---
title: "Does an AI Email Assistant Store Your Email?"
url: https://www.insulin.dev/blog/does-an-ai-email-assistant-store-your-email/
canonical: https://www.insulin.dev/blog/does-an-ai-email-assistant-store-your-email/
type: Blog
description: "Not the message body: Insulin fetches it live from Gmail or Outlook and never stores it. What it does keep is a short, exact list, and it is not nothing."
---

# Does an AI Email Assistant Store Your Email?

> Canonical HTML version: https://www.insulin.dev/blog/does-an-ai-email-assistant-store-your-email/

1.  [Home](/)
2.  /
3.  [Blog](/blog/)
4.  /
5.  Does an AI Email Assistant Store Your Email?

# Does an AI Email Assistant Store Your Email?

Not the message body: Insulin fetches it live from Gmail or Outlook and never stores it. What it does keep is a short, exact list, and it is not nothing.

![Chengjun Yuan](/leadership/chengjun.jpeg)

Chengjun Yuan

Co-founder & CTO · Sep 19, 2026

 ![Does an AI Email Assistant Store Your Email?](/images/blog/does-an-ai-email-assistant-store-your-email/hero.png)

Explore AI Summary

 [![](/logos/company/openai.svg)](https://chat.openai.com/?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fdoes-an-ai-email-assistant-store-your-email%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Security%2C%20Inbox%20App. "Summarize with ChatGPT")[![](/logos/company/anthropic.svg) ](https://claude.ai/new?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fdoes-an-ai-email-assistant-store-your-email%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Security%2C%20Inbox%20App. "Summarize with Claude")[![](/logos/company/gemini.svg)](https://www.google.com/search?udm=50&aep=11&q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fdoes-an-ai-email-assistant-store-your-email%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Security%2C%20Inbox%20App. "Summarize with Gemini")[](https://www.perplexity.ai/search/new?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fdoes-an-ai-email-assistant-store-your-email%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Security%2C%20Inbox%20App. "Summarize with Perplexity")

Table of Contents

-   [Does Insulin store the body of your email?](#does-insulin-store-the-body-of-your-email)
-   [What does Insulin keep while a mailbox is connected?](#what-does-insulin-keep-while-a-mailbox-is-connected)
-   [Is what Insulin keeps just metadata?](#is-what-insulin-keeps-just-metadata)
-   [Which model works on your mail?](#which-model-works-on-your-mail)
-   [What does Insulin write into your mailbox?](#what-does-insulin-write-into-your-mailbox)
-   [What should a security review record?](#what-should-a-security-review-record)
-   [Frequently asked questions](#frequently-asked-questions)
-   [Takeaways](#takeaways)

_Not the message body. Insulin’s Inbox app fetches each email body from Gmail or Outlook when you open the message, and the full body is never stored — but it does keep a short, specific list of other things, and a security review should know every item on it._

* * *

Connecting a mailbox is where a privacy review leans in, and the first question about any AI email assistant is the same: will it keep a copy of our mail?

Insulin’s Inbox sharpens the question, because its **Mails** view mirrors your mailbox — **Inbox**, **Starred**, **Sent** and **Drafts** — inside the workspace. A mirror is not necessarily a copy. The answer has two halves: a clean no for the body of every message, and a short list of what is kept instead. The list is the useful half, because each line of it can be checked against a data policy.

## Does Insulin store the body of your email?

No. Email bodies are fetched live from your provider each time you open a message, and the full body is never stored by Insulin.

**A fetched-live body is** one read from Gmail or Outlook at the moment you open the message, rather than from a copy Insulin keeps. The mail list shows the short preview line your provider returns with each message; the body itself comes from your provider every time you open it.

## What does Insulin keep while a mailbox is connected?

Per message: header fields, a preview line, labels, AI output and records of which rules ran. Across messages: a writing-style profile, a **History** entry for each sent email, and the chat rail’s conversation. Exactly:

Item

Fetched live or retained

Exactly what is retained

Message body

Fetched live, each time you open the message

Nothing — the full body is never stored

Header fields

Retained

Subject, sender, recipients, timestamps

Preview line

Retained

Your provider’s preview (Gmail’s snippet, Outlook’s body preview), which is what the mail list shows

Labels

Retained

The labels applied

Extraction

Retained

Any structured extraction, for example a drafted reply’s subject and body

AI drafts

Retained

The drafts themselves and their edit history

Thread summary

Retained when you request one

The summary

Rule traces

Retained

Records that explain which rules ran

Writing style

Retained

A profile learned from your recent sent mail, summarized as your greeting, sign-off, register, and common openers and closers

**Approvals ▸ History**

Retained

Per sent email: the subject, the recipients, and who pressed **Send** and when

Inbox chat rail

Retained

Your conversation with the agent, on a thread separate from your **Chat** history

The table records what is kept, not where or for how long. Settle those two in your contract review rather than assume them.

## Is what Insulin keeps just metadata?

No. Beyond routing data, five kinds of retained text come from the message or are derived from it, and a data inventory should record them as content:

-   **The subject line**, written by whoever sent the message.
-   **The preview line**, which is text from the message. Microsoft’s API reference defines Outlook’s body preview as the first 255 characters of the message body.
-   **An extraction**, which can hold a drafted reply’s subject and body.
-   **An AI draft**, a reply to the message, kept with its edit history.
-   **A thread summary**, which condenses the thread and exists only when you ask for one.

So the precise sentence for a security questionnaire is not “the assistant stores no email.” It is: _the full body is never stored; metadata, the provider’s preview line and AI output about the message are._ Every clause of that can be verified, which a blanket denial cannot.

## Which model works on your mail?

The first available one in your chain: your connected model providers first, Suger’s hosted models as the last resort. Never storing a body is not the same as never processing mail — classification, tagging, drafting a reply, summarizing a thread and building your writing-style profile are model work, and Inbox runs it on the same chain of candidate models the chat agent uses.

**Settings → Account → AI model** lists the providers Inbox can use — Claude Code, Codex, Anthropic, OpenAI and Gemini — and shows **Connected** or **Connect** for each. With none of your own connected, Inbox runs on Suger’s hosted models and the card says so. If your organization does not allow hosted models either, rules are not interpreted and no draft is produced.

Two more boundaries: the writing-style profile is used only for draft generation and never leaves your tenant, and Inbox only ever reads the knowledge bases you attach — it never adds to or changes one. Training is a separate question, covered in [whether your company data is used to train models](/blog/is-your-data-used-to-train-models/).

## What does Insulin write into your mailbox?

Very little, and the documentation states it as a limit:

-   **Drafts, on Gmail only.** Insulin mirrors each AI draft into your Gmail **Drafts** folder, creating it when the reply is generated, updating it when you edit, and deleting it when you send or archive from Inbox. Those drafts are the only messages Insulin creates in your mailbox. Outlook drafts are not mirrored.
-   **Labels and read state.** On mail you received, Insulin changes only labels and read state — never the message content — and it never deletes one. On Gmail, the labels your rules declare sync as real Gmail labels.
-   **Replies, only on your say-so.** A reply goes out from your mailbox when you press **Send** and confirm, or when an auto-send rule you wrote yourself fires. [When the Inbox app acts, and when it asks](/blog/when-the-inbox-app-acts-or-asks/) covers where that line is drawn.

## What should a security review record?

That the body is never stored, that every other row of the inventory is retained, and that five kinds of retained text are content — not “no email data.” Before you connect a mailbox:

1.  Classify the subject and preview lines, extractions, AI drafts and thread summaries as message content.
2.  Check which providers **Settings → Account → AI model** shows as connected, or whether Suger’s hosted models will do the work.
3.  Know the exit first: [what Disable and Disconnect do to your mail](/blog/disable-or-disconnect-a-mailbox/) walks through it item by item.

## Frequently asked questions

### Does Insulin store the full text of my emails?

No. Email bodies are fetched live from Gmail or Outlook each time you open a message, and the full body is never stored. Insulin does keep other items, including the subject, sender, the provider preview line and its own AI drafts.

### What does Insulin keep about each email?

The subject, sender, recipients and timestamps; the provider preview line; the labels applied; any structured extraction; the AI drafts and their edit history; a thread summary if you request one; and the rule-trace records that explain which rules ran.

### Is the preview line part of the message text?

Yes. It is the short preview your provider returns with each message, the Gmail snippet or the Outlook body preview, and it is what the mail list shows. Microsoft defines the Outlook body preview as the first 255 characters of the message body.

### Does Insulin change or delete mail in my mailbox?

It never deletes mail you received and never changes its content; on that mail it changes only labels and read state. On Gmail it also creates, updates and deletes its own AI drafts in your Drafts folder. Outlook drafts are not mirrored.

### Which AI model works on my mail?

Your connected model providers, in order, with the hosted models Suger provides as the last resort. Classification, tagging, drafting, thread summaries and the writing-style build all walk that chain. With no provider of your own connected, Inbox runs on those hosted models.

## Takeaways

-   The full body of an email is fetched live from Gmail or Outlook and never stored.
-   Never storing the body is not storing nothing: every other row of the inventory is retained.
-   Five kinds of that retained text are content. Classify them that way.
-   Storage is not processing: model work runs on your connected providers first and Suger’s hosted models last.
-   In your mailbox, Insulin creates only its own Gmail drafts, and on mail you received it changes only labels and read state.

An AI email assistant earns a mailbox connection by being exact about what it keeps. See how the [Inbox app drafts replies and labels mail for your review](/inbox-app/), while the full body of each message stays with your provider.

## Sources

Primary sources for the platform rules cited above. Last verified September 19, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.

-   [Suger docs: Inbox](https://doc.suger.io/insulin/inbox/) — Email bodies fetched live and the full body never stored; the per-message list of what is retained; the writing style, History and chat-rail records; what Insulin writes into a mailbox; the model chain Inbox work runs on; knowledge bases read-only
-   [Microsoft Graph v1.0: message resource type](https://learn.microsoft.com/en-us/graph/api/resources/message?view=graph-rest-1.0) — The bodyPreview property: the first 255 characters of the message body, in text format

## Keep reading

-   [TrustAI Model Allowlist: Which Vendors See Your PromptsSep 19, 2026](/blog/ai-model-allowlist/)
-   [SecurityLeast Privilege for AI-Built Apps: Whose Account?Sep 19, 2026](/blog/least-privilege-for-ai-built-apps/)
-   [SecurityDisable or Disconnect: What Happens to Your MailSep 13, 2026](/blog/disable-or-disconnect-a-mailbox/)
-   [Inbox AppWriting an Email Rule in Plain EnglishSep 13, 2026](/blog/writing-an-email-rule-in-plain-english/)

[Browse every post on the Insulin Blog](/blog/)

### Stay Updated

Get the latest Cloud GTM insights, product updates, and marketplace strategies delivered to your inbox.
