Privacy Policy

Effective date: 2026-06-22 · Last updated: 2026-09-12

This document mirrors the authoritative source in our repository. It is written by a solo developer and is not legal advice. In case of any discrepancy, the Korean version governs.

At a glance

MailMail is a watch email app that makes privacy a design principle, not a feature.

1. What we do not collect

The following is never transmitted to our servers, stored by us, or written to our logs in any form:

Mail-related data is not written to debug logs either. The only things we record for diagnostics are metadata that contain no body (for example, a sender hash or an action type).

2. What we process and how

2.1 Mail account credentials (app password / OAuth token)

2.2 Email body, subject, sender (summary processing)

2.3 Push-notification device token (APNs)

2.4 Outlook / Microsoft 365 account (if applicable)

2.5 Usage statistics and diagnostics (never transmitted)

2.6 Payment information

2.7 Reminders integration (Pro, optional)

2.8 Launch-notification sign-up (website, optional)

This applies only if you sign up for launch updates on the website, not in the app. Using the app never requires it.

3. When information leaves the device (summary)

DataTo whereWhatNotes
Mail credentialsYour mail providerLogin infoDirect TLS. Never our servers
Mail body/subjectYour mail provider ↔ deviceMail dataFetch, plus quick replies you choose to send. Summary stays on device
APNs tokenApple → push relay serverToken + environmentNo mail content
RemindersApple Reminders (yours)To-do titleOnly on your one-tap
PaymentApple App StorePayment processingNo access by us
Personalization keysApple iCloud KeychainRandom salt, encryption keyApple end-to-end encrypted. No access by us
Siri / ShortcutsApple (on-device system)Headline, sender, countsNo body. Only when you ask
Launch sign-upCloudflare KVEmail, language, timeOnly if you signed up on the website (2.8)

Email body, subject, sender, and credentials never reach us (the MailMail operator).

4. Third parties (processors and integrated services)

We do not sell or provide your information to third parties for any purpose other than those above.

5. Retention and use period

How we destroy data: information on the device is destroyed by operating-system file deletion when you delete the account or the app. Information in the relay store (KV) is destroyed by deleting the record at the times above. We keep no paper records and no backup copies.

5.1 Overseas transfer

We transfer personal data overseas as listed below. If you prefer not to, you can avoid the feature (turn off push notifications, skip the launch sign-up) or write to contact@mailmail.app. Turning off push notifications may delay new-mail alerts.

RecipientCountryItemsPurposeWhen / howRetention
Cloudflare, Inc.United StatesAPNs token, environmentSilent push relayFirst app launch, over HTTPSUntil token expiry
Cloudflare, Inc.United StatesEmail, language, timeOne launch noticeAt sign-up, over HTTPSUntil the notice is sent
Apple Inc.United States and othersPayment, receiptIn-app purchaseAt purchasePer Apple's policy
Microsoft Corp.United States and othersMail dataReading and sending mail when Outlook is connectedIf you connect the accountUntil you disconnect

Traffic to your mail provider (Naver, Daum/Kakao, Google, and so on) is communication with your own account, governed by that provider's privacy policy.

6. Security measures

7. Your rights as a data subject

8. Children under 14

MailMail is not directed to children under 14, and we do not knowingly collect personal information from children.

9. Privacy officer and contact

You may also report privacy concerns to the Korean authorities below:

10. Changes to this policy

If this policy changes, we will post the effective date and the changes on this page. For significant changes, we will provide additional notice via in-app announcements or update notes.

← MailMail home