Privacy policy

Your inbox is
your business.

Dumbwaiter is a Mac app and Chrome extension, made by Michael Heap. It checks mail on your Mac to bring you recent login codes and links. It has no mail-processing server.

Last updated: 10 September 2026

What Dumbwaiter reads

When you connect an account, Dumbwaiter asks Google or Microsoft for permission to read your mail. This includes the sender, subject, time, and message body. Message-body access is needed to find a code or login link.

The requested permissions are read-only. They do not allow Dumbwaiter to send, change, or delete your email. You sign in directly with Google or Microsoft. Dumbwaiter does not ask for your inbox password.

The Chrome extension also uses information from the current page to match recent mail to a login request. This can include the site address, form fields, and sign-in text. Automatic use on websites requires Chrome site-access permission.

How the local check works

The Mac app connects to Google or Microsoft to read recent messages. It sends a limited batch of message content to the Chrome extension through a connection on your Mac. The extension checks this content for a matching code or link.

This means that the local Chrome extension receives message content, including message bodies. It does not receive the account’s OAuth tokens. The mail content is not sent to a Dumbwaiter server or an AI service.

If you choose a code, Dumbwaiter can fill it into the website. If you choose a link, your browser opens the link’s destination. The destination website then handles that visit under its own privacy policy. A login link can complete sign-in when you open it.

How Google data is used

Dumbwaiter uses data received from Google only to find and show recent one-time codes, sign-in links, email-confirmation links, and password-reset links for your authentication request.

Google mail data is not sold, used for advertising, shared with data brokers, or used to train AI models. The developer does not receive or review your mail through the app.

Dumbwaiter’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

What stays on your Mac

Dumbwaiter has no server-side mail database or mail backup to delete.

How to remove access

Remove an account in the Dumbwaiter Mac app to delete its local Keychain entry. You can also revoke the app’s access in your Google or Microsoft account settings. Removing the local account does not delete any mail.

Turn off “Copy codes automatically” in the extension settings to stop copying suggested codes before your click. This does not remove codes already held by the system clipboard or a clipboard manager.

You can turn off automatic website access in the extension, or remove the extension from Chrome. Uninstall the Mac app when you no longer want to use Dumbwaiter.

Dumbwaiter does not submit a website form or open an authentication link without your choice. You choose when to fill a code or open a link.

Software update checks

Public Mac releases can check an HTTPS update feed through Sparkle. An update request can expose your IP address and basic app or system version information to the download host. System-profile reporting is disabled. Update requests do not include mail, codes, login links, or OAuth tokens.

Chrome manages updates for extensions installed from the Chrome Web Store.

This website and support

This website has no analytics, advertising scripts, tracking cookies, or sign-up form. Its interactive example uses fixed, made-up data. It does not connect to your inbox or open a real login link.

If you email support, Michael Heap receives the message and any files you choose to send. Support email is handled by the email providers used to deliver it. Only include the information needed to answer your question.

Contact

For privacy questions or help removing local account data, email Michael Heap at mike@myaskai.com.