← Email Code Display

Privacy details

This is a personal, self-hosted tool. The public repository contains code, never mailbox credentials.

Mailbox access

Google Gmail read-only and Microsoft Graph Mail.Read permissions let the Worker read recent inbox messages. It does not send, delete, or mark messages read. Microsoft User.Read identifies the connected account. OAuth refresh tokens are encrypted with AES-256-GCM in Cloudflare D1.

Analysis

Messages containing possible access codes are analyzed using the configured AI model through Cloudflare Workers AI. The subject, sender, and up to 10,000 body characters are sent for classification. Model caching and request logging are disabled for these calls. The model host's current data handling terms still apply. Gemini can optionally be configured and then sends these inputs to Google.

Retention

The Worker does not store full message bodies. Extracted codes are encrypted and served only to the authenticated device. They expire five minutes after the message was received and are removed during the next successful scheduled cleanup. Message identifiers are kept for up to one hour to avoid duplicate analysis. OAuth state expires after ten minutes.

Disconnect

Disconnecting an inbox removes its local tokens, codes, and processed-message identifiers. You can also revoke the application's permissions from Google or Microsoft account settings. Browser admin sessions expire after 24 hours.

A code visible on a desk can be read by someone nearby. Press D0 to dismiss it immediately.