Privacy Policy
Last updated 14 July 2026
Engine Mail is a privacy-focused email workspace. This Privacy Policy applies to the Engine Mail applications, website, and related services. It explains what information we process, why we use it, when it leaves your device, who may receive it, how long we keep it, and the choices and rights available to you.
At a glance
- Your everyday mailbox is fetched directly from your email provider and stored in an encrypted database on your device.
- Our backend handles limited account, device, notification, collaboration, tracking, referral, support, and update data for the features you use.
- A few optional features send specific data off your device, most notably Secure Email Share, email tracking, cloud AI, deep URL analysis, and support diagnostics. Each is explained below.
- We do not sell your personal information or use it for cross-context behavioral advertising.
- AI can run locally. If you choose a cloud AI provider, requests go directly to that provider using your own API key after we apply a privacy scrub.
1Who we are & scope
This policy covers the Engine Mail macOS app, the website at enginemail.io, our API, our secure-share pages, and related services ("Engine Mail", "we", "us"). It does not cover your email provider (Gmail, Outlook, iCloud, Yahoo, custom IMAP/SMTP) or any AI provider you connect, which are governed by their own policies. For a formal identification of the legal entity acting as data controller, contact [email protected].
2Your Engine Mail account
You create a passwordless account with your email address and a 6-digit one-time code (sent by our email provider). We store your email address, a session token, your device's push token, your profile (a first name and a built-in or uploaded avatar), where you heard about us if you tell us, and your app settings. If you enable two-factor authentication, your TOTP secret is held encrypted on our server and you get single-use backup codes.
3On-device mailbox processing
During ordinary use, your synced mail, drafts, contacts, search index, tags, and the results of AI and security features are stored on your Mac in a strongly encrypted on-device database, with the encryption key held in your Mac's secure storage. Your mail is fetched directly from your provider by your Mac. In ordinary sync, message content is not stored in Engine Mail's backend. Some optional features (below) can send selected content or metadata off the device, and encryption at rest on our servers means data is protected in storage, not that we are technically unable to read it.
4Connected email providers & push
You connect Gmail and Outlook through the provider's OAuth flow, and iCloud or Yahoo with an app-specific password; you can also add a custom IMAP/SMTP account. Access tokens and app passwords are kept in your Mac's secure storage, and your email password is never seen or stored by us.
To notify you the instant new mail arrives, Gmail and Outlook push requires us to securely hold a credential on our server to run the provider's "new mail" watch. The provider sends our backend the event metadata needed to trigger a sync (for example, that new mail arrived and a change identifier), not your message bodies; your Mac then fetches the mail directly. This token is deleted when you disconnect the mailbox or delete your account.
5AI, cloud AI & MCP clients
AI is optional and off until you choose a model. It runs one of two ways:
- Local AI (on-device via Apple Intelligence or a local model), where nothing leaves your Mac.
- Bring-your-own-key, where you connect your own OpenAI, Anthropic, Google, or OpenRouter key. Requests go directly to that provider under your key; we do not proxy them or store your key (it stays in your Mac's secure storage) or the content. Before a cloud request, personal details are replaced with placeholders as an added safeguard, though a scrub cannot guarantee removal of every identifier. The provider processes the request under its own policy.
MCP is optional and runs locally (loopback only). If you authorize an external AI client with a scoped key, Engine Mail makes the permitted data available to that client on your device; the client may then process or transmit that data under its own privacy policy, which we do not control. Review the client, key scope, and approval settings before connecting it.
6Email tracking (your sent mail)
Engine Mail can tell you when an email you send is opened or its links are clicked. Outbound tracking is currently on by default; you can turn it off per-message or globally at any time, and disabling it is as easy as enabling it.
When tracking is active on a message, we process and store: the sending account and the recipient's email address; a message/subject identifier; sent, open, and click times and event counts; the clicked URL; the request's IP address (processed briefly, then stored only in an obscured, non-identifying form) plus a coarse, country-level location derived from it; and the email client, device type, and a bot or proxy classification. Reading-time and "forwarded" signals are estimates with known limitations, not confirmed facts. An IP hash is pseudonymization, not anonymization, because the raw network address necessarily reaches our server before it is hashed or geolocated. Because tracking involves people who never created an Engine Mail account, please use it lawfully and consider your recipients.
7Team collaboration
Team Workspace stores the team membership, invitations, access permissions, thread references, internal comments, mentions, and activity needed to provide collaboration. Internal comments are visible only to teammates and are never sent by email. Whether any mailbox content transits our backend depends on the sharing method used, and shared threads are surfaced to teammates through references, not by us storing your mailbox. Comments, mentions, invitations, roles, permissions, and activity history are kept until deleted, until access is removed, or until the team or account is deleted.
8Secure Email Share
If you create a Secure Email Share link, Engine Mail uploads a sanitized copy of the selected thread to our servers so a recipient can view it in a browser. This is the product's largest exception to on-device processing, so here is exactly how it works:
- What is uploaded: a sanitized copy of the thread, including sender names and email addresses, timestamps, subject, body, inline images, and headers. Attachments are included only if you separately choose to add them.
- Sanitization: scripts, forms, and trackers are stripped before the copy is hosted, and the viewer page runs with scripts disabled.
- Access: anyone with the link (and the 4-digit PIN, if you set one) can view it. The PIN is never stored in plain text, and access is protected by automated anti-abuse safeguards.
- Access records: we log limited view analytics, including timestamps, an obscured form of the IP, coarse location, the browser type, and whether the viewer appears to be an automated bot.
- Retention: the link expires after the period shown when you create it (at most 7 days) and you can revoke it at any time. The hosted copy and access records are deleted at expiry or revocation.
9Remote content & deep URL analysis
Remote images, fonts, scripts, forms, and tracking pixels are blocked by default in the reader (Privacy Shield). When you choose to allow remote content, your Mac loads it directly over a connection that does not carry your cookies. Attachment scanning and link inspection run on your Mac. When you run a deeper URL analysis, it may query public infrastructure (such as DNS and WHOIS) and reputation services about a domain; only the domain is checked by default, and a full URL is submitted only after you confirm, because URLs can contain sensitive paths and tokens.
10Support & diagnostics
When you send a support request or feature suggestion, we receive the category, severity or importance, subject, message body, app and OS version, your account identifier, and (if you attach it) an encrypted diagnostics bundle; a copy is emailed to our support team. Please avoid pasting unnecessary sensitive content into a support message.
Diagnostics and crash reporting are currently on by default. They never include your mail content, and email addresses are scrubbed before storage. On-device diagnostic logs are protected so that only our support team can open them, and never include message contents. You can turn diagnostics off in Settings. We use a third-party crash-reporting provider configured to scrub personal data.
11Referrals & rewards
If you invite someone, we process the recipient's email address, your optional message, a personal referral token, and events such as link opens, downloads, account creation, and mailbox connection, along with your reward state and invitation history. The inviter sees only a masked funnel status, not more about a recipient than is needed to award the referral.
12Website & cookies
On enginemail.io we collect only what a form needs: a waitlist signup (email plus platform), a contact message (which we email to ourselves), and referral links. Our application stores only an obscured, non-identifying form of the visitor IP to help prevent abuse; our network and hosting providers necessarily process the raw IP in transient network and security logs to deliver and protect the site. The site uses self-hosted fonts and carries no advertising or cross-site trackers.
13Service providers & subprocessors
We share the minimum needed with a small set of providers to run the service, never for advertising and never as a sale of your data:
- Apple, for push notifications and preference sync.
- A website, content-delivery, and DNS provider, which also provides an automated abuse check and delivery of app downloads.
- A cloud hosting provider, for our backend, database, object storage, and backups.
- A transactional email provider, for your sign-in codes and support and referral emails.
- A crash and performance reporting provider, with personal data scrubbed.
- Your email provider (Google, Microsoft, Apple, Yahoo, or your custom server), to sync and send your mail.
- Your AI provider, if you connect one (bring-your-own-key), reached directly under your key.
- Public DNS, WHOIS, and reputation services, used only when you run a deep URL analysis.
14International transfers
Our backend is hosted primarily in the European region, and the providers above may process data in other countries. Where required, transfers are protected by appropriate safeguards, such as the EU Standard Contractual Clauses and the UK Addendum. You can request information about the safeguards that apply by emailing [email protected].
15Data retention
We keep each type of data only as long as needed for the purpose it was collected. In general:
- Data on your Mac stays there until you delete it, remove the account, or reset the app.
- Account, profile, session, and device data is kept while your account is active and deleted on request.
- Provider push tokens are deleted when the mailbox is disconnected or the account is deleted.
- Secure shares and their access records are deleted at expiry (at most 7 days) or when you revoke them.
- Tracking events, diagnostics, and anti-abuse logs are retained only for a limited period.
- Support tickets and referral records are kept for a limited period after they are resolved or completed.
- Backups are purged within a short window after primary deletion.
16Your privacy rights & choices
- Access a copy of your personal data, correct it, export it, or delete it.
- Restrict or object to certain processing, and withdraw consent (without affecting earlier processing).
- Control notifications, contacts access, tracking, AI, and diagnostics from Settings, and remove a mailbox or your whole account at any time.
- Complain to your local data protection authority.
We honor rights under laws such as the GDPR and CCPA. We may need to verify your identity before acting, and we aim to respond within the timeframes required by law. To make a request, email [email protected].
17Regional disclosures (California & others)
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. Depending on where you live, you may have additional rights (such as the California rights to know, delete, correct, and opt out, or to use an authorized agent) and the right to non-discriminatory treatment for exercising them. Contact [email protected] to exercise any regional right.
18Children
Engine Mail is not intended for children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact [email protected] and we will investigate and delete it where required.
19Security
Your on-device database is strongly encrypted; keys and credentials are held in your Mac's secure storage; and connections to our backend use strong, verified encryption designed to block interception. No system is perfectly secure, but privacy is the foundation of how the app is built, not an afterthought.
20Changes
We may update this policy from time to time. The version posted here, with its "last updated" date, is current, and we will note material changes. Continued use after an update means you accept the revised policy.
21Contact
For privacy questions, data requests, or concerns, email [email protected]. For general help, email [email protected]. See also our Terms of Service.