displays notifications. Navigation restoration stores opaque local folder/message identifiers, not message contents in preferences. Local Instruments performance intervals contain no addresses, subjects, bodies or search queries and are not uploaded to the publisher.

This development build has no configured publisher identity, support contact or public policy URL. These are required before release. Mail, settings, suggestions, pending actions, drafts and attachments are stored locally; credentials use Keychain. Authentication, synchronization and sending communicate with your selected mail provider. Google authorization is available only in configured builds.

Remote images are blocked by default. Loading them or trusting a sender contacts their servers. Optional Gravatar sends sender email hashes and network information; hashes are not guaranteed anonymous. Contacts permission supports local suggestions and can be revoked in macOS settings.

MCP is off by default, loopback-only and token protected. Explicitly enabling it permits token holders to read all synced mail, attachments and diagnostics. Connected agents may disclose this data to third-party AI providers under their own policies. Sending requires separate confirmation. Disable MCP or rotate the token to revoke future access; previously shared data cannot be recalled.

Account removal deletes scoped local caches, credentials and drafts, not your provider account. Shared recipient suggestions and avatar caches have a separate clear action in Privacy settings. Recovery drafts remain until saved, discarded or removed with their account. Avatar entries expire after 30 days; expired files may remain until cleared. Logs may contain addresses and diagnostic details; review them before sharing. Provider/agent retention and deletion are governed by those providers. See Help for complete local cleanup.

官网访问

本官网不设置分析脚本、账户登录或收集表单。网站由 Cloudflare Workers 提供服务;网络请求与基础设施数据处理以 Cloudflare 的相关政策为准。此处应用说明来自当前开发版本,不是 Apple 或 Google 审核通过的声明。

Cloudflare 隐私政策 · 返回 MailX 首页