Privacy policy
Your inbox is
your business.
Dumbwaiter is a Mac app and Chrome extension, made by Michael Heap. It checks mail on your Mac to bring you recent login codes and links. It has no mail-processing server.
Last updated: 10 September 2026
What Dumbwaiter reads
When you connect an account, Dumbwaiter asks Google or Microsoft for permission to read your mail. This includes the sender, subject, time, and message body. Message-body access is needed to find a code or login link.
The requested permissions are read-only. They do not allow Dumbwaiter to send, change, or delete your email. You sign in directly with Google or Microsoft. Dumbwaiter does not ask for your inbox password.
The Chrome extension also uses information from the current page to match recent mail to a login request. This can include the site address, form fields, and sign-in text. Automatic use on websites requires Chrome site-access permission.
How the local check works
The Mac app connects to Google or Microsoft to read recent messages. It sends a limited batch of message content to the Chrome extension through a connection on your Mac. The extension checks this content for a matching code or link.
This means that the local Chrome extension receives message content, including message bodies. It does not receive the account’s OAuth tokens. The mail content is not sent to a Dumbwaiter server or an AI service.
If you choose a code, Dumbwaiter can fill it into the website. If you choose a link, your browser opens the link’s destination. The destination website then handles that visit under its own privacy policy. A login link can complete sign-in when you open it.
How Google data is used
Dumbwaiter uses data received from Google only to find and show recent one-time codes, sign-in links, email-confirmation links, and password-reset links for your authentication request.
Google mail data is not sold, used for advertising, shared with data brokers, or used to train AI models. The developer does not receive or review your mail through the app.
Dumbwaiter’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
What stays on your Mac
- Account access: OAuth tokens and connected-account details are stored in the macOS Keychain. The extension does not receive the tokens.
- Mail content: Recent message content is processed in memory. Dumbwaiter does not create a mail archive.
- Copied codes: “Copy codes automatically” is on by default. A suggested code may be copied to the system clipboard before you click. Selecting a code also copies it when Chrome allows clipboard access. The system or a clipboard manager can keep or sync copied content under its own settings.
- Settings: Chrome stores extension preferences on your device. Its session storage holds temporary watch state, account-check results, and message identifiers used to prevent repeated results.
Dumbwaiter has no server-side mail database or mail backup to delete.
How to remove access
Remove an account in the Dumbwaiter Mac app to delete its local Keychain entry. You can also revoke the app’s access in your Google or Microsoft account settings. Removing the local account does not delete any mail.
Turn off “Copy codes automatically” in the extension settings to stop copying suggested codes before your click. This does not remove codes already held by the system clipboard or a clipboard manager.
You can turn off automatic website access in the extension, or remove the extension from Chrome. Uninstall the Mac app when you no longer want to use Dumbwaiter.
Dumbwaiter does not submit a website form or open an authentication link without your choice. You choose when to fill a code or open a link.
Software update checks
Public Mac releases can check an HTTPS update feed through Sparkle. An update request can expose your IP address and basic app or system version information to the download host. System-profile reporting is disabled. Update requests do not include mail, codes, login links, or OAuth tokens.
Chrome manages updates for extensions installed from the Chrome Web Store.
This website and support
This website has no analytics, advertising scripts, tracking cookies, or sign-up form. Its interactive example uses fixed, made-up data. It does not connect to your inbox or open a real login link.
If you email support, Michael Heap receives the message and any files you choose to send. Support email is handled by the email providers used to deliver it. Only include the information needed to answer your question.
Contact
For privacy questions or help removing local account data, email Michael Heap at mike@myaskai.com.