Troxic is a native macOS email client for Gmail, Microsoft 365, and IMAP/SMTP. Your mail stays between your Mac and the services you already use. Troxic operates no mail backend of its own. This page describes the shipping app. It does not describe planned consent changes.
The short version. Ordinary mail is exchanged directly between your Mac and Google, Microsoft, or your IMAP host. Tokens live in the macOS Keychain. Troxic has no analytics, telemetry, or crash reporter. Two optional services can each be handed one thread when you ask: OpenAI and DFIR Lab, each under your own key.
1. Who we are
Troxic is a native macOS email client. Privacy questions: contact@troxic.ch.
DFIR Lab (api.dfir-lab.ch) is an optional phishing service you can connect with your own key. When you run a check, that one message is sent to DFIR Lab. That is the only case where mail you select is sent to a third party other than your mail host or OpenAI.
2. What Troxic accesses
Google (Gmail)
First Connect Google requests openid, email, profile, and gmail.modify. Troxic never requests https://mail.google.com/ and cannot permanently delete Gmail.
Optional, only if you turn them on:
- Calendar —
calendar.eventsandcalendar.calendarlist.readonly. Denying Calendar does not affect mail. Connect Calendar only signs in for Calendar without Gmail. - Mailbox settings —
gmail.settings.basicfor filters, vacation replies, and send-as identities.
Microsoft 365
First Connect Microsoft requests mail only:
| Scope | Required to finish Connect? | Why |
|---|---|---|
openid email profile offline_access User.Read | Yes | Identify the account and stay signed in |
Mail.ReadWrite | Yes | Read, organize, trash (not purge) |
Mail.Send | Yes | Send mail you compose |
Optional, only if you turn them on:
- Calendar —
Calendars.ReadWriteafter Connect Calendar. Denying Calendar does not affect mail. Connect Calendar only requestsCalendars.ReadWriteandCalendars.ReadWrite.Sharedwith no Mail scopes, for identities that can open shared or resource calendars but have no mailbox. - Mailbox settings —
MailboxSettings.ReadWritefor Inbox rules and automatic replies.
Troxic uses delegated Microsoft Graph /me only. It does not request application (app-only) Mail.* permissions.
IMAP / SMTP
Messages and folders on the server you configure. The password is stored in the macOS Keychain and used only from this Mac. There is no OAuth for IMAP.
People
People is a local directory you build yourself, one per account. You add an address from the People workspace or by choosing Add to People on an address in mail. Troxic does not request a contacts scope and does not import Google Contacts, Microsoft Contacts, or any provider address book.
When you add someone, Troxic may fill the card from sender and recipient headers already in that account's local mail cache. Syncing mail does not create People entries on its own.
3. Where your data lives
- On your Mac. The mail cache is in the app sandbox (SwiftData). Google and Microsoft tokens, IMAP passwords, and optional OpenAI and DFIR Lab keys are in the macOS Keychain (service
com.troxic.mac.secrets, AfterFirstUnlock, not iCloud-syncable). - On the provider. Gmail, Microsoft 365, and your IMAP host remain the system of record.
- Nowhere else for ordinary mail. Troxic has no backend, no analytics SDK, no telemetry, and no crash reporter. Logging must not interpolate credentials, bodies, attachment bytes, or raw server responses.
Optional Apple Intelligence requests stay on this Mac.
4. What Troxic does not do
- Operate a mail server, sync service, or index of your mailbox.
- Sell, rent, or use your mail for advertising.
- Train a Troxic model on your mail.
- Permanently delete Gmail (
mail.google.comis never requested). - Import arbitrary received EML/mbox into Microsoft Graph. That path is disabled rather than creating drafts.
- Create server-side account forwarding.
5. User-initiated import and export
Export starts only after you choose Export and a destination. Troxic prefers provider-original RFC 822 bytes. Output is staged in the sandbox, written through the system save panel, and quarantined.
Import starts only after you pick an EML/mbox file, review a preflight, choose an account, and confirm. Gmail import uses gmail.modify. IMAP import uses APPEND. Microsoft import of arbitrary received mail is unsupported.
6. Optional services that leave this Mac
Every row below requires your action and, except Apple Intelligence, credentials you supply. Troxic never sends the whole mailbox.
| Service | Trigger | What is sent | Destination |
|---|---|---|---|
| OpenAI | An AI action you invoke, or opt-in Inbox headlines | That thread or draft; headlines send subject + snippet of the last 12 visible rows only | api.openai.com under your key, store: false |
| Apple Intelligence | You select On this Mac (or Automatic with no valid OpenAI key) | Nothing leaves the Mac | On device |
| DFIR Lab | Check with DFIR Lab on a conversation, or a link check | That message as RFC 822 (headers, body, attachments; cap 200 000 characters), or the URL you chose / the http(s) links in the conversation you opened if Check links is Automatic | api.dfir-lab.ch under your key |
| Remote images | People you have written to, or a sender you allow | Image request | The sender's host, directly from your Mac |
| Links you confirm | The confirm sheet | The URL you clicked | Your default browser |
Calendar data is never sent to OpenAI or DFIR Lab. DFIR Lab analysis is used only to return the verdict you asked for. It is not used to train a Troxic model.
Troxic does not publish a retention period for a submitted message. That figure is DFIR Lab's to confirm, not ours to invent. Write to contact@troxic.ch if you need it.
7. This website
troxic.ch is the marketing site. It may use Vercel Web Analytics (page views). That is website traffic, not mailbox data. The macOS app does not include that SDK.
8. Google API Services User Data Policy (Limited Use)
Troxic's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data, optional Calendar data, and optional mailbox-settings data are used only to provide the features you see, are never used for advertising, are never sold, and are transferred to a third party (OpenAI or DFIR Lab) only at your explicit request as described above.
9. Deleting your data
Settings → Account → disconnect signs you out, removes that account's local cache, and removes stored credentials. Disconnect Google also revokes the grant at Google. You can also revoke Troxic at myaccount.google.com/permissions or at myaccount.microsoft.com.
Removing the OpenAI or DFIR Lab key deletes that key from Keychain.
10. Children
Troxic is not directed at children under 16.
11. Changes
Material changes will be dated on this page and noted in the app's release notes before they take effect.