Product contract

Done means verified.

Flick is testing one bounded decision session across selected Gmail accounts a participant personally controls.

Availability and account limits are shown before connection or purchase. The contract below describes the bounded result a current build must verify before displaying it.

01

Verified Finish target

A finish may be shown only after Flick confirms the displayed actions in a named snapshot. Its receipt must name selected accounts, snapshot time, scan limits, confirmed actions, failed accounts, and exclusions.

Example target receipt: “12 displayed decisions confirmed across three selected accounts for the 08:42–08:43 snapshot. New mail and messages outside this scan are not included.”
  • Bounded: it never represents that a mailbox is empty.
  • Fail-closed: a failed account or unconfirmed provider action makes Verified Finish unavailable.
  • No optimistic finish: an empty local card stack is not provider confirmation.
02

Identity Firewall

The pilot is limited to independently authenticated Gmail identities the participant personally controls. Delegated, shared, team-managed, and alias-only mailboxes are outside the pilot.

  • Every displayed card and action must name its canonical account.
  • The service—not a client-supplied fallback—must bind the user, account, conversation, and current inbound version.
  • A stale, foreign, disconnected, or ambiguous action must fail closed.
03

Current action semantics

  • Archive target: the contained feasibility rail removes only the exact displayed message snapshot from Inbox and preserves unread state. The public app is sample-only while that rail is independently verified.
  • Keep: records a Flick decision and does not itself change Gmail. A later message in the conversation must be treated as a new inbound version.
  • Reply: can create a draft for the user to review. The current public build does not expose live reply actions.
  • Unsubscribe: records a request result, not proof that a sender stopped future mail.
04

Content and authorization

Google's restricted gmail.modify grant is technically broad enough to read, compose, and send Gmail. Flick's current interface uses it for reading, label changes, and requested draft creation; it does not expose or invoke Send.

Selected message content can pass request-scoped through Flick infrastructure and Anthropic when a user requests AI drafting. Minimal action state and encrypted approved draft text can persist temporarily for delivery and reconciliation. Flick does not maintain a general mailbox copy or train its own models on mailbox content.

05

Sample-only demo

The demo contains fabricated messages. It cannot connect to, read, or change a real mailbox.

Open the sample-only demo → · Read pilot status → · Get support →

Turn the next inbox decision into a finite deck.

Open Flick with an account you control, or practice first with fabricated sample mail. Provider results remain limited to the accounts, messages, and actions Flick actually confirms.

Open Flick with your inbox →

Practice with the sample deck · Get Flick for iPhone