MailBuddy · Privacy Policy
Privacy Policy
This policy explains how MailBuddy accesses Google account data, which actions require the restricted gmail.modify scope, where OAuth tokens are stored, and when optional AI features send content to a provider.
Effective date · July 24, 2026
1. Scope and operator
This Privacy Policy applies to the MailBuddy macOS application operated by Zrindy LLC, referred to in this policy as Zrindy, we, or us. MailBuddy is an email client that lets users connect Gmail accounts and manage mail from a native macOS interface.
2. Google account data MailBuddy accesses
After you approve Google OAuth 2.0 access, MailBuddy may process the following data to provide features you directly request:
- Basic identity data from
openid,email, andprofile, including your Google account identifier, email address, display name, and profile image when available. - Gmail message and thread content, headers, sender and recipient information, dates, snippets, labels, read status, stars, and attachment metadata.
- Attachment content only when MailBuddy must display it or when you explicitly download or open the attachment.
- Draft and outgoing message content that you create, reply to, or forward through MailBuddy.
3. Why MailBuddy requests gmail.modify
MailBuddy requests https://www.googleapis.com/auth/gmail.modify so the app can display mail and perform visible actions initiated by the user. Those actions include:
- Reading and searching messages and threads.
- Marking messages read or unread, adding or removing stars, archiving, moving to Trash, and restoring mail.
- Creating and applying labels, including labels used for MailBuddy Kanban workflow states.
- Creating drafts and sending new messages, replies, and forwarded messages.
MailBuddy does not use a permission that permanently deletes Gmail messages while bypassing Trash. We do not use Google user data for advertising, credit decisions, surveillance, or to build user profiles unrelated to MailBuddy’s email features.
4. OAuth sign-in and token storage
MailBuddy opens Google sign-in in your system browser and does not collect or store your Gmail password. OAuth access and refresh tokens are stored locally in the macOS Keychain. Zrindy does not operate a server-side MailBuddy account database that stores those tokens.
You can revoke access at any time from Google Account permissions. Revocation prevents future Gmail API access until you sign in and grant access again.
5. Local storage and retention
MailBuddy may cache message metadata, message bodies, display resources, labels, settings, AI model files, and other app state on your Mac to provide the interface and improve responsiveness. Logging out removes that account’s OAuth credential from Keychain and deletes that account’s locally cached mailbox data from MailBuddy. Downloaded AI model files are shared app resources and remain until you remove the model or MailBuddy’s application data.
MailBuddy does not independently retain a copy of your Gmail mailbox on a Zrindy mail server.
6. AI processing
Gemma on device. If you select a downloaded Gemma model, MailBuddy processes the prompt and email context locally on your Mac. That content is not sent to Zrindy or an external AI provider for the Gemma operation.
Optional Codex processing. If you select Codex and initiate an AI action such as summarizing or drafting, MailBuddy sends the prompt and the relevant email context (for example subject, sender, message body, and thread context) to OpenAI through the Codex SDK using the Codex session authenticated on your Mac. MailBuddy does not send Gmail content to Codex in the background merely because an account is connected.
OpenAI processes provider-bound data under its applicable Privacy Policy and service terms. MailBuddy’s use of information received from Google Workspace APIs does not include using or transferring Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models. Users who do not want provider processing can keep Gemma selected or avoid Codex actions.
7. Sharing and transfer
We do not sell Google user data. MailBuddy transfers Google user data only when necessary to provide a user-requested MailBuddy feature, when the user explicitly initiates optional provider-backed AI processing described above, when required by law, or when needed to address security or abuse with appropriate safeguards.
MailBuddy’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Security
MailBuddy uses OAuth 2.0 with PKCE and state validation, macOS Keychain storage, HTTPS Google APIs, and application-level access controls. No method of storage or transmission is completely secure, but we use safeguards appropriate to the data and the desktop application environment.
9. Your choices and deletion
- Remove an account from MailBuddy and delete its locally cached app data.
- Revoke MailBuddy from Google Account permissions.
- Delete messages, labels, drafts, and other Gmail data through MailBuddy or Gmail, subject to Gmail’s behavior and retention rules.
- Choose local Gemma instead of Codex, or do not invoke AI features.
- Contact us to ask questions or request deletion of support correspondence held by Zrindy.
10. Children, changes, and contact
MailBuddy is not directed to children under 13. We may update this policy as the app, providers, or legal requirements change. Material changes will be published at this URL with a revised effective date.
For privacy, security, deletion, or support questions, contact dev@zrindy.com.