Privacy policy
Last updated 28 September 2026
Who runs Chatmail
Chatmail is a private, self-hosted email client operated by Edwin Hirawan for his own use. It is not offered to the public. Questions: [email protected].
Data Chatmail accesses
When the operator connects one of his own Google accounts, Chatmail requests access to:
- Basic profile (name, email address, profile picture) to sign in and label the account.
- Gmail (messages, attachments, labels and metadata) to display, search, tag, archive, draft, send and delete email in that mailbox.
- Google Calendar events to create or update calendar events from emails, such as meeting invitations.
How the data is used
- Only to provide Chatmail's features to the operator: reading, organising and replying to his own email.
- It is not sold, not used for advertising, and not used to build profiles of anyone.
- It is not used to train AI or machine-learning models.
Where the data is stored
Email content, tags, rules and the Google access tokens are stored on the operator's own computer. They are not uploaded to any Chatmail server, because there is none. The app is reachable only over the operator's private network, using HTTPS.
Sharing with third parties
Data is shared only when the operator turns on an optional feature, and only as much as that feature needs:
- AI features: message text may be sent to an AI provider (for example Anthropic's API) or to a model running on the operator's own computer, to summarise or draft replies.
- Notifications: short message previews may be sent to the operator's own devices through browser push, Telegram or WhatsApp.
Nothing is shared with anyone else, except where required by law.
Google API data
Chatmail's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Keeping and deleting data
Data is kept until the operator removes an account from Chatmail or deletes the app's data. Access can be revoked at any time at myaccount.google.com/permissions. To request deletion, email [email protected].
Changes
If this policy changes, the date at the top will be updated.