Guide

How do I get documents that arrive by email into a vault without forwarding them to a company?

How do I get documents that arrive by email into a vault without forwarding them to a company?

Use a document app that signs in to your mailbox from your own device rather than one you forward mail to. Give it the IMAP server, your address, an app password and a folder, and it connects over TLS straight to your provider, files the attachments of new messages and marks them read. Nothing passes through the vendor, so the mail stays between you and your email provider — which is the difference between a mailbox you have connected and a mailbox somebody else now holds a copy of.

Most of the documents worth keeping arrive by email. The insurance renewal, the tenancy agreement, the invoice, the boarding pass. They sit in an inbox where they are safe from nothing and findable by nobody, and the step everyone skips is the one where you save the attachment somewhere it will still be a year from now.

The usual answer from a document vault is a forwarding address: send your mail to you@theircompany.com and it appears in the product. That works, and it means the company now holds your mail on a server of theirs, in a form they can read. For a product whose entire claim is that it cannot read your documents, that is not a feature — it is the claim, gone.

So Keepsake does it the other way round. The app on your device signs in to your mailbox and takes the attachments out. Nothing of yours passes through anything of ours, because nothing of ours is involved.

What you need before you start

Three things, all from your email provider rather than from us:

  • The IMAP server name — imap.gmail.com, outlook.office365.com, imap.fastmail.com, or whatever your provider publishes. It is on their help page under "IMAP settings".
  • Your address, which is usually the username as well.
  • An app password, if your provider issues them — Gmail, Outlook, Fastmail, Yahoo and most others do, and several now require one. It is a password that works for one program and can be revoked on its own, without changing the password you sign in with. That is exactly the right shape for this, and it means revoking Keepsake's access is a setting in your mail account rather than a request to us.

There is no port to choose. It is 993, which is IMAP inside TLS from the first byte, and the app refuses any other port before it opens a socket. The alternative — port 143 with STARTTLS — begins the conversation in plaintext and upgrades, and there is no version of "we tried to upgrade and could not" that is safe to continue from. So the whole ladder is missing rather than optional.

What it will and will not do

The complete list, and it is short on purpose:

It doesIt does not
Sign in to the one host you configured, over TLS, from your own device.Contact any other host, ever — including ours.
List unread messages in the folder you chose.Read messages you have already read, or messages in other folders.
File the attachments of a message.Read, store or index the message body. It reaches no field of any document.
Mark a message read once its attachments are filed.Delete, move or alter anything. There is no delete command in the client at all.
Tell you what it skipped and why, message by message.Drop anything quietly.

The password is held by the operating system's own secret store — Windows DPAPI on the desktop, the Android Keystore on the phone. It is not in the vault, and it is not in anything that syncs, so a copy of your vault taken to another machine does not carry your mail credentials with it.

The messages it leaves behind, and the reason each one is given

A check that filed three of seven attachments and said nothing would leave you believing all seven arrived. So every message it does not file is listed, with the reason:

  • Not from a sender on your list. If you named senders, everything else is skipped and stays unread.
  • Too large. Refused from the size the server states, so it is never downloaded in order to be discarded.
  • No attachment. A message with nothing to file is said to have nothing to file.
  • Left for the next check. There is a cap on how many messages one check will bring down. Anything past it is not dropped — it is still unread, and the next check takes it.
  • Refused by type. The attachments themselves go through the same allow-list every other import uses: programs, archives and macro-enabled documents are refused by name, and so is statement.pdf.exe.

The order matters and is deliberate: sender first, then size, then attachment, then the count. Reversed, twenty signature logos from a newsletter would push out the one real invoice.

Where a document says it came from

Every document filed this way is stamped with the mailbox, the folder, the sender and the date it arrived — written onto the document itself, so that a year later the answer to "where did this come from" is on the document rather than in somebody's memory.

Note what that sentence does not say. It records the provenance; it does not claim the document is genuine. An email is not proof of anything, and a vault that implied otherwise would be lending its credibility to whoever sent the message.

What happens when it stops working

Sooner or later a password changes, an app password is revoked, or a provider moves a server. When that happens the check counts the failures and, after a few, stops itself and says so instead of continuing.

That is not politeness. An application that presents a wrong password to a mail server every half hour is how an account gets locked — and the account is yours, not ours. Saving the settings again is what clears the count and starts it going, which is also the moment you have fixed whatever the message told you was wrong.

Step by step

  1. Open the mailbox settings. On Windows: Settings, then the "Mailbox — check an inbox for documents" section. On Android: Settings, then Mailbox — check an inbox.
  2. Fill in the server, your address and an app password. The folder defaults to INBOX. The interval defaults to every 30 minutes and can be anything from 5 minutes to a day.
  3. Optionally, name the senders you want documents from. One per line. An entry starting with @ matches a whole domain and its subdomains — @aviva.co.uk takes mail from anywhere at Aviva. Leave it empty and everything in that folder is considered, which is a reasonable default because you also chose the folder.
  4. Press Check now. The first check tells you what it filed and lists every message it did not, with the reason. If the sign-in is refused, the message says so in the same words on both platforms.
  5. Leave it running. From then on it checks on its own schedule while the app is running and your vault is unlocked. A check that is skipped is not a check that is lost: the messages are still unread and the next one takes them.

Questions

Is this the same as connecting my Gmail account?

No. There is no OAuth prompt, no token held on a server of ours, and no account of yours linked to anything of ours — because there is no server of ours in this at all. The app on your machine opens a TLS connection to the one IMAP host you named. Revoking it is done in your mail provider's settings, by deleting the app password, and takes effect immediately.

Can I forward documents to a Keepsake address instead?

There is no such address, and there will not be one on these terms. A forwarding address means a server of ours receiving and holding your mail in a form we can read, which is the single thing this product exists to avoid. The mailbox check is the same job done from the other end.

Does it work in the web app?

No, and it is a deliberate absence rather than an unfinished feature. A browser cannot open a raw connection to a mail server, so a web version would have to route your mailbox credentials and your mail through a server of ours — which is exactly the design we rejected. On iPhone and in the browser, saving the message as a file and importing it does the same job with nothing in the middle.

Will it delete or move my email?

It marks a message read after its attachments are filed. That is the entire list of changes it can make: there is no delete and no expunge command anywhere in the client, which is how that promise stays true rather than being a policy someone could change.

Does it read my emails?

Only the four headers it needs to decide — who sent it, the subject, the date, and whether it has attachments — and then only the attachments themselves. The body is never read into any field of any document, and the test suite plants a marker string in a message body and fails if it appears anywhere in the vault.

What about two-factor authentication?

That is what an app password is for. Your account keeps its second factor for you signing in; the app password works only for mail programs, only for this, and can be revoked on its own.

Where Keepsake fits

Keepsake is our product, so read this part with that in mind. Everything above is true whether or not you use it, and most of it you can do with a folder and an afternoon.

A message the check fetches is written out exactly as a saved .eml would have been and handed to the same importer that reads one you dropped in yourself. So both paths file documents by identical code, with identical caps and identical refusal wording — see getting documents in for the other ways a document arrives, and importing a folder for moving a whole archive at once.

What decides all of it lives in one file, shared/mailbox-poll.json, which the Windows app and the Android app both read. That is why the two describe the same limits in the same words, and why a refusal reworded once is reworded everywhere.