OpenMailbox
OpenMailbox privacy policy
Last updated: 10 October 2026
1. Introduction
OpenMailbox is a desktop mail app made by OpenApps ("we", "us"). This policy says what the app does with your data, including data from your Google account. It covers the app, and in section 9 this website.
The short version: the app runs on your computer, your mail stays on your computer, and we do not receive it.
2. What the app handles, and where it is kept
| What | Where it is kept | Sent to OpenApps? |
|---|---|---|
| Your mail: messages, attachments, folders, drafts | An encrypted database file on your computer | No |
| Mailbox passwords and provider sign-ins (such as the permission Google issues) | Your computer's keychain (macOS Keychain; on Windows, a file protected by Windows for your user account) | No |
| Your sharing identity: a key pair made on your computer | The private half in the keychain | No |
| The record of what people and agents you shared with did | The same encrypted database | No |
The app contains no advertising, no analytics and no usage tracking.
3. Google user data
If you add a Gmail mailbox with Sign in with Google, the app asks Google for these permissions:
- Read, compose, send and permanently delete all your email from Gmail (
https://mail.google.com/). Google requires this permission for any mail app that connects over its standard mail servers (IMAP and SMTP). - Your email address (
openid,email), so the app knows which mailbox signed in.
What the app accesses. Your Gmail messages, attachments, folders and labels, and your email address.
How it is used. Only to provide the mail features you see: to show and search your mail, to send the mail you write, and to mark, star, archive or delete mail when you ask. It is not used for advertising, it is not sold, it is not used to train AI models, and nobody at OpenApps can read it, because it never reaches us.
How it is stored. The sign-in Google issues is kept in your computer's keychain. Mail fetched from Gmail is kept in the app's encrypted database on your computer.
Who it is shared with. Nobody, unless you choose to share a mailbox as described in section 4.
OpenMailbox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Sharing you choose to do
OpenMailbox lets you share a group of mailboxes with other people, or with an AI agent on your computer. Nothing is shared until you invite someone, and every invitation is made out to one specific person's key.
- A full member works the mailboxes from their own device. To make that possible, the app sends the sign-in for each mailbox in the group, which for a Gmail mailbox is the permission Google issued, to that person's device. It travels encrypted so that only their device can read it. Their device then fetches the mail directly from the provider. The app tells you this before you invite them.
- A limited member receives no sign-in. Their app asks yours for what they are allowed to see, and your app sends them only that, encrypted to their device. You can restrict them to reading, and to mail from senders you name.
- An AI agent you give access to reads mail through the app on your computer. What it reads goes to whichever AI service runs that agent, which is your choice and not ours. The app says so when you set one up, and holds anything the agent wants to send until you approve it.
You can see what each person or agent did, change what they may do, and remove them. Removing a limited member or an agent ends their access at once. A full member already holds the sign-in, so to be sure they no longer have access you should also remove OpenMailbox's access in your Google Account or change the mailbox password; the app tells you this when you remove them.
5. What the app connects to
- Your mail providers, to fetch and send mail, and their sign-in services, to sign you in.
- A relay, only if you use sharing. It passes encrypted messages between your device and the devices of people you shared with. By default this is a relay we run; you can choose another. The relay cannot read the messages. Like any server, it sees the public keys involved, when messages pass, and the internet address they come from.
- The server of a message's sender, only when you press Load images on that message.
- Your own domain, when you add a mailbox on a domain the app does not know, to look up its mail settings.
- OpenWallet ID, only if you choose to verify your sharing identity with it. That shares your email address and your public key with that service.
The app connects to nothing else.
6. Keeping and deleting
- Removing a mailbox in the app deletes its mail from the app's database and its sign-in from the keychain. Nothing is deleted at the provider.
- You can withdraw Google's permission at any time in your Google Account.
- Uninstalling the app and deleting its data folder removes everything it kept.
- Because we hold none of your mail or sign-ins, there is nothing for us to delete on our side.
7. Security
Connections to mail servers are encrypted. The database on your computer is encrypted with a key held in your keychain. What passes between shared devices is encrypted end to end. Anyone with access to your unlocked computer account can open the app, so protect that account as you would your mail.
8. Children
OpenMailbox is not directed at children under 13.
9. This website
openmailbox.si is a plain website. It sets no cookies, shows no ads, counts no page views, and loads its fonts from our own server. Our web server keeps an ordinary log of requests (your IP address, your browser's description and the pages requested) to keep the site running and to stop abuse. Those logs are deleted after 90 days.
10. Changes to this policy
If we change this policy we will change the date at the top. A change to what the app does with Google user data would come with a new version of the app, and this page will describe it before that version is released.
11. Contact
Questions and requests: contact@openapps.network.