How your email stays private

Muninn handles business email about customers, leads, tips and invoices. Here is where that data is stored and who can act on it.

Where your data is stored

On your mail server
Muninn reads and acts via IMAP and SMTP. The mail server remains the primary source, so changes appear in your other clients too.
In one local file
The full-text and semantic search index, cases, people, style profiles and history are stored in one SQLite database on your computer or own server.
In a protected secret store
Desktop uses the system keyring. The server package uses encrypted storage with a separate key. Secrets are not kept in the database or logs.
No Muninn cloud
We don't receive your email, contacts or app usage data.

What AI can read

Only what a task needs
Classification, summaries, drafts and agent tasks send only the text the task needs, not the whole mailbox.
Zero data retention
Strict mode allows only providers contractually bound not to store your text or train on it.
Or fully local
Run models on your hardware with Ollama or SGLang. No text is sent to an AI provider.
Accounts and usage limits
Use your own provider accounts and choose a model per task. A daily token limit keeps costs predictable.

An agent that asks first

Read-only by default
Every account starts read-only. You allow changes on the server one account at a time.
Approval for actions
Sending, forwarding, deleting and unsubscribing require your approval unless you explicitly let a rule act on its own. Irreversible actions require a second approval.
Email content is kept separate
Email content is treated as untrusted data and kept separate from the agent’s instructions. Muninn checks how web addresses entered a task before fetching them.
Run limits and logs
Each agent run has limits on steps, context and time, with a readable log. All actions are recorded. Moves and flags can be undone.

Thunderbird's profile stays untouched

Choose a Thunderbird profile and accounts before importing. Passwords, address book and local email archive are separate options, off by default. Muninn reads the profile but never writes to it.