What leaves your device
Primail is network-connected. The destinations below are the ones the current client actually uses. This is not a guarantee that nothing else will ever appear, and it is not “exactly three hosts.”
Mail provider (always, for new mail)
Section titled “Mail provider (always, for new mail)”New fetch and send talk directly to your IMAP (port 993) and SMTP (port 465) servers with implicit TLS. Plaintext and STARTTLS are not supported. Connections carry headers, bodies, attachments, flags, and the credentials needed to authenticate.
Cached reading, local search, and local drafts do not need a Primail cloud account. See System requirements.
sync_run / the in-app refresh are this same IMAP path, not a
Primail configuration-sync service.
Optional: remote images in a message
Section titled “Optional: remote images in a message”Settings → Privacy → Remote images keeps three separate current controls. None of them is a conversation-wide grant.
- Load remote images automatically defaults to off and
keeps the saved value. When off, remote
<img>URLs are stripped before the body frame. - Show images on that message’s blocked-images banner unlocks this message only for the current session. The message id is held in memory and is not saved.
- Always from a sender stores that address in this app profile’s localStorage. That trust persists until you Revoke or Clear all under Settings → Privacy. It is not a temporary grant.
Unlocking one message does not unlock the rest of the thread. There is no current verified-conversation image permission.
When images load, the request goes to whatever host is in the message — often the sender or a tracker.
Optional: network avatars
Section titled “Optional: network avatars”Settings → Privacy → Load avatars from the network defaults to
on (saved value is preserved). Candidates are Gravatar
(www.gravatar.com/avatar/… from an email hash) and, for
organization domains, Clearbit (logo.clearbit.com/…). Turn the
control off to keep initials-only avatars.
Optional: OAuth
Section titled “Optional: OAuth”Signing in with Google or Microsoft contacts that provider’s authorization and token endpoints. That is not IMAP, and it is not a Primail host.
Optional: explicit Gemini helpers
Section titled “Optional: explicit Gemini helpers”If GEMINI_API_KEY is configured, MCP/CLI ai_* tools send
message text to Gemini. The consumer GUI has no bundled AI
control. Your MCP client may also send tool results to its own
model provider.
What is not a current product path
Section titled “What is not a current product path”sync.primail.appas a live preferences/pin/credential hostupdates.primail.appas a fixed daily version-check host- A background Primail Cloud sync
- An absolute TLS 1.3-only claim beyond “implicit TLS on 993/465”
Settings → Support → Updates can expose an auto-update preference; that is not documented here as a public CDN hostname.
Experimental primail-sync source is not a user-facing cloud you
are signed into.
Local-only
Section titled “Local-only”On this device, unless you opted into a network control above:
- The SQLite cache and Tantivy index
- Local drafts and the schedule/outbox tables
- The daily
primail.log.*activity file - Mail passwords in Keychain (used by local Primail processes)