Legal

Privacy Policy

Effective date: 26 July 2026 · Applies to the Mailie Pro Android application and the mailie.pro website.

This Privacy Policy explains how the Mailie Pro application (the “App”) and the website at mailie.pro (the “Site”) handle personal data. The App and the Site are published and operated by Mailie Pro (“Mailie Pro”, “we”, “us”, “our”), which is the data controller for the limited processing described in this policy.

Our guiding principle is data minimisation, implemented in architecture rather than in policy: the App is engineered so that your email cannot reach us, and the Site is engineered to function without tracking you. Where this policy says we do not receive something, that is because there is no mechanism by which we could.

1. Summary

This summary is provided for convenience only and does not replace the full text below.

  • The App collects no personal data. It contains no analytics, telemetry, crash reporting, advertising identifiers or fingerprinting, creates no account with us, and sends nothing to us. Your email travels only between your device and the mail server you configure.
  • All artificial-intelligence processing happens on your device. Your messages, your prompts and your questions are never transmitted to us or to any third-party AI service, and are never used to develop, train, fine-tune or improve any generalised AI or machine-learning model, whether ours or anyone else’s.
  • Where you choose to connect a Google account using OAuth, the Google user data the App receives stays on your device. Our use of it complies with the Google API Services User Data Policy, including the Limited Use requirements — see section 6.
  • The Site uses first-party, cookieless analytics that store no IP address and no device fingerprint, and it honours Do Not Track and Global Privacy Control signals.
  • If you contact us, we keep your message and contact details only to reply to you and to prevent abuse.
  • We do not sell or share personal information as those terms are defined under United States state privacy laws, and we serve no advertising anywhere.

2. Who we are

Mailie Pro is an independent software publisher. Correspondence, including formal notices and data-protection requests, may be sent to the addresses in section 18. Our registered address and, where one is required, details of any representative appointed under Article 27 of the GDPR, are available on written request to legal@mailie.pro.

We are not affiliated with, endorsed by, or sponsored by Google LLC, Microsoft Corporation, Proton AG, the Mozilla Foundation, or any mail provider whose servers you may choose to connect to.

3. Scope of this policy

This policy covers:

  • the Mailie Pro Android application distributed through Google Play; and
  • the website at mailie.pro, including its contact form.

It does not cover the mail providers, servers or third-party services you choose to connect the App to. Those are independent controllers of your data and their own privacy policies apply. Choosing to connect the App to a service is your decision, and this policy cannot and does not describe what that service does with your information.

4. The application

The App runs entirely on your device. It contains no telemetry, analytics SDK, advertising identifier, crash-reporting service or fingerprinting code, and it does not create an account with us. We operate no mail service, no synchronisation backend and no AI endpoint.

4.1 Email content and credentials

Your messages, attachments, contacts, calendar invitations and login credentials are exchanged solely between your device and the mail server or servers you configure. We never receive, transmit, store, process or have access to them. Credentials are sealed at rest using an AES-256-GCM key held in your device’s hardware-backed Android Keystore, and are never written in plaintext.

4.2 On-device storage

Cached mail, attachments, contacts, generated briefings, classification history and the semantic search index are stored in an encrypted SQLCipher (AES-256) database in the App’s private storage. This data never leaves your device except where you explicitly export it. Uninstalling the App removes it.

4.3 Contacts

The App includes its own address book stored in the encrypted database described above. It does not request the Android contacts permission and cannot read your device’s address book. You may import contacts from a vCard file you select, or import a single contact through the system picker, in both cases by explicit action. If you enable CardDAV synchronisation, contacts are exchanged directly between your device and the server associated with that mail account, and server discovery is constrained to that account’s own domain; nothing is sent to us.

4.4 Permissions

The App requests only the minimum permissions it needs, and asks for notification permission only at the point you enable notifications. It does not request access to your contacts, your location, your camera, or broad device storage. Attachments and imports use a one-shot file-picker grant that expires. Document scanning is performed by Google Play services in its own process and returns only the pages you choose to keep.

4.5 Diagnostics

The App displays device and engine diagnostics — processor, memory, acceleration back-end, model status and speed measurements. These are computed and displayed locally for your information and are not transmitted anywhere.

5. Every connection the app makes

Because “we collect nothing” is only meaningful if you know where the App does connect, the following is a complete list of the network connections it can make and what each carries. Every connection uses TLS. Several are optional and are made only if you enable the relevant feature.

DestinationWhenWhat is sent
Your mail server(s) Always, to send and receive mail Your credentials and your mail, as any mail client must. Chosen and controlled by you.
Your chosen DNS-over-HTTPS resolver Always, to resolve server names The hostname being resolved. No mail content, no identifiers.
Hugging Face (model files) Once, when a language or embedding model is downloaded An ordinary file request. No account, no mail content, nothing about you.
Google (machine-learning model files) Only if you enable translation or handwriting input A request for the generic language model. Your text and your ink are never sent.
A correspondent’s Web Key Directory While composing, to find their public encryption key A hashed form of the recipient’s address to their own domain. No message content.
Your CardDAV server Only if you enable contact synchronisation Your contacts, to the server for that account only.
Your alias provider (SimpleLogin / addy.io) Only if you configure one A request to create an alias, authenticated with the token you supplied.
A sender’s unsubscribe endpoint Only when you tap Unsubscribe The one-click unsubscribe request that sender published.
Your UnifiedPush distributor Only if you enable UnifiedPush A push registration for the account. Chosen and hosted by you.
A carrier’s tracking page Only when you tap a tracking action Opens your browser at a hard-coded carrier domain — never a link taken from the email.

No connection on this list goes to us. The App has no endpoint of ours to call. If you enable the SOCKS5 / Tor routing option, every connection above — including the DNS-over-HTTPS lookups — is routed through the proxy you configure, and the App fails the connection rather than bypassing the proxy if it is unreachable.

6. Google user data and OAuth access

This section applies where the App accesses a Google account (for example, a Gmail mailbox) through Google OAuth, whether using restricted scopes such as full mail access or gmail.modify, or sensitive scopes such as gmail.readonly, gmail.send or profile scopes. It applies in addition to, and does not limit, the rest of this policy.

Limited Use disclosure. Mailie Pro’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6.1 What we access, and why

The App requests only the scopes required for the mail-client features that are visible and prominent in its own interface: reading your mail so it can display, search, summarise and triage it on your device; modifying message state so that reading, starring, archiving, moving and deleting work; and sending mail so that composing, replying and forwarding work. Each scope is shown to you on Google’s consent screen before any access occurs, and you may decline.

6.2 How Google user data is handled

  • It stays on your device. Google user data obtained through these scopes is processed and stored only in the App’s encrypted local storage on your device. It is not uploaded to any server operated by or for us. We operate no backend that could receive it.
  • Tokens are protected. OAuth access and refresh tokens are sealed with a hardware-backed Android Keystore key and are never stored in plaintext, never logged, and never transmitted to us.
  • We do not transfer it. We do not sell, rent, trade, disclose or otherwise transfer Google user data to any third party, other than as strictly necessary to provide or improve the user-facing features described above, to comply with applicable law, or as part of a merger, acquisition or sale of assets, in which case we would give affected users advance notice and obtain consent where required.
  • We do not use it for advertising. Google user data is never used for serving advertisements of any kind, including retargeted, personalised or interest-based advertising. The App contains no advertising code.
  • No human reads it. No employee, contractor or agent of Mailie Pro reads, or is technically able to read, your Google user data. There is no support tool, log, database or console through which such access could occur. We would only ever seek access with your prior affirmative consent for specific messages, where necessary for security purposes such as investigating abuse, or where required by law — and none of those routes exists today, because the data never leaves your device.
  • It is never used to train AI. See section 7.

6.3 Client-only architecture

Mailie Pro is a client-only application. Google user data is transmitted between your device and Google’s servers directly, and to no other destination. We do not operate servers that store, process, cache, proxy or transit Google user data, and we hold no credentials that would permit access to your mailbox. Any independent security assessment of our handling of restricted scopes should be understood in that light: there is no server-side environment in which such data exists.

6.4 Retention, revocation and deletion

Because Google user data is held only on your device, you control its lifetime entirely:

  • Remove one account: delete the account inside the App. Its cached mail, tokens and derived data are erased from the device.
  • Remove everything: uninstall the App, or clear its storage in Android Settings. All locally held data, including all Google user data, is destroyed.
  • Revoke our access: visit myaccount.google.com/permissions and remove Mailie Pro’s access at any time. Revocation takes effect immediately at Google and the App can no longer reach your mailbox.

We cannot delete Google user data on your behalf, because we never hold a copy of it. If you believe we hold data about you and wish it erased, contact privacy@mailie.pro and we will act on your request as described in section 13.

7. Artificial intelligence and machine learning

All AI features in the App — the briefing, summaries, smart replies, composition and rewriting, classification, semantic search, question answering, translation, text recognition and handwriting recognition — are performed by models that execute locally on your device.

  • Your email content and your prompts are never transmitted to us, to Google, or to any other AI provider for processing.
  • Your data is never used to develop, train, fine-tune, evaluate or otherwise improve any generalised artificial-intelligence or machine-learning model, whether ours or a third party’s. This applies expressly and without exception to Google user data obtained through OAuth.
  • What the App learns from your behaviour — your category corrections, your important correspondents, your writing style — is derived on your device, stored encrypted on your device, and used only to personalise your own experience. It is not aggregated, not pooled, and not shared, because there is nowhere for it to be sent.
  • Model files themselves are generic, publicly available models downloaded once. Downloading a model sends nothing about you and does not transmit your data to its publisher.
  • AI output can be inaccurate or incomplete. The App states this where output is shown, and you should verify important details against the original message. See the Terms of Use.

8. The website

When you visit mailie.pro, we process limited data as described below. The Site loads no third-party scripts or fonts by default.

8.1 First-party analytics

To understand aggregate traffic we record, per page view: the page path, the referring site’s host, a coarse country and region, your device category (desktop, mobile or tablet), and your browser and operating-system family, together with a random identifier that exists only for the current browser tab. We do not store your IP address, set any cookie, or build a profile or fingerprint. Your IP address is used transiently, in memory, only to derive the coarse country, and is then discarded. If your browser sends a Do Not Track signal or a Global Privacy Control signal, no analytics event is recorded at all.

8.2 Contact form

If you send us a message, we process the name, email address, subject and message you provide, together with your IP address and a coarse country, in order to respond to you and to detect and prevent spam and abuse. Your message and our replies are retained as a conversation so that correspondence remains coherent.

8.3 Security logging

To protect the Site we record security-relevant events — failed administrative logins, automated scanning, rate-limit events, invalid form tokens — including the source IP address, user agent, requested path and a short description, and we maintain a per-address activity record so that abusive sources can be identified and blocked. These records are used only for security and abuse prevention and are never used for analytics, profiling or marketing.

8.4 Spam protection

Depending on configuration, the contact form may use a third-party challenge service — Cloudflare Turnstile or Google reCAPTCHA — to distinguish people from bots. When such a service is enabled, that provider processes limited technical data under its own privacy policy, and its script is loaded from that provider. By default the Site uses a self-hosted method that loads no third-party script at all.

8.5 Cookies

The public Site sets no cookies for visitors. Two items of browser storage are used for the Site to function: a preference recording whether you selected light or dark mode, and a random per-tab identifier used to count a visit once rather than repeatedly. Neither is a cookie, neither is transmitted to a third party, and both are removed when you clear site data. A single, strictly necessary encrypted session cookie is used only on the separate administrative dashboard, which is for the operator and is not part of your visit.

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

ProcessingPurposeLegal basis
Site analyticsUnderstanding aggregate, non-identifying usageLegitimate interests — Art. 6(1)(f)
Contact formResponding to your enquirySteps at your request prior to a contract, and legitimate interests — Art. 6(1)(b) and (f)
Security logging and IP blockingSecurity and integrity of the SiteLegitimate interests — Art. 6(1)(f)
Spam protectionPreventing abuse of the contact formLegitimate interests — Art. 6(1)(f)

We have assessed in each case that our interest in operating and securing the Site does not override your rights and freedoms, in particular because the data involved is minimal, is not used to profile you, and is not combined with anything else. You may object to processing based on legitimate interests as described in section 13. The App itself involves no processing of your personal data by us, so no legal basis is engaged.

10. How we share personal data

We do not sell, rent or trade personal information, and we do not share it for advertising or cross-context behavioural advertising. We use a small number of service providers (processors) strictly to operate the Site: our hosting provider; an email provider used to deliver contact messages and our replies; and, where enabled, the spam-protection provider named in section 8.4. These providers act on our documented instructions and are bound by appropriate confidentiality and security obligations.

We may also disclose information where we are required to do so by law, or where necessary to establish, exercise or defend legal claims, or to protect the rights, property or safety of Mailie Pro, our users or the public. We will resist requests that we consider unlawful or overbroad, and where we are legally permitted to notify you of a request, we will.

11. International transfers

Our servers and service providers may be located in countries other than yours. Where personal data is transferred internationally from the EEA, the United Kingdom or Switzerland, we rely on appropriate safeguards — in particular the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with any supplementary measures required — or on an applicable adequacy decision or derogation. Details of the safeguards applied to a particular transfer are available on request.

12. Retention

DataRetention
App data (mail, contacts, tokens, AI output)Held only on your device, for as long as you keep it. Removed on account deletion or uninstall.
Site analytics eventsAggregate and non-identifying; retained no longer than 24 months.
Contact messages and repliesRetained while needed to handle your enquiry and for up to 24 months afterwards, then deleted.
Security event logsRetained no longer than 12 months, except where a specific record is needed for an ongoing investigation or legal claim.
Per-address activity and block-list recordsRetained while the address remains relevant to abuse prevention, and reviewed periodically.

We delete or irreversibly anonymise data when it is no longer needed for the purposes described in this policy.

13. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw any consent you have given. Withdrawing consent does not affect processing carried out before the withdrawal.

EEA, United Kingdom and Switzerland. You have the rights set out in Articles 15–22 of the GDPR and the equivalent UK provisions, including the right to object to processing based on legitimate interests. You also have the right to lodge a complaint with your supervisory authority; we would appreciate the chance to address your concern first.

California. Under the CCPA as amended by the CPRA you have the right to know, delete and correct personal information, and to opt out of its “sale” or “sharing”. We do not sell or share personal information, and we do not use it for cross-context behavioural advertising, so there is nothing to opt out of. We do not knowingly collect or process sensitive personal information as that term is defined by the CPRA, and we do not use or disclose any personal information for purposes beyond those described here. You may exercise your rights through an authorised agent. In the preceding twelve months we collected the categories of information described in section 8 for the purposes described there.

Other jurisdictions. Residents of other United States states with comprehensive privacy laws, and of other countries with equivalent legislation, have substantially similar rights, which we honour on the same basis.

To exercise any right, email privacy@mailie.pro. We will respond within the period required by applicable law — generally one month under the GDPR and 45 days under the CCPA — and will tell you if we need longer. We may ask for information sufficient to verify your identity, used only for that purpose. We will never discriminate against you for exercising your rights.

Please note that, because the App holds your data only on your own device, requests relating to App data are generally satisfied by the self-service steps in section 6.4 — we have nothing to produce, correct or delete.

14. Children

The App and Site are not directed to children, and we do not knowingly collect personal data from children under the age of 16, or under the age of 13 in the United States. If you believe a child has provided us with personal data, contact privacy@mailie.pro and we will delete it promptly.

15. Security

We apply technical and organisational measures appropriate to the limited data we process: TLS in transit, encryption of sensitive data at rest, modern password hashing and optional two-factor authentication on the administrative interface, strict access control, rate limiting, and a database that is never exposed to the public internet. On your device, the App applies the protections described in sections 4 and 6.

No method of transmission or storage is completely secure, and we do not claim otherwise. Our principal safeguard is that we hold almost nothing in the first place. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals, without undue delay.

If you believe you have found a security vulnerability, please report it privately to help@mailie.pro before disclosing it publicly. We will not pursue legal action against researchers who act in good faith and allow us reasonable time to respond.

16. Purchases

The App is sold through Google Play. Google is the merchant of record: your payment, applicable taxes and any refund are processed and governed by Google under Google’s privacy policy and the Google Play terms. We never receive your payment card details. We may receive aggregate, non-identifying sales statistics from Google Play.

17. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the effective date at the top and, where a change is material, take reasonable steps to bring it to your attention — including, where the change concerns the handling of Google user data, obtaining any consent required before the change takes effect. Your continued use of the App or Site after an update takes effect constitutes acceptance of the revised policy. Previous versions are available on request from legal@mailie.pro.

18. How to contact us

Please use the address that matches your reason for writing:

If you are not satisfied with our response, you may escalate to your local data-protection supervisory authority.