Privacy
Effective July 2026 · applies to the Postel Mail macOS app and postelmail.com
What Postel Mail accesses
Postel Mail connects directly from your Mac to Google’s APIs after you authorize a Gmail account. The initial connection requests permission to read your mailbox and to send messages you explicitly choose to send. Two further permissions are requested only when you first use the matching feature: managing drafts (the first time you compose) and organizing mail — archive, labels, read state (the first time you triage). OAuth credentials are stored in the macOS Keychain.
Where your data lives
Mail metadata, opened message bodies, synchronization state, and recoverable drafts may be stored locally in your Mac’s Application Support directory. No mail content, message metadata, or OAuth token is transmitted to BNFY servers. Push notifications, when enabled, use a content-free relay that stores no Gmail credentials and cannot read mail.
Remote images
Remote images are blocked by default, so senders learn neither your IP address nor when you opened a message. You can load images for an individual message, or enable automatic loading in Settings — the setting explains that automatic loading may reveal your IP address and message-open time to a sender.
What Postel Mail does not do
No advertising, no analytics, no cross-app tracking, and no sale of user data. Message bodies, subjects, addresses, OAuth tokens, MIME payloads, and attachment contents are excluded from diagnostic logging. Diagnostics remain local and export-only.
Retention and deletion
Removing your account from Postel Mail clears its account-scoped cache after pending draft recovery is resolved. Moving the app to the Trash does not remove its local data by itself: to erase everything, also remove the app’s folder from your Mac’s Application Support directory — the support page walks through it. Because BNFY holds no copy of your mail, there is nothing further to delete on our side.
Google API Services — Limited Use
Postel Mail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide the mail client features you see, is never used for advertising, and is never transferred except as necessary to provide those features, for security, or to comply with law.
The website’s mailing list
Separately from the app: if you enter your email address in the signup form on this site, we store that address with our email provider, Resend, for one purpose — sending you the launch announcement and, later, release notes you can opt out of. We record the address and the fact that it came from postelmail.com; nothing else. Every email includes an unsubscribe link, and you can have the address deleted entirely by writing to [email protected]. This is the only personal data this website collects: no analytics, no tracking pixels, no third-party scripts.
Contact
Questions about this policy: [email protected].