Postel
Privacy

Privacy

Effective July 2026 · applies to the Postel Mail macOS app and postelmail.com

What Postel Mail accesses

Postel Mail connects directly from your Mac to Google’s APIs after you authorize a Gmail account. The initial connection requests permission to read your mailbox and to send messages you explicitly choose to send. Two further permissions are requested only when you first use the matching feature: managing drafts (the first time you compose) and organizing mail — archive, labels, read state (the first time you triage). OAuth credentials are stored in the macOS Keychain.

Where your data lives

Mail metadata, opened message bodies, synchronization state, and recoverable drafts may be stored locally in your Mac’s Application Support directory. No mail content, message metadata, or OAuth token is transmitted to BNFY servers.

Push notifications

When you enable Private Push Sync, Postel Mail uses a relay service operated by BNFY to deliver near-real-time Gmail refresh signals. The relay cannot read, send, or modify your mail and holds no Gmail OAuth credentials.

What the relay sees. When Gmail detects new activity it publishes two fields to a Google Cloud Pub/Sub topic: your account’s email address and an opaque numeric checkpoint (historyId). The relay receives this message, derives a one-way keyed hash (HMAC) from the email address to look up your registered device, and forwards a push signal. The raw email address is used only for that hash derivation and is not stored; the historyId is forwarded to your Mac and is not stored by the relay. Your Mac then uses its own locally held Gmail credentials to fetch the actual changes — the relay has no role in that fetch.

What the relay stores. A registration record in Google Cloud Firestore: the keyed hash of your email address (not the address itself), an installation identifier, an Apple Push Notification service (APNs) device token, your app version, and expiry timestamps. No message content, subject, sender, recipient, label, attachment, draft, or OAuth token is stored.

What reaches Apple. The push payload sent through APNs contains a registration identifier, the opaque historyId checkpoint, and an optional delivery-correlation identifier. No mail content is included.

Retention. Expired registrations stop receiving pushes immediately. The underlying record is deleted asynchronously: the relay sweeps every six hours while running, and a Firestore time-to-live policy provides a platform backstop that typically completes deletion within 24 hours of expiry. Disabling Private Push Sync or signing out deletes the registration promptly.

Infrastructure. The relay runs on Google Cloud Platform (Cloud Run, Pub/Sub, Firestore, Secret Manager). Apple Push Notification service delivers the signal to your Mac. These are the only third-party processors involved in the push path.

Remote images

Remote images are blocked by default, so senders learn neither your IP address nor when you opened a message. You can load images for an individual message, or enable automatic loading in Settings — the setting explains that automatic loading may reveal your IP address and message-open time to a sender.

Attachments you send

When you attach an image, Postel Mail strips its identifying metadata before the message leaves your Mac — EXIF, including the GPS coordinates recording where a photo was taken, along with the XMP and IPTC records that can carry your name, your camera, and your software. Orientation is kept, so the picture still arrives the right way up. This happens whether you paste the image, drag it in, or choose it from a file dialog.

Two limits are worth knowing. Other kinds of file — PDFs, documents, archives — are sent exactly as they are, so whatever metadata the application that made them wrote inside is still there. And when you forward a message, its attachments are passed through byte for byte: those are the original sender’s files, and quietly rewriting them would change what you were asked to pass along.

Google Contacts

Contact photos are off by default. If you enable Show contact photos, Postel Mail requests read-only access to your Google Contacts. Contact names, addresses, and photos are cached locally on your Mac, scoped to that Google account, and cleared when you disable the setting, disconnect or sign out, or switch accounts. Photos are fetched from Google’s CDN and matched to sender addresses on your device; Postel Mail does not send those addresses to a sender or an avatar service.

A matching photo means only that the address appears in your Google Contacts. It does not verify who sent the message.

Software updates

Postel Mail can check postelmail.com for new versions. Automatic checks are off initially; on the app’s second launch, it asks whether you want to enable them, and you can change that answer later in Settings. Until you opt in, Postel Mail checks only when you choose Check for Updates… from its menu. A check sends a standard web request whose user agent identifies Postel Mail, its running version, and the Sparkle updater version; as with any web request, the server sees your IP address. Postel Mail attaches no account, mail, device, or installation identifier and does not enable Sparkle’s optional system profile. Every update is cryptographically signed by us and verified on your Mac before it is installed.

What Postel Mail does not do

In the app: no advertising, no analytics, no cross-app tracking, and no sale of user data. Message bodies, subjects, addresses, OAuth tokens, MIME payloads, and attachment contents are excluded from diagnostic logging. Diagnostics remain local and export-only.

Retention and deletion

Removing your account from Postel Mail clears its account-scoped cache after pending draft recovery is resolved. Moving the app to the Trash does not remove its local data by itself: to erase everything, also remove the app’s folder from your Mac’s Application Support directory — the support page walks through it. Because BNFY holds no copy of your mail, there is nothing further to delete on our side.

Google API Services — Limited Use

Postel Mail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide the mail client features you see, is never used for advertising, and is never transferred except as necessary to provide those features, for security, or to comply with law.

The website’s mailing list

Separately from the app: if you enter your email address in the signup form on this site, we store that address with our email provider, Resend, for one purpose — sending you the launch announcement and, later, release notes you can opt out of. We record the address and the fact that it came from postelmail.com; nothing else. Every email includes an unsubscribe link, and you can have the address deleted entirely by writing to [email protected]. Beyond this address and the visit measurement described below, this website collects no personal data.

Website analytics

This site uses Google Analytics to count visits and see which pages are read. Google Analytics sets cookies in your browser and receives your IP address, rough location, and the pages you view; we have not enabled its advertising features. This measurement exists only on postelmail.com — the Postel Mail app itself contains no analytics. Google describes its handling of this data in the Google Privacy Policy.

Contact

Questions about this policy: [email protected].