A few months ago I shared Paperweight here. An open-source desktop app that scans your inbox to map out your digital footprint.
Every account you create, every service you sign up for, every online purchase is connected to your email address. Most people have 100+ accounts they’ve forgotten about, creating security risks and privacy exposure.
Local-first. Your inbox is scanned on your own device, your data never leaves it, and there is no account or cloud component.
Since last time, a lot has changed:
- New pii analysis engine to check addresses, phones, IBANs, national IDs, cards, and more
- Improved multi-language lexicons for better classification
- Track GDPR data requests you send fromPaperweight
- Improved sync, receiver, hide-my-email aliases, and message tagging
- Fully verified builds for Apple, Windows and Gmail OAuth connections
- Several minor improvements and bug fixes
Links


I understand the concern, but MIT has been very intentional to signal the opposite of what you’re worried about. Paperweight runs fully local. Everything works without any back-end or external services. No one can turn this into some paid SaaS to lock features. It already passes the walk-away test and there’s literally nothing to rug and if the project ever goes into a direction you don’t like you don’t lose access or need anyone’s permission.
While GPL theoretically gives you the same opportunity, I feel like it adds some overhead and potentially locks out genuine contributors.
And especially in the age of AI, code is cheap and if someone wants to build a closed Paperweight, the license is not going to stop them.