AI permissions

How Nixt Mail asks before sending mail to a model, how long a permission lasts, and what any AI caller can and cannot do.

Nixt Mail never sends mail text or a file to a model because a setting was switched on once. It asks, in a sentence naming where it goes, at the moment it is first needed. Your answer grants a permission that lasts a few hours, applies to that one destination, and is never written to disk.

How permissions work

  • Asked when needed. There is no checklist at setup time. Each question appears the first time an action needs it.
  • Tied to one destination. A permission names the destination AI pointed at when you agreed: the placement, the provider and the host. If any of those change, every permission that named the old destination ends and you are asked again.
  • Always temporary. Every permission expires.
  • Held in memory only. Quitting Nixt Mail ends every permission. The next time you open Nixt Mail, you are asked again.
  • Narrow. A permission to send a message does not cover sending a file. A file is a separate question.
PermissionWhen you are askedWhat it coversHow long it lasts
Sending messages to a destinationThe first time the Assistant, Draft with AI, Summarize with AI or Say it differently sends something to that destinationQuestions in the Assistant, Draft with AI, Summarize with AI and Say it differently8 hours
Sending files to a destinationThe first time you choose Ask about this file for that destinationAsking about files, and everything the first permission covers8 hours
Sending several threadsEvery time you click Summarize N threads in AutopilotThose threads. Agreeing also grants the first permission, if you do not already hold itUntil the last thread is sent
Letting Rosalyn triageEvery time you click Start in Triage with RosalynReading the unread messages the dialog names, in that list, and suggesting changes to them4 hours

Because a file permission also covers sending messages, you are not asked separately about messages after agreeing to send a file to the same destination.

The questions about several threads and about Rosalyn are asked every time, because each one names a number of messages.

The questions you are asked

Sending a message

The dialog is titled Send this thread to host**?**. Its text says that the text of the message will be sent to that host, whose terms apply there, and what that destination does with it afterwards, and ends Continue?

DestinationWhose terms the dialog namesWhat it says happens to the text
Your own serverUnder the operator of that endpoint, which on loopback is the user themselves.What that endpoint keeps is decided by whoever runs it. On this machine, that is you.
Your AI providerUnder the user, under their own account with that provider.What they keep, and for how long, is between you and them under your own account — most providers hold requests for a period for abuse review. Nixt Mail cannot read their policy and will not guess at it for them.
  • Click Send it to grant the permission and send the request.
  • Click Not now to send nothing. The feature then says Nothing has been granted for this yet, so nothing was sent.

Sending several threads

The dialog is titled Send N threads to host**?**. Its text says that the text of that many threads will be sent to that host one at a time, whose terms apply there, and what that destination does with it afterwards. It adds that fetching them for this does not mark them read, and ends Continue?

  • Click Send N to send them. For one thread, the button reads Send it.
  • Click Not now to send nothing.

It is asked even when you already hold the permission to send messages, because that permission was granted for a single message.

Letting Rosalyn triage

The dialog is titled Triage with Rosalyn. It says that Rosalyn will read the unread messages it counts, in the list it names, and propose changes, for the next 4 hours. It says that nothing happens until you confirm each change, and that nothing can be sent. A second line says that each message goes to the AI destination as it is read, and stays unread.

  • Click Start to grant the permission and begin.
  • Click Not now to send nothing.

The permission covers only the messages the dialog counted. Mail that arrives afterwards is not included.

Sending a file

The dialog is titled Send file name to host**?**. Its text names the file and its size, says it will be sent to that host as well, explains that attachments are usually the most sensitive thing in a mailbox and so this is a separate question, and asks whether to send attachments to that destination.

  • Click Send the file to grant the permission. For a file someone sent you, the file is downloaded only now, after you agree.
  • Click Not now to send nothing and download nothing.

Only files Nixt Mail can turn into text can be asked about. See Which files can be read.

When a permission ends

A permission ends when:

  • its time runs out,
  • you quit Nixt Mail,
  • you change the AI placement, the provider, or the host name in the address, or
  • you set AI to Off.

Changing only the model name does not end a permission.

While you hold permissions for the current destination, Settings › AI and services shows a line under the AI settings: Changing this ends N permission(s) you granted for the current destination. You will be asked again.

To end every permission before it expires, quit Nixt Mail, change where AI runs, or set AI to Off.

Messages when a permission is missing

MessageWhat it meansWhat to do
Nothing has been granted for this yet, so nothing was sent.You have not agreed to this, or chose Not now.Try again and agree to the dialog.
That permission has run out. Granting it again takes one answer.The permission expired.Try again and agree to the dialog.
The destination changed since this was granted, so it no longer applies.Where AI runs changed after you agreed.Try again and agree to the new dialog.
That is outside what was granted, so it stopped and did not proceed.The action needs more than was granted — for example, a file under a permission that covers only messages.Try again; the wider question is asked.

What any AI caller can and cannot do

The Assistant, Draft with AI, Summarize with AI and Say it differently only produce text. They cannot read anything beyond what is described on AI overview, and they cannot change your mailbox.

Rosalyn reads only the unread messages the dialog names. She can suggest archiving, flagging or marking read. She makes only the changes you leave ticked and confirm, and Undo it all reverses them.

No AI caller can do these, whatever it is told:

  • Send mail. The only way mail leaves Nixt Mail is you pressing Send.
  • Delete anything permanently.
  • Read your passwords, sign-ins or API keys.
  • Change settings, where AI runs, or any permission. A caller cannot widen what it was allowed.

Something unclear or out of date on this page? Tell us.