Privacy Policy — OneMail Desktop
Last updated: 2026-08-08
OneMail Desktop is a desktop email client. It is developed by an individual
developer ("we", "the developer"), not a company, and is distributed for
personal use. This policy explains what data OneMail Desktop accesses and how it
is handled.
Summary
OneMail Desktop does not have a server. There is no backend
operated by the developer that your email, contacts, or calendar data is
ever sent to. All data OneMail Desktop accesses stays on your own computer,
except for the direct connection your computer makes to your own email
provider (e.g. Google, or your IMAP/SMTP server) to send and receive your
mail.
What data OneMail Desktop accesses
- Email messages, folders, and labels — read and
written directly between your computer and your email provider's own
servers (IMAP/SMTP, or Gmail via Google's API).
- Google Account sign-in — when you connect a Gmail
account via "Sign in with Google", OneMail Desktop requests the
https://mail.google.com/ scope (full mail access, needed to
read, send, and organize your Gmail the same way any email app needs to)
and basic profile/email address info.
- Google Drive (optional) — if you separately choose
to connect Google Drive for the cloud-attachment feature, OneMail Desktop
requests the narrow
drive.file scope, which only grants
access to files OneMail Desktop itself creates in your Drive — never your
existing Drive files.
Where your data is stored
- Credentials and OAuth tokens are stored in your
operating system's own secure credential store (Windows Credential
Manager, macOS Keychain, or the Linux Secret Service) — never in a plain
file, and never transmitted anywhere by OneMail Desktop.
- Message cache (for offline access and fast search)
is stored in a local database on your computer, with message bodies
encrypted at rest using AES-256-GCM.
- No message content, credentials, or metadata is ever uploaded to any
server operated by the developer. OneMail Desktop has no analytics, telemetry,
advertising, or third-party tracking of any kind.
Data protection mechanisms
OneMail Desktop applies the following technical protections to your data:
- Encryption in transit — all connections to your mail
provider (IMAP/SMTP or Gmail API) use TLS. OAuth token exchanges with
Google use HTTPS.
- Encryption at rest — the local message cache is
encrypted using AES-256-GCM. The encryption key never leaves your
computer.
- Credential isolation — OAuth tokens and passwords are
never stored in application files or databases. They are stored only in
your operating system's dedicated secure credential store (Windows
Credential Manager, macOS Keychain, or the Linux Secret Service), which is
access-controlled by the OS itself.
- No server-side storage — because OneMail Desktop has
no backend server, there is no central database of user data that could
be breached; each user's data exists only on that user's own device.
- Least-privilege scopes — OneMail Desktop requests
only the Google scopes each feature strictly requires (e.g. the optional
Drive attachment feature uses
drive.file, which is limited to
files the app itself creates, rather than broader Drive access).
Optional AI features (self-hosted / offline)
OneMail Desktop's AI features (summarization, reply suggestions, task
extraction) run entirely locally on your own computer via
Ollama in a self-hosted, offline
configuration. The AI model runs as a local process on your own device;
your email content is processed on-device and is never transmitted
to Ollama, Inc. or any other model provider over the network, and
is never used to train, improve, or fine-tune any AI/ML model, foundational
or otherwise. This differs from cloud-hosted AI services: no API call
leaves your computer for this feature.
Limited Use compliance statement
The use of any information received from Google APIs by OneMail Desktop
will adhere to the
Google
API Services User Data Policy, including the Limited Use requirements.
OneMail Desktop does not use, transfer, or sell Google user data — raw,
aggregated, or derived — to create, train, or improve any generalized or
foundational AI/ML models, whether operated by OneMail Desktop's developer
or any third party.
Data sharing
We do not sell, rent, or share your data with any third party. Your
data is only ever exchanged directly between your computer and the mail
provider(s) you configure yourself, and (for the optional local AI
features) your own on-device Ollama process.
Your controls
- Remove a connected account at any time from within OneMail Desktop, which
deletes its locally cached data.
- Revoke OneMail Desktop's access to your Google Account at any time from
Google Account →
Security → Third-party access.
- Uninstalling OneMail Desktop removes its local application data.
Contact
Questions about this policy: asiakaspalvelu@selaa.fi