Privacy

TL;DR: your email passes through MailPush on its way to your device and is not saved. We keep a list of your message ids and labels, your label names, the names of your calendars if you turn on Calendar, and the access Google gave MailPush, encrypted. You can delete all of it at any time.

On this page

What MailPush asks Google for

When you connect, Google shows you what MailPush asks for. There are two things:

  • Read, organize and send your Gmail. MailPush needs this to show your mail in Apple Mail, keep its list of your messages and labels up to date, mark mail as read or flagged, move it between folders, labels and Trash, and send the mail you write on your iPhone or iPad. This permission cannot delete mail for good, and MailPush never asks for the wider permission that could.
  • Your basic sign in identity. This gives MailPush Google's permanent id for your Google account. We use it to count the Google accounts that have ever connected (see Deleting your account below) and to check that you picked the account that was invited. It does not give us your name, your photo or your contacts.

If you turn on Calendar, MailPush asks for two more permissions, described under Calendar below.

MailPush uses this access only to do what your device asks: learn about new mail, fetch a message when your device opens it, change a message when you change it on your device, and send the mail you send.

Your email passes through and is not saved

Email content is only in transit. It passes through the MailPush server on its way to your device, and it is never saved in MailPush's database, files or logs. That covers message text, attachments, subjects, senders, recipients and dates.

What MailPush keeps

To work, the server keeps this about you:

  • Your Gmail address and the state of your account.
  • The access Google gave MailPush for your account, encrypted. The key is not stored with the data.
  • A one way hash of your MailPush password. Nobody can read it back. It is shown to you once.
  • A list of your messages. For each one: the Gmail id, the conversation id, the system labels (Inbox, Sent, Trash and so on), the ids of your own labels on it, and its folder. No text.
  • Your label names. They are the one piece of your mail's content that MailPush keeps, because they are the folder names on your device. They are never written to a log.
  • For each device: what it says about itself when it sets up the account (its type, name, model and system version and, if it sends them, a phone number or a hardware id), its sync state (message ids and whether each message is read or flagged), the Gmail ids of the messages it was given, and a one way hash of its device id and key with the time of its last sign in, which is forgotten after 90 days without one.
  • For mail you send: one way hashes of the message identifiers for 7 days, or until it is settled when Gmail did not confirm the send, so the same message is never sent twice.
  • Logs. MailPush's own log files hold times, ids, addresses and errors, never email content. By default they are deleted after 90 days. The web server's access log is one of them: for each page request it holds the time, the internet address the web server sees, the page address without anything after a question mark, the status and size of the answer, and the name of your app.

Calendar

Calendar is optional. When you turn it on, Google asks for two more permissions: to see and change the events of your calendars, and to see your list of calendars. They are called calendar.events and calendar.calendarlist.readonly. MailPush never asks for the wider calendar permission, and asks for these two only from people who turn Calendar on.

Event content passes through MailPush only in memory: titles, start and end times, time zones, repeat rules, places, notes, guests, organizers, alerts, attachment and video call links, and the phone numbers and PINs to join a call. It is never written to the database, to files or to logs. No title, place, note or guest of an event is stored. While MailPush answers your device's date window, the answer is kept in memory as item ids and version values only.

Turning Calendar off removes your calendars from your devices, stops the notifications and deletes what MailPush kept about them. Google does not let an app give back the calendar permission on its own without also giving up mail access, so the permission stays until you delete your account or remove MailPush in your Google Account settings, which also stops mail.

Deleting your account

You can delete your account on your account page. We email you a code first, and you type your Gmail address to confirm. We can also delete accounts from the admin page. Deleting an account does this:

  • Your MailPush password stops working right away, and every sign in session ends.
  • MailPush asks Google to remove its access to your account. If Google does not answer, MailPush keeps trying for up to 24 hours. If every try fails, we are told, so we can ask you to remove MailPush in your Google Account settings yourself.
  • Your message list, label names, device sync data on the server, known device records, request and invitation records and any set aside records are deleted. So are your calendar names and the ids and version stamps of your events, and Google's notifications for your calendars are stopped. MailPush's database overwrites deleted data with zeros, so it is not left readable in unused parts of the database file.

If you come back later, you can ask for access again.

How MailPush protects your data

  • This site loads nothing from other websites. No trackers, no analytics, no ads, no outside fonts or scripts, and no CAPTCHAs. Its cookies keep you signed in and protect its forms. A separate cookie remembers your appearance choice (Auto, Light or Dark) for a year. It holds only that word and is not used for tracking.
  • You sign in with a code or a link sent to your email. Each one works once and expires after 10 minutes (30 minutes to confirm a request), and five wrong tries end a code.
  • Your Google access is encrypted, and your MailPush password, sessions, codes and links are stored as hashes, so a copy of the database alone cannot be used to sign in or to reach your Gmail.
  • Wrong MailPush passwords are limited and blocked, and so are requests, sign in attempts and emails.

Google API Services User Data Policy

MailPush's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In plain words, about the data MailPush gets from your Google account:

  • MailPush uses it only for the features you see: your Gmail in Apple Mail, and your Google Calendar in the Calendar app if you turn Calendar on.
  • MailPush does not pass it to anyone else, except as needed for those features, to keep the service secure (which includes an encrypted nightly backup of its own data, copied to our storage provider, which cannot read it) or to follow the law.
  • MailPush does not use it for ads and does not sell it. It does not use it to train artificial intelligence or machine learning models.
  • MailPush has no screen, log or tool that shows your email to anyone. It is not saved, and the admin page does not show it.

Contact

For a question about privacy or security, or to report a problem, contact us.