AI & your privacy

AI that works for you — if you want it.
Hardened against AI that doesn't.

Many people are concerned about AI, especially near their email, and that's reasonable. This page sets out exactly what goCORA's AI does, what it never does, and how goCORA protects you from AI used by someone else. Every statement here describes how the app works today; if that ever changes, this page changes with it.

AI that works for you — if you want it

  1. Off until you turn it on. No AI runs until you add your own API key and allow a provider.
  2. Nothing is sent unless you tap. goCORA has no background AI. You choose the message and the action.
  3. Your key, your provider. Mail goes from your device straight to Anthropic or OpenAI, never through goCORA's servers. Your key is kept in your device's secure storage.
  4. AI suggests. You decide. AI never sends or deletes. It moves mail only after you approve it in Tidy my inbox, and only into folders you already have.
  5. See what's sent. goCORA asks your permission for each provider before anything is sent, and asks again if what's sent ever changes.
  6. One switch turns it off. Set the AI agent to Off, withdraw permission or remove your key in AI Assistant settings. Hide every AI option with Show AI features in Settings.

Hardened against AI that doesn't

Myth or fact?

Tap a myth to see the facts.

Myth goCORA's AI reads all my email in the background.

Fact Nothing is sent until you tap an AI action, and then only what that action needs — usually the one message you're looking at.

Myth My email passes through goCORA's servers on its way to the AI.

Fact It goes straight from your device to the provider you chose, using your own key. goCORA's servers never see your mail or your AI requests.

Myth The AI could send or delete my email on its own.

Fact It can't. Sending and deleting always need you. Tidy my inbox only moves the messages you tick and approve with Move selected.

Myth A scam email could tell the AI to forward my mail to a stranger.

Fact goCORA tells the AI to treat every email as data, strips hidden text first, and the AI has no ability to forward, send or move anything. The worst a scam email can do is be summarized — so still read summaries with the same care as the email itself.

Myth Once AI is on, I can't really turn it off.

Fact One switch turns the AI agent off. You can also withdraw permission or delete your key — and nothing more is sent.

Myth AI tools on my computer can always read goCORA's screen.

Fact With Hide from screen capture on (Android and Windows), screen-capturing apps and agents see a blank window.

How it works — for the technically curious
  • Consent gate: permission is stored per provider with a version number, and is checked inside the AI service itself — not just on screen — before any request is built. A change in what's sent bumps the version, so you're asked again.
  • Prompt-injection defences: email content is wrapped in delimiters and labelled untrusted; delimiter look-alikes inside the content (sender, subject, body, attachment text and file name) are neutralised; HTML is converted to plain text, dropping hidden elements, display:none, zero-size and tiny fonts, text the same colour as its background, and zero-width characters. The HTML version of an email is used whenever it has one, because the plain-text copy most mail programs send alongside it shows hidden text as ordinary text. Hidden text that addresses an AI ("ignore previous instructions", "system prompt", "Claude, tell the user…") is detected on the device and reported to you by goCORA itself.
  • Advice kept out of your email: a suggested reply comes back as two parts, the reply and any cautions; only the reply goes into a draft.
  • No tools for the model: the AI returns text only. Every change to your mailbox goes through one gateway that enforces your per-account autonomy setting and always asks before sending or deleting. AI-suggested folders must already exist, and message IDs must be ones the AI was shown.
  • Output handling: AI results are shown in a plain text label, never a web view.
  • Keys: stored in the operating system's secure storage (the iOS Keychain, Android Keystore-backed encrypted storage, Windows data protection), never in goCORA's database or settings, and readable only after an interactive sign-in.
  • Screen capture: FLAG_SECURE on Android, WDA_EXCLUDEFROMCAPTURE on Windows.

What happens to your data once it reaches Anthropic or OpenAI is covered by that provider's own API terms and privacy policy, which you agree to when you create your API key.