Mailcoach privacy policy
Effective
Mailcoach is an email app for Android made by seqavo. It connects your phone directly to your mail provider. There is no Mailcoach server: your mail travels between your phone and your provider, and nowhere else.
This policy explains what Mailcoach can access, where that data is kept, and what it is used for. The short version: your mail stays on your phone, and we never see it.
What Mailcoach accesses
When you add a Google account, Mailcoach asks Google for permission to:
- Read, send, delete and manage your email (the https://mail.google.com/ scope). This is what lets Mailcoach act as a mail client over IMAP and SMTP: show your inbox, search it, and send, archive, star or delete messages when you ask.
- See your email address (the openid and email scopes). This labels the account inside the app and tells Mailcoach which mailbox it is talking to.
- Keep a file in a hidden, app-only folder in your Google Drive (the drive.appdata scope). This folder is used only for optional setup sync, described below. Mailcoach cannot see any other file in your Drive.
Where Microsoft sign-in is offered, Mailcoach asks Microsoft for permission to read your mail over IMAP and send it over SMTP (the IMAP.AccessAsUser.All and SMTP.Send scopes), to stay signed in (offline_access), and to see your address and name (openid, email and profile).
For Google and Microsoft accounts, Mailcoach never sees your password. On phones with Google Play services you can pick a Google account that is already on the phone, and Google shows its own consent screen; Google Play then keeps that access, so Mailcoach stores no token for it. Otherwise sign-in happens on Google’s or Microsoft’s own page, and the provider hands Mailcoach a token that works only for the permissions above. You can revoke that access at any time from your Google Account at https://myaccount.google.com/permissions, or the equivalent Microsoft page.
For other providers you can set up an account by hand, with its IMAP and SMTP server and your password. The password is stored encrypted on the phone and sent only to that provider’s servers.
Where your data is kept
Messages Mailcoach downloads are stored on your phone, in a database encrypted with a key held in the Android Keystore. If you turn on the biometric lock, that key is released only after your fingerprint or face is recognised.
Attachments you open, files attached to a draft, and mail waiting to be sent are kept in the app’s private storage on the phone, which other apps cannot read.
Sign-in tokens and passwords are stored encrypted on the phone, with a key held in the Android Keystore.
Logos of the people and companies that write to you are kept on the phone too, so they do not need to be fetched again.
Nothing is uploaded to seqavo. We do not run a server that receives, relays, stores or indexes your mail, your contacts, your tokens or your address.
What your data is used for
Mail data is used only to provide the features of a mail client to you, on your phone: showing messages, searching them, notifying you about new mail, and carrying out the actions you take. Search runs on the phone, over the copy Mailcoach already holds.
We do not use your mail to build profiles, to train models, to show advertising, or for any purpose other than the feature you are using. No human at seqavo reads your mail. There are no exceptions for security review, abuse investigation or product research.
Mailcoach’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That policy is at https://developers.google.com/terms/api-services-user-data-policy.
Who your data is shared with
Nobody. Mailcoach does not sell, rent, transfer or disclose your mail, your address or any data derived from it to any third party. The only parties that see your mail are you and your mail provider.
The app contains no analytics library, no crash reporter and no advertising SDK, so there is no third party receiving usage data from the app either.
Setup sync
Setup sync is off unless you turn it on. When it is on, Mailcoach keeps a file in the hidden app-only folder of the first Google account you added, so a new phone can restore your setup. The file holds your account list, the sign-in credentials for those accounts, your signatures, your app settings and your phone’s model name. It contains no messages. It is protected by your Google account, and only Mailcoach can read it. Turning setup sync off deletes the file, and you can also remove it from Google Drive’s settings under “Manage apps”.
Network connections
Mailcoach connects to:
- Your mail provider’s servers, to sign in and to read and send mail. For Google these are accounts.google.com, oauth2.googleapis.com, openidconnect.googleapis.com, imap.gmail.com, smtp.gmail.com, Google Play services on the phone and, for setup sync only, www.googleapis.com. For Microsoft they are login.microsoftonline.com, outlook.office365.com and smtp.office365.com. For an account you set up by hand, they are the servers you enter.
- When you set up an account by hand, the email domain’s own configuration address and autoconfig.thunderbird.net, to look up its server settings. Only the domain is sent, not your address or password.
- The websites of the people and companies that write to you, to fetch their logo (for example example.com/favicon.ico for mail from example.com). Only the logo is requested; each site can see that a phone fetched it.
- dl.seqavo.com, when you open the Updates screen, to check for a new version and download it if you choose. The check sends no information about you or your phone.
- Remote images in messages, only if you ask. Messages are shown with remote images and tracking pixels removed. Loading them for a message, or for all messages, is your choice in the app.
- Links you tap, which open in your browser.
That is the whole list. The app makes no other connections.
Android permissions
- Internet and network state: to reach your mail provider, and to wait for a connection rather than fail when there is none.
- Notifications: to tell you about new mail, and about a message that could not be sent. You can decline this and the app still works.
- Foreground service, wake lock and start at boot: to keep a connection to your provider open while syncing, so new mail arrives promptly and actions you took offline are delivered.
- Contacts, optional: Android shows the Google accounts on a phone only to apps allowed to read contacts. Mailcoach asks so it can list those accounts when you sign in, and never reads your contacts. If you decline, you can still sign in.
- Biometrics: only if you turn on the app lock.
- Install apps: to install a Mailcoach update you have chosen to download. Android asks you before each install.
Mailcoach does not request access to your location, camera, microphone, photos or files.
Retention and deletion
Mail stays on your phone for as long as the account is added. Removing an account from Mailcoach deletes its messages, attachments, mail waiting to be sent, tokens and search index from the phone. Uninstalling the app deletes everything Mailcoach stored.
Removing an account or uninstalling the app does not delete anything from your mail provider. Your mail is still in Gmail or Outlook, exactly as it was.
Because seqavo holds no copy of your data, there is nothing for us to delete on our side. If you used setup sync, turn it off first to delete its file from your Drive. Revoking Mailcoach’s access from your Google Account then completes the removal.
Children
Mailcoach is not directed at children under 13, and we do not knowingly collect data from them. As described above, we do not collect data from anyone.
Changes to this policy
If Mailcoach ever starts collecting, storing or sharing data in a way this policy does not cover, we will update this page and change the effective date at the top before that version of the app is released. The app will not quietly start doing something this page says it does not do.
Contact
Questions about this policy or about your data go to support@seqavo.com.