Changelog
What changed, and when.
Taken from the project’s own history. Sortmail is pre-1.0, and the top entry is work not yet released.
In progress: Outlook, real labels and reasons you can see
- Outlook mailboxes — Outlook.com and Microsoft 365 — alongside Gmail.
- Categories are filed into labels in your own mailbox, named Sortmail/ and the category; on Outlook, categories of the same name, with filed mail moved to the Archive folder.
- Messages that need you show why they are there, on the row.
- Moving a message saves a rule for that sender, and a later correction for the same sender replaces the earlier one.
- Move anything in Gmail and Sortmail learns: swapping one Sortmail label for another in any Gmail app is the same correction as making it here. Outlook moves are not read back yet.
- A free preview: your recent mail sorted, with reasons, before anything in your mailbox changes.
- Payments moved to Stripe, with renewal reminder emails before each renewal.
- Daily digest at the hour you choose, in your own time zone, showing what was filed and why: how each filed message was decided, and which ones to check.
- After you subscribe, the mail your preview sorted is moved into its categories.
- Renewal reminder emails before every renewal: 21 days before a yearly one, 3 days before a monthly one.
- Disconnecting a mailbox revokes the permission at Google and deletes the stored token.
- Public guides, a permissions page and the sub-processor list.
Real sign-in, billing and the database
- Sign-in by emailed link, and the Google connection flow.
- Account deletion wired to the purge.
- Hosting set up so the web servers can encrypt mailbox tokens but not decrypt them; only the worker can.
The worker
- The background service that syncs, classifies, re-sorts, sends the digest and purges deleted accounts.
- Gmail is asked for headers only unless you turn on reading message text.
Gmail, and one place for prices
- The Gmail connection, signed in through Google.
- Founding and list prices, with the founding cohort capped and the cap enforced in code.
The rules the product keeps
- Strict checks on every request and background job, so a message body cannot ride along.
- Mailbox tokens encrypted with a key per mailbox.
- The daily digest, built from counts and sender domains only.
- The fair-use rules: new mail is never limited.
- Account deletion that purges everything within a day.
Pages that load
- Fixed a content security policy that blocked the app’s own scripts.
- Buttons that called routes which did not exist yet now say so instead of failing.
Foundation
- Every page of the site, the sign-up flow and the app, in their first form.
- A database with no column for a message body, and a test that fails if one is added.
- The legal pages: privacy, terms, data processing, fair use and security.