GalMail Privacy Policy
Effective date: September 10, 2026
Information GalMail processes
The app connects directly to an email provider you authorize. On your device it processes account identifiers, email content and metadata, contacts, drafts, attachments, labels, settings, search indexes, and OAuth tokens to provide the mail client. The default hosted path receives opaque routing identifiers, push tokens, event times, encrypted blobs, blob sizes, and limited operational metadata. It is designed not to receive plaintext mail, search queries, or provider OAuth tokens.
Data protection for sensitive data
Mail, contacts, drafts, attachments, calendar events, and OAuth tokens are sensitive data. GalMail protects them as follows. Transport: the app talks to Google and Microsoft only over TLS. Tokens: provider OAuth tokens stay in the operating-system keychain or platform secret store on the device; they are not written into app logs or sent to GalMail servers. On-device data: mail and calendar data are processed locally on the device you control; access follows the device lock and OS app sandbox. Hosted path: when used, the hosted service is designed to store encrypted blobs and operational metadata only, not plaintext mail, search queries, or provider tokens. Remote processing of mail content is off by default. GalMail does not sell personal information and does not use mail or calendar content for advertising. Google and Microsoft continue to store mail and events under their own terms once you authorize those providers.
Why information is processed
GalMail processes information to authenticate accounts, synchronize and secure local data, deliver generic push hints, perform remote features you explicitly enable, prevent abuse, and respond to support, security, and legal requests. GalMail does not sell personal information or use mail content for advertising.
Sharing
Information is shared only with the email provider you select, infrastructure needed to operate the selected service, remote processors named at consent, or authorities when legally required. Apple Push Notification service or a web push provider receives a generic notification and routing token, not a sender, subject, body, or provider token.
Retention, choices, and contact
Removing an account deletes GalMail-controlled local account data. It does not delete provider-hosted mail. Contact privacy@galmail.app for access, deletion, or questions.