There are two shapes of answer and they have very different consequences. The common one is to grant a hosted assistant OAuth access to your mail provider, or to forward your inbox to it, which means a third party holds a copy of your mail indefinitely and a breach of their systems is a breach of yours. The other is to read the accounts already configured on your machine, in place, with nothing copied anywhere. Grux OS does the second: Mailbox talks to your IMAP server directly, Calendar and Contacts use the macOS system permissions for the accounts already on the Mac, and there is no Grux server for a copy to live on. Your credentials go to the macOS Keychain and are sent only to the provider they belong to.
| Surface | Talks to | Needs |
|---|---|---|
| Mailbox | Your IMAP server, directly | IMAP details |
| Calendar | The calendars already on your Mac | The macOS Calendar permission |
| Contacts | The contacts already on your Mac | The macOS Contacts permission |
| Notes and Documents | Files on your disk | Nothing |
| Compose and send | A sending provider you configure | A Resend key, plus IMAP |
Mail, calendar and contact access reach the model as tools rather than as a dump of your data. A tool call fetches what the turn needs and nothing else, so a question about one meeting does not put a year of your calendar in a prompt.
The case it was built for is the one where a vendor mail needs a reply, a date and somebody's number. Mailbox, Calendar and Contacts are three rows apart in one sidebar, pointed at your real accounts, so that is one turn instead of three applications.