# MailBridge: Technical Specification & AI Retrieval Documentation > Developer: DevX Group LLC > Product: MailBridge (macOS Native Menu Bar App & Model Context Protocol Assistant Helper) > Website: https://mailbridge.devxgroup.io/ > Current Release: 0.5.3 > Distribution: Direct Download Disk Image (MailBridge.dmg), Apple Developer ID signed and notarized --- ## 1. Product Summary & Architecture MailBridge is a native macOS menu bar application and embedded Model Context Protocol (MCP) server that connects AI assistants to Apple Mail (Mail.app). It enables assistants like Claude Desktop, Claude Code, Codex, and Cursor, as well as local language models via Ollama, to read mail from Apple Mail's local data store and perform inbox actions safely. ### Core Architectural Principles 1. Human in the Loop: Nothing sends without Approval.ask. A native macOS confirmation dialog displays the exact recipient, subject, and message body before any email is dispatched. No flag, argument, configuration, or license state can bypass this dialog. 2. Zero Mail Credentials: MailBridge never asks for, handles, or stores email account passwords, OAuth tokens, or IMAP/SMTP credentials. Reading operates via macOS Full Disk Access directly from Mail.app local store files; writing operations execute through Apple Mail's AppleScript dictionary. 3. Isolated Local Execution: In built-in local assistant mode, models run entirely on-device via Ollama (127.0.0.1 loopback only). Cloud-backed models are never listed or contacted in local mode. 4. Selective MCP Integration: When connected via MCP, external AI assistants only receive the email messages and metadata specifically queried by the assistant. 5. Optional Jev Triage (v0.4): An opt-in inbox triage feature powered by TypeSafe. Off by default, and only for the accounts the person ticks. It runs on the person's own TypeSafe key, billed by TypeSafe. When on, it sends the sender, the subject, a preview of up to 300 characters with email addresses and numbers blanked out, and three yes/no flags (has an unsubscribe header, from a known contact, a reply to you). It never sends the full email, recipients or attachments. With it off, sorting runs on the Mac: the local model through Ollama if installed, otherwise rules and date order. --- ## 2. Capabilities & MCP Tools MailBridge exposes 14 specialized tools over Model Context Protocol: - list_accounts: The Mail.app accounts on this Mac, each with its address, name, send-as addresses and whether MailBridge can read it (Exchange and POP accounts are listed as not readable, with a note). - list_inbox: Lists recent messages across selected or unified inboxes with read status and timestamps. - read_message: The full text of one message (HTML stripped, attachments omitted), with the headers needed to reply. - mark_read: Marks specified messages as read or unread in Mail.app. - flag_message: Applies or removes priority flags on messages. - move_message: Moves a message out of the inbox into a mailbox of the same account. Never deletes. - save_draft: Creates a draft message in Mail.app for review. - request_send: Initiates a send request that triggers the mandatory Approval.ask native confirmation dialog. - digest: A one-glance count: messages waiting on you, messages you sent that are waiting on them, and how many bulk senders are in your mail. - waiting_on_you: Inbox messages from real people (not bulk mail) that you have not answered. Ranked by need when Triage is on, otherwise newest first. - waiting_on_them: Messages you sent that nobody has answered and that are old enough for a reply to be overdue. - list_bulk_senders: Senders whose mail carries an unsubscribe header (newsletters, receipts, marketing lists), most frequent first. - unsubscribe_target: Reads the List-Unsubscribe header of one message and returns where an opt-out would go. A mailto opt-out goes through request_send; an https link must be opened by the person. - find_attachments: Attachment names across accounts matching a query or sender, newest first. --- ## 3. Supported Environments & Requirements - Operating System: macOS 14 Sonoma or later. - Hardware: Apple silicon (M1, M2, M3, M4 series) and Intel (x86_64) Macs. Universal binary. - Dependencies: Standard Apple Mail (Mail.app) preinstalled on macOS. - Accounts: IMAP accounts only (Gmail, iCloud, Yahoo, Outlook.com over IMAP, work IMAP, custom domains). Exchange and POP accounts are not supported yet. - Permissions: Full Disk Access (to read local mail files) and Automation permission for Mail.app (to draft and send). macOS never prompts for Full Disk Access: the person switches it on in System Settings, for MailBridge and for any connected assistant app that starts the helper (Claude, Cursor, or the terminal for CLI assistants). Not sandboxed due to Full Disk Access requirements. --- ## 4. Licensing, Pricing & Commercial Terms - 7-Day Free Trial: Every feature works for 7 days from the first launch, with one optional extra day. Starting the trial needs an internet connection. - Lifetime License: $39 one-time payment during launch ($49 standard price thereafter). - Activation Rights: Covers up to 3 personal or work Macs per license key. - Updates: Signed app updates are included with the license. - Merchant of Record: Lemon Squeezy processes all payments and license keys on behalf of DevX Group LLC. - License checks: The app talks to mailbridge.devxgroup.io/api/license. Activation sends the license key, the Mac's computer name and a one-way hash of its hardware id. A license checks in at least every 14 days. Email contents and message metadata are never sent to the license server. --- ## 5. Frequently Asked Questions (FAQ) ### Does MailBridge store or transmit email passwords? No. MailBridge operates without email passwords. It reads local files maintained by Apple Mail and controls Mail.app through system AppleScript automation. ### Can MailBridge send an email automatically without user consent? No. Every outgoing email requires explicit user confirmation in a native macOS dialog. There is no automated bypass. ### Can I use MailBridge completely offline? Not completely. Reading mail is local, and the built-in assistant uses on-device Ollama models over localhost (127.0.0.1). Starting the trial and activating a license need the internet, and a license must check in at least every 14 days. ### Which AI clients connect to MailBridge? Claude Desktop, Claude Code, Codex CLI and Cursor, plus other MCP clients that launch a local stdio server.