AI that works for you — if you want it.Hardened against AI that doesn't.
Many people are concerned about AI, especially near their email, and that's reasonable. goCORA gives you the best
of AI on your terms, and defends you against AI used by someone else. Every statement on this page describes how
goCORA works today.
Your devicegoCORA app
→
Anthropic or OpenAIwith your own API key
goCORA serversnot in the path
Only when you tap an AI action, and only after you've given permission.
AI that works for you — if you want it
- Off until you turn it on. No AI runs until you add your own key and allow a provider.
- Nothing is sent unless you tap. goCORA has no background AI. You choose the message and the action.
- Your key, your provider. Mail goes from your device straight to Anthropic or OpenAI, never through goCORA's servers. Your key is kept in your device's secure storage.
- AI suggests. You decide. AI never sends or deletes. It moves mail only after you approve it in Tidy my inbox, and only into folders you already have.
- See what's sent. goCORA asks your permission for each provider, and asks again if what's sent ever changes.
- One switch turns it off.
Hardened against AI that doesn't
- Scam emails can't take control. goCORA treats every email as data, not instructions. It strips hidden text — invisible, same-colour or microscopic — and blocks fake markers before anything reaches the AI — and tells you when an email tried.
- AI answers can't leak your mail. Answers are shown as plain text, never run as a web page, and Ask your mailbox shows which emails each answer came from.
- Your key stays locked. It's kept in your device's secure storage and can't be used until you've signed in to goCORA.
- Hide from screen capture. One switch blanks goCORA for screenshots, screen recording and apps or AI agents that capture the screen (Android and Windows).
- Bots are held back. goCORA's website limits automated votes and suggestions and safely displays anything people submit.
Myth or fact?
MythgoCORA's AI reads all my email in the background.
FactNothing is sent until you tap an AI action, and then only what that action needs — usually the one message you're looking at.
MythMy email passes through goCORA's servers on its way to the AI.
FactIt goes straight from your device to the provider you chose, using your own key. goCORA's servers never see your mail or your AI requests.
MythThe AI could send or delete my email on its own.
FactIt can't. Sending and deleting always need you. Tidy my inbox only moves the messages you tick and approve with Move selected.
MythA scam email could tell the AI to forward my mail to a stranger.
FactgoCORA tells the AI to treat every email as data, strips hidden text first, and the AI has no ability to forward, send or move anything. Still read AI summaries with the same care as the email itself.
MythOnce AI is on, I can't really turn it off.
FactOne switch turns the AI agent off. You can also withdraw permission or delete your key — and nothing more is sent.
MythAI tools on my computer can always read goCORA's screen.
FactWith Hide from screen capture on (Android and Windows), screen-capturing apps and agents see a blank window.
How it works — for the technically curious
- Consent gate: permission is stored per provider with a version number and checked inside the AI service itself, not just on screen, before any request is built.
- Prompt-injection defences: email content is wrapped in delimiters and labelled untrusted; delimiter look-alikes inside it are neutralised; HTML becomes plain text, dropping hidden elements, zero-size and tiny fonts, text the same colour as its background, and zero-width characters. The HTML version of an email is used whenever it has one, because the plain-text copy shows hidden text as ordinary text. Hidden text that addresses an AI is detected on your device and reported to you by goCORA itself.
- No tools for the model: the AI returns text only. Every change to your mailbox goes through one gateway that always asks before sending or deleting. AI-suggested folders must already exist.
- Output handling: AI results are shown as plain text, never in a web view.
- Keys: kept in the operating system's secure storage, never in goCORA's database or settings, and usable only after an interactive sign-in.
- Screen capture:
FLAG_SECURE on Android, WDA_EXCLUDEFROMCAPTURE on Windows.
What happens to your data once it reaches Anthropic or OpenAI is covered by that provider's own API terms and privacy policy.
Anthropic and OpenAI are trademarks of their respective owners; goCORA is not affiliated with them.