Can an email assistant work without access to your mailbox?
Published 12 August 2026 · 6 min read
Yes, an email assistant can work without any access to your mailbox. The mechanism is forwarding: you send one message to a dedicated address, the tool sees that message and nothing else, and it answers with whatever it can work out from that single email. What you lose is everything that depends on context across your archive. What you gain is that no third party holds a key to your account.
This article explains what a no-access assistant can and cannot do, why the permission question is worth taking seriously even for tools you trust, and how to evaluate any email product that asks you to connect an account.
What connecting an account actually grants
When you connect a mail account to a third-party product, you are usually granting a broad, standing permission rather than a narrow one. In practice that typically covers reading messages you have not chosen to share, keeping that access until you revoke it, and in many products the ability to modify or send on your behalf.
None of this is sinister, and the major providers have review processes for exactly this reason. It is simply worth naming clearly, because the consent screen goes past quickly and the mental model most people are left with is the tool can help with my email, when the technical reality is the tool can read my email.
The distinction becomes concrete in three situations that are common for the people this kind of tool is sold to.
- You handle client material under a confidentiality agreement, and that agreement did not anticipate a third-party service reading it.
- Your employer restricts which applications may connect to the company mail system, and the approval process takes longer than the problem you are trying to solve.
- Your inbox contains material about other people who never agreed to anything, which is true of essentially every inbox.
How the forwarding model works
A forwarding-based assistant gives you a private address that belongs only to you. You forward a message to it, the service receives it exactly as any other recipient would, and it processes that copy. Your original message stays untouched in your mailbox, because the service has no way to reach into your mailbox at all.
The important property is that this uses no special integration. Forwarding is part of the email standard itself, so it works from Gmail, Outlook, Fastmail, a company Exchange server or a client you have never heard of. Nothing has to approve it, and nothing breaks when a provider changes its API terms.
What it can do well
- Judge how urgent one message is, based on what is in it rather than on who sent it.
- State plainly what is being asked, which is more useful than it sounds for long or evasive emails.
- Produce a first draft reply you can edit, which removes the blank page problem.
- Work identically across every provider you use, including ones no client app supports.
What it genuinely cannot do
- Answer questions about mail you did not forward. There is no archive to search.
- Connect a message to a thread from six months ago, unless you forward that too.
- Sort, label, archive or delete anything in your inbox. It has no permission to modify anything.
- Do anything automatically. Nothing happens until you press Forward, which is a real cost and the main argument against this model.
That last limitation is the honest trade. A connected assistant helps with every message without being asked. A forwarding assistant helps only with the ones you choose. If you want coverage without effort, connected tools are the better answer and you should use one.
Automatic forwarding, and why it is a middle path
Most mail providers let you create a rule that forwards certain messages automatically, for example anything from outside your organisation that is not a newsletter. This recovers part of the automation without granting standing access, because the rule lives in your mailbox and you control it.
It is a genuine middle path, with one caveat worth stating: a broad forwarding rule sends more than you might intend, so it is worth writing the rule narrowly and reviewing what it catches after a week. The point of the model is that you decide what leaves your mailbox, and a careless rule quietly gives that decision away.
What happens to a message once you forward it
No access does not mean no data. The moment you forward a message, a copy of it exists on somebody else's servers, and that copy is subject to whatever retention, storage and deletion policy the service actually operates. A forwarding model narrows what a tool can reach; it does not make the question of storage disappear, and any provider that implies otherwise is overselling.
So the useful questions shift from what can you access to what do you keep. Is the message body stored after processing, or only the result? Can you delete an individual item yourself, from the interface, without emailing support? Does deleting your account remove the content immediately or on some later schedule? Is content excluded from model training, and is that stated in the terms rather than in marketing copy?
These are answerable questions with short answers, and a provider that gives you vague ones is telling you something. It is also worth checking who else is involved, because every service of this kind runs on somebody else's infrastructure: a mail provider that receives the forwarded message, a model provider that processes the text, a database host that stores the result. Three companies is normal. Not being able to name them is not.
How to evaluate any email tool that asks for access
Whether or not you use a forwarding-based product, these questions are worth asking of anything that wants to connect to your mail. They take five minutes and they are the difference between an informed decision and a reflex.
- What exactly is being requested: read only, or read and modify and send?
- Is the access limited to messages you select, or standing across the whole account?
- Where is message content stored, for how long, and can you delete it yourself?
- Is your content used to train models, and is the answer written down somewhere binding rather than said in a blog post?
- What happens to stored content when you cancel: is deletion immediate, delayed, or manual?
- Who is on the subprocessor list, since the answer is never just this one company?
A product that answers all six plainly is usually safe to trust regardless of its access model. A product that cannot answer them is a risk even if it asks for very little, because the questions are about operational care, not just permissions.
Choosing between the two models
Pick a connected assistant if you want help on everything, your archive is where the value is, and the access question is not a constraint in your work. That is a completely reasonable position and covers most people.
Pick a forwarding assistant if the access itself is the obstacle, whether because of a client contract, an employer policy, or a simple preference not to hand over a standing key. Accept in exchange that it only ever sees what you send it.
CatchTheMail is built on the second model, for the reasons above: you get a private forwarding address, and each message you send comes back with a priority score, a summary of the actual request and a reply you can send. It cannot touch anything in your mailbox, which is both the strongest thing about it and its clearest limitation.
About the author
Kadir Yenitürk builds CatchTheMail, an email assistant that works by forwarding and never connects to your mailbox. He writes about the parts of email work that tools usually ignore.
Keep reading
Forward one email and see what comes back
No mailbox connection, no install. Free for 7 days, and no card is required to start.
Try CatchTheMail