# Build brief — a focused alternative to Inbox Zero

> **Verdict:** Partly, if you narrow it · **Buildability:** 63/100 · **Category:** Email
> **Source:** https://www.canitbevibecoded.com/inbox-zero
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from Inbox Zero. Verify current pricing and capabilities before acting.

## Context

**Inbox Zero** — AI email assistant that organizes inboxes, drafts replies, blocks cold email, and automates cleanup. It currently costs $20/mo.

The personal Gmail loop is a contained project: classify new mail, apply labels, draft replies, and surface bulk cleanup. The gap is making it trustworthy enough to sit inside a real inbox every day: OAuth setup and review, token refresh, provider quirks, continuous sync, retries, rate limits, security, and integrations. Inbox Zero itself is open source, so anyone wanting the full product should self-host the official code instead of rebuilding all of it.

This brief describes a focused, single-operator replacement for the part of Inbox Zero that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

Watch one Gmail inbox, classify and label new threads, create reply drafts for review, and group noisy senders for cleanup.

- Build a focused single-user workflow with real persistence, search, and export.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- Node 22.
- Always-on machine or VPS for continuous processing.

### Data and integrations

- Google Cloud OAuth client.
- OpenAI API key.

Each of these needs a real account, credential, or quota. Set them up before writing feature code.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me a self-hosted personal Gmail assistant that covers the core Inbox Zero loop.
Use Node 22 + TypeScript + Fastify + better-sqlite3; server-rendered HTML and vanilla JS, no React.
Run on localhost by default, with one Dockerfile for an always-on VPS behind Caddy.
Support exactly one Gmail or Google Workspace mailbox through the Gmail API.
Use a Google OAuth client from .env and request only gmail.modify and gmail.compose; store the refresh token encrypted with an APP_SECRET.
On first run, import 14 days of mail; then poll Gmail history every two minutes and persist the last history ID.
Deduplicate jobs by Gmail message ID, use exponential backoff for transient API failures, and surface a failed-jobs page.
Rules live in rules.md: label definitions, priority senders, newsletters, cold email, and messages that need a reply.
For each new thread, call the OpenAI API with the thread text plus rules.md and require validated JSON: labels, priority, needsReply, summary, and optional draftReply.
Apply Gmail labels automatically, but never archive, delete, unsubscribe, or send without a click.
When needsReply is true, create or update a Gmail draft in the original thread; never send mail from the app.
Build one dashboard with Priority, Needs reply, Newsletters, Cold email, and Failed jobs views.
Add a bulk-cleanup screen grouped by sender with message counts and List-Unsubscribe support; show the exact action and require confirmation.
Add a small analytics page: daily received count, top senders, category totals, and estimated time saved.
Store only IDs, classifications, job state, and draft metadata in SQLite; do not persist full message bodies after processing.
Redact tokens and email contents from logs; add CSRF protection and bind the admin UI to localhost unless ADMIN_TOKEN is set.
Include fixture-based tests for classification parsing, idempotent sync, label application, draft creation, and unsubscribe confirmation.
Out of scope: Outlook, multiple accounts, mobile apps, Slack/Telegram, calendar context, attachment filing, multi-user accounts, billing, and telemetry.
README: exact Google Cloud OAuth setup, scopes and redirect URI, .env example, how to revoke access, Docker/Caddy deployment, backups, and expected LLM costs.
Return finished code with migrations and scripts for dev, test, and start; no pseudocode or TODOs.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- Outlook and reliable multi-account support.
- Battle-tested token refresh, push sync, retries, rate-limit handling, and background uptime.
- Reply-in-your-voice learning with deeper mailbox, calendar, and knowledge-base context.
- Slack and Telegram chat, mobile access, meeting briefs, and attachment filing.
- Connectors, OAuth flows, and vendor API changes require constant upkeep.
- The last 20 percent is sync, migration fidelity, speed, and edge cases.

## What you still own after launch

- Secure credentials, rotate secrets, and handle provider rate limits.
- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.
- Maintain every third-party integration as APIs and OAuth rules change.

## Risk

**Operational risk.** The code is achievable; dependable data, integrations, and ongoing operations are the real cost.

Editorial confidence in this assessment: high. No independent one-shot implementation is linked yet.

## Prior art

Working open-source software you can read, fork, or borrow from before starting:

- [Inbox Zero](https://github.com/elie222/inbox-zero) — The official open-source product, with a supported self-hosting path

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/inbox-zero
