Version history
Every released version, newest first. The newest versions are also listed, with more detail on the code, in the change log.
- v0.65: Help is one click away. Wherever Enveliq asks you to set something up, there is now a link to the step-by-step guide on GitHub, which opens in a new tab: first-time setup, unlocking, two-factor sign-in, adding people, the AI model, connecting a mailbox (Gmail, iCloud, Yahoo, Outlook and Microsoft 365, Proton Mail), Google Calendar and other calendars, reminders, the Hermes agent, reporting, single sign-on, writing help, and the warning that shows when a page is not encrypted. Pointers that used to say "see docs/... in the Enveliq folder" are now links. A setup code that is still the placeholder from the install file, or shorter than 16 characters, is ignored and a random one is made instead.
- v0.64: Writing help. The reply box and the New email box get a button: Write a reply for me when the box is empty, Check my reply when you have written something. The AI reads your words and, for a reply, the email you are answering, and shows its suggestion in a separate box labelled Suggested by AI that says nothing in it is sent. Accept copies it into your box (with Put my version back), or you can select just the parts you like and copy them across; Try again and Copy are there too. What is in your own box is what gets sent. If you used writing help on a message, pressing Send first shows a short check with the exact text, and warns about any gap left in [square brackets]; ordinary replies are not slowed. It is off until you turn it on in Settings, AI instructions, where a box of plain, friendly default writing instructions is ready for you to keep, change or add to. Administration, Features has a Writing help switch. Nothing the AI sees or writes is stored or logged. See docs/WRITING_HELP.md.
- v0.63: Administrators can edit saved shipping carriers. In Shipping, under Carriers Enveliq can link to, an administrator now sees Edit next to each shared carrier and can fix its name or tracking-page address (the same address rules as when adding). Everyone else sees no change.
- v0.62: Shipping: Track all, Copy number and carriers you can add. When two or more parcels are on their way, Track all opens each one in its carrier's own page (if only one opens, allow pop-ups for Enveliq). Every parcel with a tracking number has a Copy number button. The built-in carrier list grew (Couriers Please, TNT, DPD, Evri, Yodel), and when a parcel's carrier has no link, Add this carrier lets anyone teach Enveliq its tracking page: paste the address from the carrier's website with
{number}where the tracking number goes (or type the parcel's number and Enveliq finds it). A carrier added by one person is available to everyone; the person who added it, or an administrator, can remove it. Enveliq still never contacts a carrier: your own browser opens the page. - v0.61: Messages between people. People who share one Enveliq can now write to each other: one to one, or in a small group (up to 8 people). Messages appears in the sidebar with a blue count when something is waiting, and Home shows a card such as "Beth and Sam left you 2 messages" with a Read messages button. On a phone the list and the conversation are two separate screens. Each conversation can be muted, and you can unsend your own message. Only the people in a conversation can open it; anyone else, an administrator included, is told "Not found". What other people see of you is your name and picture. Profile has a new switch, Show me in the people list, and Administration, Features has a Messages on/off switch (people can also switch it off for themselves). Plain text only, up to 2,000 characters. Not in this version yet: the shared board, keeping messages for a set time, and "tell me about new messages" reminders. See docs/MESSAGES.md.
- v0.60: The Enveliq icon is back on the browser tab. The inbox page now names its tab icon (and the home-screen icon for phones), so the tab shows the Enveliq logo again instead of a blank page symbol.
- v0.59: A tidier menu, Profile settings and password rules. Light mode, Settings and Administration now live in the menu that opens when you click your name (only Agent stays in the sidebar), with a new Profile settings item. The Profile page is all optional: name, email address, a line about you and a small round picture (shrunk on your device, checked on the server, kept encrypted; other people can only ever see your name, picture and that line). Administration, Sign-in rules has a new Password requirements card (minimum length, how many numbers, capital letters, small letters and symbols, and whether the username may appear in the password); the change-password and add-person boxes tell people the rules in plain words. Settings and Administration were reorganised into clear groups (You, Your mail, How it works for you, Help / People, Mail, AI, System), long pages fold their detail away, and the demo-only pages that did nothing in a real install were folded into one Security & privacy page. Plan for messaging between people: docs/MESSAGES.md.
- v0.58: Sidebar numbers for Shipping and Waiting for reply. Each now shows how many it is following (for example 5 orders, or 2 emails waiting on an answer) instead of an empty dash, and nothing is shown when there are none. The number turns blue when one of them needs you (an order to confirm arrived, or a reply nobody has sent).
- v0.57: A slow agent no longer times out. Your main Hermes agent can take a minute or two to answer when it uses its tools, which is longer than a reverse proxy waits (that showed as "Request failed (504)"). The Agent chat now sends your message at once and keeps checking back until the agent has answered; the answer appears by itself, a failure is shown on the chat with what you typed kept, and coming back to a chat that is still being answered picks it up. The Test the agent button works the same way.
- v0.56: Chat with your main Hermes agent. Administration, Agent chat has a new optional Use a different agent for this chat section (address, model name, access key and a Test the agent button), so the Agent button can talk to your main Hermes agent with all its tools (Home Assistant, pfSense, Grafana) while email summaries keep using the plain model. Guide: docs/AGENT.md.
- v0.55: Settings and Administration work on a phone. They open as a full-screen sheet, and the sections (My email accounts, Sign-in & security, Users, AI model, Features and the rest) sit in a row along the top that you swipe sideways, instead of a side list that was squeezed off the screen.
- v0.54: No scrolling behind panels. While Settings, the mobile menu, the view panel, compose or a viewer is open, the page underneath no longer scrolls when you swipe or use the mouse wheel, even when the panel itself has nothing to scroll.
- v0.53: Refresh keeps your place. Pressing refresh now leaves you on the same page (inbox, Sent, Tasks, Shipping, Waiting for reply, Reviewed, Archived, or an open Settings or Administration section; the address bar shows it after #/) and keeps any emails you had expanded open (remembered by this browser tab only). A small, quiet Expand all / Collapse all link sits next to the Filter on the inbox. Shipping: an email listed under "emails matched" becomes a link that opens it in your inbox when it is still there (it stays plain text when it is gone); every order has a Note button for your own words ("new headphones", up to 500 characters, kept with the order and never changed by later emails); and the AI is asked for a fuller description of what the order is for (brand, model, colour, quantity) and the order total, shown on the card.
- v0.52: Waiting for reply. Enveliq follows the emails you sent that ask for something. It is off until you switch it on for a mailbox (Settings, My email accounts, Turn Waiting for reply on), because to judge a sent email the AI model has to read it: if that model is a cloud service, the text goes to it. It only looks at emails you send after you switch it on. What is already in Sent is never read, so a big Sent folder costs nothing. Each new sent email (Proton, Gmail, your phone, anywhere) is shown to your AI model once, and if you are waiting on an answer a short note is kept (who, subject, date, one line saying what you are waiting for), never the email. To follow an older email, open Sent, expand it and press Follow for a reply. A reply in your inbox on the same thread closes the note by itself. After 3 days with no reply (1 to 14, set on the page) an amber "Waiting on others" card appears on Home with Write a nudge (opens New email, addressed and started for you), Got a reply, Ask again in 3 days and Not needed. The new Waiting for reply page lists every note and has Check my sent mail now. Closed notes are forgotten after 7 days, unanswered ones after 30. Replies are spotted from the inbox, so one deleted before it was checked will not close a note; press Got a reply.
- v0.51: Shipping. Enveliq follows your online orders from the emails you get. The same AI summary that reads an email also says whether it is about an order or a delivery (confirmed, shipped, out for delivery, delivered, delayed) and picks out the shop, order number, carrier, tracking number, expected date and the items in a few words. Emails are joined to one order by order number, then tracking number, then the shop's only open order; if there is nothing to go on it asks "Is this an order?". A later date shows as Delayed. The new Shipping page (under Tracking in the menu) shows each order with a progress line and a Track button that opens the carrier's own page in your browser; Enveliq never contacts a carrier. When an order is delivered, a teal card on Home asks "Did it arrive?": Yes, I've got it clears it, Not yet asks again tomorrow. Arrived orders are forgotten after 14 days. Only the facts are kept, never the email. There is a switch for it in Administration and in Settings. Orders are found from new summaries only, not emails summarised before this version. Next: Waiting for reply (v0.52).
- v0.50: Unsubscribe button. Newsletters show an Unsubscribe button on the email and in View original email, so you never hunt for the link at the bottom. Enveliq reads the sender's own List-Unsubscribe header, and in View original also looks for an "unsubscribe" link in the text. Pressing it opens the sender's page in a new tab from your own browser; Enveliq never opens it for you. Links that point inside a home network, or anything other than a plain web address, are ignored.
- v0.49: Updates without building on the server. After every push that passes all the checks, GitHub publishes both images to your private package store (
ghcr.io/<you>/enveliqandenveliq-render, taggedlatest, a version and a commit). Your server only pulls and redeploys, for example with one press in Arcane. Setup is in docs/DEPLOY.md. Building on the server still works. - v0.48: Phone fix for pop-up windows. On a phone, View original email, Reply, New email, pictures and documents now open as full-screen sheets with a large Close button that stays in view (the top bar used to cover the old Ă— and it was too small to tap). The phone's Back button closes View original instead of leaving Enveliq. A new browser check covers it on two phone sizes.
- v0.47: Use your own agent in the chat. Administration, Agent chat lets the Agent button talk to your own agent (for example Hermes) as itself, with its own instructions and tools, instead of Enveliq's short helper instructions. You can keep it to administrators only and rename it. Enveliq still sends it only what you type, never your email, tasks or settings.
- v0.46: Hermes chat. An Agent button above Light mode opens a chat popup where you can talk to your AI model (for example Hermes). It is plain chat only: it sees what you type and nothing else (no email, tasks or settings) and cannot change anything. Chats are saved, encrypted for each person alone, with a Chats list to reopen, rename or delete them and a + New button for a fresh conversation.
- v0.45: Tasks Calendar view (a month grid beside Focus and List). Google Calendar, instantly: Enveliq can write to a Google calendar of its own through Google's API (an administrator registers a free OAuth client once; see docs/CALENDAR.md), so a finished task leaves Google at once instead of after the link refreshes. An email with an open task now stays in Enveliq (past 14 days, or after being read elsewhere) until the task is done or removed. The Today card follows the page width setting.
- v0.44: Browser pop-ups and Email reminders, and Calendar & To-do. Reminders can also pop up on this phone or computer (Web Push, end-to-end encrypted) or arrive as an email to your own mailbox. Calendar & To-do: Tasks can go to a calendar and follow the task: a private calendar link any app can subscribe to (Google and Outlook refresh it only every few hours), an instant CalDAV connection (Nextcloud, Radicale, Baikal, Fastmail) that adds, moves and deletes events within a minute, and a Home Assistant To-do list that adds, ticks off and removes items and finishes the task here when you tick it there. Done, removed, replied-to or dealt-with tasks leave the calendar. Guide: docs/CALENDAR.md. The old mock Home Assistant task toggles are gone.
- v0.43: Tasks make themselves. When an email's summary says something needs doing, a task is made with no button to press, dated from the summary (no date means today). A Today card at the top of the inbox (replacing the yellow due bar) shows up to three things; a new Tasks page has Focus (one task at a time: Open the email, Done, Not today, Move) and a normal list. Move is one tap (later today, tomorrow morning, this weekend, next week, or a day). Missed tasks roll into today and say "Waiting since Tue", never "overdue". A task ends by itself when you reply, press Reviewed, Archive or Bin, or the email leaves your inbox, and says why for a day and a half. Tasks belong to one person. Reminders can also go to ntfy, Gotify, Home Assistant, Discord, Telegram, Slack, Pushover, Matrix or any webhook: a morning summary, a reminder when something is due, gentle nudges, quiet hours and a private mode that hides titles. Set up under Settings, Reminders; step-by-step guides in docs/NOTIFICATIONS.md.
- v0.42: Blue counts in the sidebar are hidden when they are zero. Clicking "N need you" under the Inbox heading shows just those emails (new "Needs you" choice in Filter). Deleting, archiving or marking several emails now shows a short fixed label on the button instead of a changing count that wrapped onto a second line.
- v0.41: PDFs are now drawn by their own locked-down container (
enveliq-render): private network with no internet, read-only, no access to your data or keys. The main container no longer contains a PDF parser. When you update, build both images (see docs/ACCESS.md):docker build -t enveliq:local . && docker build -f Dockerfile.render -t enveliq-render:local ., and make sure your Arcane project uses the newdocker-compose.yml. - v0.40: an All emails switch beside Sort (administrator and per-person switches). It also lists mail you have already read, for the last 14 days (newest 100), as quiet one-line entries; unread mail gets a blue dot and tint, and switching it off returns the inbox to the normal design. Opening an entry shows "Summary not generated" with a Generate summary button; requests wait in a server-side line, one at a time, and survive a refresh.
- v0.39: PDFs and text, CSV and JSON attachments can be viewed in the page (View button) without downloading. PDFs are drawn as page pictures by a limited helper process on the server (poppler is now part of the Docker image); the PDF itself never reaches the browser. Word, Excel and PowerPoint files still need Save to my device.
- v0.38: Undo on a new email now brings back its attachments as well as the recipients, subject and text.
- v0.37: optional email features. New email with an address book (names and addresses from mail you read and write, plus vCard import and export), Sent (read-only, last 14 days, never stored), and pictures and attachments on demand (shown from memory, never stored, remote pictures still blocked). An administrator switches each feature on or off (Administration, Features) and each person can switch off any feature for themselves (Settings, General settings). Also: Undo send, a Replied marker, legal pages and a footer, and a light/dark switch on the sign-in pages.
- v0.36: opening Enveliq by IP address and port on a trusted network, with no SSH tunnel or reverse proxy, is now a documented opt-in (
docs/NETWORK_ACCESS.md); every email in the inbox is one thin row (sender, subject, summary, time, a Reviewed button); click anywhere on a row to open the full card with Reply, Archive, Bin and View email. A small amber dot marks mail that needs action, and the header shows a count for the view. the Setup guide in Settings is for everyone and has no AI summaries step (administrators choose the AI model in Administration, or in the first-run guide). the Microsoft setup guide on the Administration page, Microsoft sign-in, is a plain numbered list that fits any width. Until an administrator saves it, Outlook shows as not available under Add a mailbox and points to that page. - v0.35: Outlook, Hotmail and Microsoft 365 mailboxes. Microsoft only allows its own sign-in page, so an administrator registers their own free app once (shown with every step and the exact redirect address when an administrator chooses Outlook under Add a mailbox; full guide in
docs/MICROSOFT.md). People then press Sign in with Microsoft; mail is read and sent with a token that is kept encrypted and never shown. No registration is built in. - v0.34: The Grafana dashboard no longer needs Prometheus. With only a Loki data source chosen, Enveliq installs a dashboard drawn from its event logs; adding Prometheus later and installing again swaps in the full one.
- v0.33: Reporting page tidied: each output is a tick box that shows only its own settings. New OpenTelemetry push (Enveliq sends the same numbers to Grafana Alloy on a timer, no scrape job or token needed), and a Grafana connection using a service-account token: one button installs or updates the built-in dashboard in a folder (data sources chosen from a list or typed), and key events (vault locked or unlocked, AI changes, a mailbox failing and recovering) appear as markers on the charts. See
docs/REPORTING.md. - v0.32: Reporting for Grafana and others (Administration, Reporting). Four outputs, each off until switched on: Prometheus metrics at
/metrics(access token), JSON log lines on the container output, Loki push (Loki, Grafana Alloy or Grafana Cloud) and a signed JSON webhook. Counts, timings and security events only, never email content. Includes an importable Grafana dashboard and alert rules; seedocs/REPORTING.md. - v0.31: More AI choices. Administration, AI model now has an AI service picker: local servers (Ollama, LM Studio, llama.cpp, vLLM, other) and cloud services (OpenAI, Anthropic, Google Gemini, OpenRouter, Groq, Mistral, xAI, DeepSeek, Together AI). A cloud service needs an access key and a ticked confirmation that email text is sent to that company; it is only contacted at its own fixed https address. Anthropic uses its native API.
ENVELIQ_LLM_PROVIDERselects a cloud service from the server's environment. - v0.30: The built-in AI prompt is now visible to administrators (Administration, AI instructions) and can be replaced after ticking a box that says the change is at their own risk. The reply format and the rule to ignore commands inside an email are always added after any prompt, so a custom one cannot remove them. A "Custom prompt in use" badge and a Restore button are shown, and the extra-instructions box still works on top of either prompt.
- v0.29: Reviewed and Archived lists now work: what you mark Reviewed or Archive still changes your real mailbox at once, and Enveliq keeps its summary card in the Status lists for a few days. General settings (every user) switch each list on or off and set how long (up to an administrator's maximum, set under Administration, Reviewed & Archived). New AI instructions: an administrator's instructions for every summary plus each person's own additions. The Mailboxes page shows only the mailboxes; the email list moved behind a Diagnostics button. Only administrators see the AI step of the setup guide. Reviewed, Archive and Bin buttons show "Working…" at once.
- v0.28: Optional vault key, for single sign-on setups that do not want a second password after each restart. Make one with
openssl rand -hex 32, put it in.envasENVELIQ_VAULT_KEYbefore the first start, and Enveliq unlocks itself; setup then asks for no passphrase. A key file outside the data volume is the stronger alternative, and an existing vault switches with one command. Seedocs/VAULT_KEY.md. - v0.27: One place for settings. The inbox sidebar has Settings (personal: email accounts, sign-in & security, setup guide, preferences) and, for administrators, a separate Administration pop-up (users, sign-in rules & SSO, AI model, automatic sync and the rest). Both show the real pages inside the pop-up, so there is no second set of settings under your username; that menu now only has Sign out. The standalone pages still exist for sign-in, first setup and direct links, with a shorter top bar.
- v0.26: Automatic sync. Every 10 minutes (an administrator changes it, or turns it off, under Administration, Automatic sync;
ENVELIQ_SYNC_MINUTESoverrides it) the server fetches new unread mail for each mailbox, summarises it if AI is on, and forgets items handled elsewhere; each mailbox can switch it off on the Mailboxes page, which also shows how the last automatic check went. It runs only while Enveliq is unlocked and never counts as activity, so the idle lock still locks it on time (automatic sync then pauses until someone unlocks). A brand-new install opens the setup guide once. The inbox re-reads its list every minute. Fixed unreadable buttons in the add-mailbox sign-in popup, which now follows light and dark mode. - v0.25: Connect Gmail, iCloud Mail, Yahoo Mail, Fastmail and any other IMAP service with an app password, beside Proton Mail Bridge. The setup guide and the Mailboxes page now start with a choice of email service and show that service's own steps for getting an app password (Outlook and Microsoft 365 are listed with the reason they cannot be connected, because Microsoft allows only its own sign-in screen). Any number of mailboxes can be connected. New services are added in one place on the server (
backend/mail/providers.py). Connections are encrypted with the server's certificate checked, to public servers on standard ports unless the administrator lists a server inENVELIQ_MAIL_ALLOWED_HOSTS. The inbox has a Sort menu (newest, oldest, priority, sender) and, with two or more mailboxes, a mailbox filter. See docs/EMAIL_SERVICES.md. - v0.24: Setup guide at
/welcome(also in the menu): three steps (connect Proton Mail, choose AI summaries, first sync) with a plain-language explanation of every field, a test after each step, and advice for each kind of failure. The AI model can now be set up in the app by an administrator (address, model name, optional key), tested with a made-up email before it is saved; the key is stored encrypted. Sync also fills in the date of older items, so every card shows when it arrived. Inbox cards: the time and the View email button share the same right margin, matching the left. The sample banner points new people to the guide. - v0.23: Sync now drops items you have since read, archived or deleted in another app (only Enveliq's saved summary is removed; the mailbox is never changed, and nothing is removed if Bridge reports a reset mailbox). Light and dark mode, with a toggle in the sidebar above Settings; the choice is remembered in your browser and also applies to the sign-in and Mailboxes pages. "View email" buttons now line up, and sender names are no longer bold.
- v0.22: Inbox cards no longer show category, priority, "action needed" or mailbox tags (the AI still stores them for later). "View email" text is tidied: invisible padding characters, lines of spaces and long runs of blank lines are removed, and text-direction control characters are stripped. Fixed a stray "null" under the sync result on Mailboxes.
- v0.21: AI summaries from a model you run yourself (any OpenAI-style chat server on your network). Each synced email gets a short summary, category, priority, "action needed" flag and suggested task. The email text is read on demand, sent only to your model and discarded; only the short result is stored. Off unless the server is configured (
ENVELIQ_LLM_URL,ENVELIQ_LLM_MODEL) and the mailbox owner switches it on. Sync now / Sync mail summarise new emails. Test it withpython -m backend.mail.llm. - v0.20: The Inbox page shows your real Proton mail instead of sample emails, with a Sync mail button and the same View email, Reply, Reviewed, Archive and Bin actions (these change the real mailbox). Emails keep the date they were sent. Fixed a stray "nullnull" under the original in the Mailboxes viewer.
- v0.19: Proton Mail Bridge connection. Pinned Bridge certificate, sync of unread mail headers, view of the original email as plain text, replies that keep alias addresses and send from the right identity, and archive/bin/mark-read in the real mailbox. New Mailboxes page, a command-line connection check, a Docker network and forwarder guide (
docs/PROTON_BRIDGE.md). - v0.18: Automated checks in GitHub Actions on every push (tests, browser checks, Docker build, dependency scan) and weekly Dependabot updates. Security update: Starlette 1.6.0, FastAPI 0.141.1 and pyasn1 0.6.4 fix advisories the first scan found.
- v0.17: Standalone server with its own sign-in. Accounts with passwords, authenticator-app two-factor, passkeys and recovery codes; single sign-on with Authentik, Authelia and other OpenID Connect providers, including automatic account creation and group-based administrator rights; administration of users, sign-in rules and SSO; first-run setup code; unlocking the vault no longer signs anyone in. Sign-in pages served by the server under a strict Content Security Policy. Docker image and compose file. The development identity and
ENVELIQ_DEV_MODEare gone. - v0.16: View the original email from any review item (fetched on demand, shown as text with remote images blocked, never stored). Reply from inside Enveliq with alias-aware addressing: replies go to the Reply-To/From address exactly as received (so Proton Pass and SimpleLogin reverse aliases work), and come from the address the email was delivered to when the account can send from it. The prototype simulates sending; real sending arrives with the provider adapters. Backend stores an encrypted reply context and message locator, with header-injection checks.
- v0.15: Cleaner layout. The top bar now holds only the page title and search. Settings and the user switcher moved to the bottom of the sidebar, separate from the mailbox views. An arrow on the sidebar edge collapses it to an icon rail, with the EQ logo in place of the wordmark; on phones the sidebar is always the icon rail.
- v0.14: Removing an email account is now easy to find: a Remove button in the account list, a Remove account button at the top of every account's settings, and a removal section on the Overview tab. One confirmation, then the account and its review items are deleted (email at the provider is untouched).
- v0.13: Full security review. 19 findings fixed, including script injection from email content in the UI, a production mode that still used the development identity, rate-limit bypasses, and account disconnect never actually deleting data. Each is covered by a new regression test (37 tests in total). The backend now refuses to start without
ENVELIQ_DEV_MODE=1, Argon2id comes fromcryptography(argon2-cffi removed), and the default data folder moved from/tmp/enveliqtodata/. Details in SECURITY.md. - v0.12: Rebranded as Enveliq: logo, tagline and blue palette in the prototype; all code, settings and documentation renamed. Environment variables now start with
ENVELIQ_instead ofINBOX_. The vault's encryption labels changed, so a local development vault made with v0.11 or earlier must be deleted (data/vault.sqlite3) and set up again. - v0.11: Prototype published as a hosted live preview page. Sample data replaced with fictional examples. The vault panel uses the real backend when one is serving the page, and otherwise simulates the vault in the page (the passphrase is never sent anywhere). Repository reorganised.
- v0.10: Account-management tab strip keeps its scroll position.
- v0.9: Continuous-scroll PDF preview; Home Assistant script/notify notification targets.
- v0.8: Attachment architecture: RAM-only preview leases, encrypted provider locators, purge on resolve.
- v0.7: Secure backend foundation: Argon2id + AES-256-GCM vault.
Attachment handling in v0.8
The attachment design is intentionally disk-averse. Original attachment bytes are not written to the application database or data directory. During processing they are handled by a future isolated RAM/tmpfs worker. The browser viewer requests a safe rendered derivative on demand; a bounded in-memory preview lease may keep that derivative for up to five minutes, then it is zeroed/evicted.
When a message is Binned or expires, the backend resolve endpoint removes the retained encrypted message record and its encrypted attachment metadata/summary and purges any active preview leases. Reviewed and Archived (v0.29) keep a trimmed card for a few days (no mailbox link, no attachment details), unless the person switched that list off. The source mail provider remains the system of record for the original attachment.
The v0.8 backend contains the RAM preview lease store, recursive raw-content persistence checks, encrypted provider attachment locators, browser redaction of locators, attachment policy endpoints, and message-resolution purge endpoint. The actual IMAP/Gmail/Proton fetch/render worker is still a later provider-adapter step and must follow the invariants in SECURITY.md.
v0.9 UI changes
Continuous-scroll PDF preview
PDF previews no longer use page-forward/page-back controls. All safe rendered page derivatives are displayed in one vertically scrollable document viewer. This matches normal PDF-reader behaviour and keeps navigation simple on desktop, tablet, and Home Assistant mobile clients.
The prototype contains multiple simulated multi-page documents so the behaviour can be exercised without retaining raw PDF files.
Home Assistant notification scripts
Per-mailbox notification delivery can now use either:
- a Home Assistant
script.*entity - a Home Assistant
notify.*service - no immediate notification
Script targets are the preferred abstraction when a household wants device changes to be managed in one Home Assistant script rather than updating every automation or integration setting.
The prototype includes script.notify_julien, script.notify_beth, and script.notify_both as sample discovered targets. The production integration will enumerate available Home Assistant script entities dynamically and will not hard-code these names.
For script delivery, the intended default variable contract is:
titlemessagedata
The integration will invoke the selected script through Home Assistant rather than exposing notification devices to the processing App.
v0.10 UI fix
The horizontally scrollable account-management tab strip now preserves its exact
scrollLeft position when switching between Overview, Sync & folders, AI &
processing, Tasks & actions, Notifications, Privacy & sharing, and Security &
connection.
Previously the management view was re-rendered after a tab click, which recreated the tab strip and reset it to the far left. v0.10 stores the user's horizontal position and restores it immediately after the render. Manual horizontal scrolling is tracked continuously. Opening a different account intentionally starts the tab strip from the left.