Skip to content

What your AI provider sees when you query your inbox

Follow one question through the system: what reaches the assistant's provider, what Koltrix returns and does not receive, and how to ask narrowly to share less.

Koltrix Team6 min read
A white robotic hand holding a mechanical counter
Photo by Bernd Dittrich on Unsplash
On this page(10 sections)
  1. The path of one question
  2. What Koltrix sends, and what it does not
  3. What the provider does with it
  4. Koltrix's own AI is a different path
  5. What you control
  6. A practical data-minimization routine
  7. Which mailboxes are poor candidates
  8. What about hidden instructions in the mail itself
  9. Questions to ask any provider
  10. Key takeaways

When you ask Claude "what did Dana say about the renewal?", where does Dana's email go? The honest answer has three parts, and it is worth understanding all three before you connect a mailbox that matters.

This post follows one question through the system: who sees what, what Koltrix sends, what it does not, and which decisions are yours. It stays on facts we can state and avoids promises about other companies' policies, which you should read for yourself.

The path of one question

Say you type: "Summarize the thread with Dana about the renewal."

Step Where it happens What moves
1 You type in the assistant app Your question goes to the assistant's provider, for example Anthropic for Claude or OpenAI for ChatGPT
2 The model decides to call a Koltrix tool A tool call goes from the assistant app to Koltrix, such as a search and then a read of one thread
3 Koltrix checks the token and your access Koltrix replies with the thread's text, only for mail you can open
4 The assistant app gets the result The thread text enters the model's context, which means it is sent to the provider
5 The model writes the summary The summary comes back to you

Step 4 is the one to dwell on. For the assistant to summarize a thread, the thread has to be given to the model, and the model runs at the provider. That is how any assistant that reads your data works, with email or with any other source. It is not specific to Koltrix.

What Koltrix sends, and what it does not

Koltrix returns what a tool call asks for, and only that.

  • A search returns summaries of matching conversations: subject, sender, snippet, date, unread state and labels.
  • A read returns the messages in one conversation: from, to, cc, date, subject and plain-text body, with attachments listed by name and size, not downloaded.
  • An inbox summary returns counts and the conversations waiting for a reply.

It does not send your whole mailbox, and it does not send what no tool asked for. Attachments are not opened or sent. Everything is restricted to the mailboxes you can open, checked on every call.

In the other direction, Koltrix does not receive your conversations with the assistant. It sees the tool calls the assistant makes, and the audit log records each call by tool name, not by content. So there is no copy of your chat sitting in Koltrix.

What the provider does with it

This is where we have to be careful, because it is not our policy. When mail reaches an assistant provider, it is handled under that provider's terms. Those terms differ by company, by plan and over time. They typically cover whether conversations are retained, for how long, who can access them, and whether they can be used to improve models. Business and enterprise plans often have different terms from personal plans.

We will not summarize those terms for you, because a summary written on one day is wrong later. What we recommend:

  • Read the current terms and the data settings for your plan, in the provider's own documentation.
  • Check settings that control retention and training, if your plan has them, before connecting a mailbox.
  • Ask your provider's business team if your needs are specific, for example contractual restrictions on where customer messages may go.
  • Use a business or team plan if you handle other people's data at work, rather than a personal account, and read what it promises.

Koltrix's own AI is a different path

Koltrix has its own AI features in the app: sorting, summaries, suggested replies. That path is separate from MCP. It runs on providers Koltrix selected and documents on its security and subprocessors pages, it can be turned off per workspace, and it never sends without a person clicking Send. An MCP connection, by contrast, is a third-party assistant you chose, working through your account.

Keeping the two straight avoids a common confusion. Turning off Koltrix's AI does not stop an assistant someone has connected over MCP, and turning off MCP assistants does not change Koltrix's own sorting. They are separate switches for separate paths. You can read the details on Koltrix's security page and its subprocessors list.

What you control

Decision Who How
Whether assistants can connect to the workspace at all Owner or admin Turn assistants off for the workspace
Whether you connect one You Approve or deny on the approval page
What it can do You The permissions you approve
What it can see Your access An assistant never sees more than you can open
What you ask it to look at You The prompt: be specific about sender, label and dates
Cutting it off You or an admin Revoke the connection, effective immediately

The most underrated control is the last-but-one: what you ask. An assistant reads what the question needs. "Summarize my thread with Dana about the renewal" brings one thread into the model's context. "Read my whole inbox and tell me everything" brings in far more. Specific questions are cheaper, faster, more accurate and expose less.

A practical data-minimization routine

  • Ask narrow. Name the sender, the label, the date range.
  • Prefer summaries of one thread over sweeps of many.
  • Keep the most sensitive mail out of assistant sessions. An assistant has all the access you have, so you cannot restrict a connection to part of your mail. You can choose not to ask about those threads.
  • Do not paste secrets into prompts. Passwords, API keys and full payment numbers do not belong in a chat, whatever the mailbox policy.
  • Be aware of attachments. The assistant sees their names and sizes, not their contents. If you paste an attachment's text into the chat, that text goes to the provider too.
  • Review connections now and then. Reviewing and revoking AI app connections suggests a routine.

Which mailboxes are poor candidates

Some mail you would rather not put in front of any third-party model:

  • Material your contracts keep away from third parties.
  • Regulated personal data you are obliged to handle under specific rules.
  • Active legal matters.
  • Anything you would not email to an outside contractor.

For these, the safe answer is to not ask the assistant about those conversations. If an entire workspace is in that category, an admin can switch assistants off for it. This is not legal advice; check your own obligations.

What about hidden instructions in the mail itself

Data flow has a second direction. The mail an assistant reads is text from other people, and some of it may be written to manipulate the model. That is a different risk from privacy, but it travels the same path. Koltrix fences email content in tool results, marks it as untrusted, third-party text and tells the assistant to treat it as data, and its tools are narrow: no deleting, no forwarding, and sending is off by default. Defending AI assistants against hidden instructions covers it.

Questions to ask any provider

  • Are my conversations retained, and for how long?
  • Can they be used to train models, and can I opt out?
  • Who at the company can read them?
  • What changes on a business plan?
  • Can I delete them, and what does deletion cover?
  • Where are they processed?

If you cannot find the answers, treat that as an answer.

Key takeaways

  • To answer a question about your mail, an assistant must hand the relevant text to its model, so it goes to the provider and is handled under the provider's terms.
  • Koltrix returns only what a tool call asks for, from mailboxes you can open, and it does not receive your conversations with the assistant.
  • Read the provider's current terms and data settings for your plan; we do not summarize them for you.
  • Koltrix's own AI is a separate path with separate switches.
  • The best control is a specific question. Read the integration overview and the docs privacy section for the details.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn