Effective date: August 4, 2026
1. Introduction
This Privacy Policy explains how MailFlow: Smart Mail Assistant (“MailFlow,” “we,” “our,” or “us”) accesses, uses, stores, protects, and shares information when users access the MailFlow macOS application and its related website.
MailFlow is a native macOS email client that allows users to connect a Gmail account and read, organize, compose, send, trash, and permanently delete email.
By using MailFlow, you acknowledge the practices described in this Privacy Policy.
2. Information MailFlow accesses
Google Account information When you connect a Google account, MailFlow may access:
-
Your name
-
Your primary email address
-
Your Google profile picture
-
Your Google account identifier
-
OAuth authorization information
This information is used to identify and display your connected account inside MailFlow.
Gmail information To provide email-management features, MailFlow may access:
-
Gmail message and thread identifiers
-
Sender names and email addresses
-
Message subjects
-
Message previews or snippets
-
Message timestamps
-
Gmail labels and folders
-
Read or unread status
-
Starred status
-
Inbox unread counts
-
Recipient addresses
-
Subjects and message content composed by the user
MailFlow may perform the following Gmail actions when requested by the user:
-
Send email
-
Mark messages as read or unread
-
Star or unstar messages
-
Archive messages
-
Move messages to Trash
-
Permanently delete messages
MailFlow does not automatically send or permanently delete email.
3. How MailFlow uses Google user data
MailFlow uses Google user data only to provide or improve visible email features requested by the user.
Google user data is used to:
-
Authenticate the connected Google account
-
Display account information
-
Load and display Gmail messages
-
Display Gmail folders, labels, and status
-
Search messages displayed in the application
-
Compose and send email
-
Mark messages as read or unread
-
Star and archive messages
-
Move messages to Trash
-
Permanently delete confirmed messages
-
Display unread-message counts
-
Notify users about new messages
MailFlow does not use Google user data for unrelated purposes.
4. Gmail permission requested
MailFlow requests:
https://mail.google.com/
This permission allows MailFlow to read, compose, send, modify, trash, and permanently delete Gmail messages.
The permission is required because MailFlow provides permanent deletion from the Trash mailbox. Permanent deletion is unavailable through narrower Gmail permissions.
MailFlow requires explicit confirmation before permanently deleting a message.
5. How information is stored
OAuth credentials Google OAuth access and refresh tokens are stored locally in the user’s macOS Keychain.
OAuth credentials remain stored until:
-
The user removes the connected account from MailFlow
-
The user revokes MailFlow’s access
-
Google expires or revokes the authorization
-
The application’s local data is removed
MailFlow never collects or stores Google passwords.
Gmail information MailFlow requests Gmail information directly from Google when required to provide application functionality.
Gmail information displayed by MailFlow is processed locally on the user’s Mac. MailFlow does not operate a developer-controlled server for storing copies of users’ Gmail messages.
Local preferences MailFlow may locally store:
-
Connected account information
-
Selected account
-
Notification preferences
-
Refresh interval
-
Preferred browser
-
Application settings
-
Purchase or entitlement status
These preferences are used to maintain application functionality.
6. How information is shared
MailFlow does not sell Google user data.
MailFlow does not share or transfer Gmail data to:
-
Advertisers
-
Advertising platforms
-
Data brokers
-
Information resellers
-
Credit-reporting services
-
Artificial-intelligence model-training providers
Information may be disclosed only when reasonably necessary:
-
To complete an action requested by the user
-
To investigate abuse or a security incident
-
To comply with applicable legal requirements
-
To protect the rights, safety, or security of users and the application
-
As part of a business transfer where permitted by law and subject to appropriate notice and consent
MailFlow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
7. Human access to Gmail data
MailFlow’s developers, employees, contractors, and support personnel do not read users’ Gmail messages.
Human access may occur only when:
-
The user gives explicit permission to review specific information for support
-
Access is necessary to investigate abuse or a security incident
-
Access is required by applicable law
-
Information has been aggregated and anonymized for legitimate internal operations
Users should avoid sending sensitive email content in support requests unless necessary.
8. Advertising and artificial intelligence
MailFlow does not use Gmail data to:
-
Train artificial-intelligence models
-
Build advertising profiles
-
Serve personalized advertisements
-
Retarget users with advertisements
-
Determine creditworthiness
-
Make lending decisions
“Smart Mail Assistant” describes the application’s email-management experience. It does not mean Gmail data is used to train AI systems.
9. Notifications
With the user’s permission, MailFlow may display macOS notifications about new messages.
Users can disable notifications through MailFlow or macOS System Settings.
10. Purchases
MailFlow may offer subscriptions or upgrades through Apple’s App Store and StoreKit services.
Apple processes payment information. MailFlow does not receive or store complete payment-card details.
Apple may provide transaction and entitlement information required to determine access to purchased features.
11. Website information
When users visit the MailFlow website, the website provider may process standard technical information, including:
-
IP address
-
Browser and device type
-
Requested webpage
-
Access date and time
-
Standard server logs
Website information is not used to access a user’s Gmail account.
If analytics, advertising, or non-essential cookies are added later, this Privacy Policy will be updated before those practices begin.
12. Data retention and deletion
OAuth credentials remain in the macOS Keychain until the account is removed, authorization is revoked, or the credentials expire.
Local account preferences may remain until the account is removed, application data is deleted, or MailFlow is uninstalled.
To disconnect a Google account:
-
Open MailFlow.
-
Open Settings.
-
Locate the connected account.
-
Select Remove account.
-
Confirm the removal.
Users may also revoke access through their Google Account’s third-party connections settings.
Because MailFlow does not maintain a developer-controlled Gmail storage server, there is normally no separate server copy of the mailbox to delete.
13. Security
MailFlow uses reasonable security measures designed to protect user information, including:
-
Google OAuth authorization
-
PKCE protection during authorization
-
macOS Keychain storage
-
Encrypted HTTPS communication
-
User confirmation before permanent deletion
No storage or transmission method can be guaranteed completely secure. Users are responsible for protecting access to their Mac and Google Account.
14. Children’s privacy
MailFlow is not directed to children who cannot legally consent to use online services in their jurisdiction.
We do not knowingly collect information from children in violation of applicable law. Parents or guardians may contact us if they believe a child has provided information improperly.
15. Third-party services
MailFlow depends on services provided by:
-
Google OAuth
-
Gmail API
-
Google Account
-
Apple macOS
-
Apple App Store
-
Apple StoreKit
-
Apple notification services
These services operate under their own privacy policies and terms.
16. Changes to this Privacy Policy
We may update this Privacy Policy when MailFlow’s features, legal obligations, or data practices change.
The updated policy will be published on this page with a revised effective date. Material changes will be communicated when required by law.
17. Contact information
For questions about this Privacy Policy, Google user data, or account access, contact:
Email: usmansharif643@gmail.com
Website: https://laughlab.net