Privacy policy
MindMail collects nothing.
Last updated 28 August 2026. This is the whole policy; it is short because there is little to say.
What the app stores
Your account settings, your mail cache, your rules, snoozes, outbox and activity log are stored on your iPhone, in the app’s own container, protected by iOS Data Protection. Passwords, app passwords and Google refresh tokens are stored in the iOS Keychain. None of it is uploaded anywhere, and the app excludes its mail cache from iCloud and iTunes backups.
What the app connects to
- Your IMAP and SMTP servers, the ones you configured, to read and send your mail.
- accounts.google.com and oauth2.googleapis.com, only if you add a Gmail account with Sign in with Google, to obtain and refresh the token Google issues for that account.
- Image hosts inside a message, only when you tap Load Remote Images, and only for that message.
Nothing else. No analytics, no crash reporting, no update checks, no advertising identifiers, no third‑party SDKs. The app’s Settings → Privacy screen lists every host it has connected to since installation.
Google user data
When you sign in with Google, MindMail requests the Gmail scope needed for IMAP and SMTP access, plus your email address to label the account. The resulting tokens are used solely to read and send mail on your behalf from your device, are stored only in the Keychain on that device, and are never transmitted to us or to anyone else. MindMail’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time from your Google Account’s security settings.
Contacts
If you allow access to Contacts, names and email addresses are read into memory to suggest recipients while you write. They are not stored by the app and never leave the phone.
What we receive
Nothing. There is no MindMail server. We cannot see your mail, your accounts, your usage or your device.
This website
mindmail.one serves static files. It sets no cookies, loads no third‑party resources and runs no analytics. The web server keeps standard access logs for a short time for operational purposes.
Changes
If this policy changes, the date above changes with it and the change is described here.
Contact
Questions about this policy: write to the address published on mindmail.one when the public release arrives; until then MindMail is a private build.