Privacy policy
The short version
imaily runs on your computer. Your email is read by the application on your Mac directly from your email provider, and everything imaily stores is stored on your Mac. We do not operate a server that receives, stores or processes your email. We do not sell, rent or share your data with anyone.
Who we are
imaily is made by Sociably Media (Yorgos Kastritseas), Athens, Greece. Contact: [email protected].
What the application accesses
- Your mailboxes. imaily connects to the mail accounts you add, using IMAP to read and SMTP to send, with the credentials or sign-in you provide. It reads message headers, and message bodies for messages you open or that it needs to classify (for example receipts). It can move messages to your provider's Bin folder and mark them read when you ask it to. It never permanently deletes mail.
- Credentials. App-specific passwords and sign-in tokens are stored on your Mac in your user configuration folder with owner-only permissions. They are sent only to your own mail provider.
- Local database. Standing rules, reminders, reply watches, a cache of recent briefings and receipts, and the things you ask imaily to remember are kept in a local SQLite file on your Mac. Delete the file and it is gone.
What leaves your computer
- Your mail provider. IMAP and SMTP traffic between your Mac and your provider, encrypted in transit (TLS).
- The AI provider. To write the briefing and understand your requests, imaily sends message subjects, sender names and addresses, short text snippets, and your typed requests to the AI provider you configure (by default Anthropic), using your own API key. That provider's terms govern that data; under Anthropic's API terms, data sent through the API is not used to train models. You can disable AI entirely; imaily then classifies mail with local rules only.
- Unsubscribe requests. When you click Unsubscribe, imaily sends the sender's own one-click unsubscribe request (RFC 8058) or opens their unsubscribe page in your browser.
- Remote images. With "Load images" on, images inside a mail are fetched from the sender's server when you open it, which lets senders know it was opened. You can turn this off in Settings.
Nothing else leaves your computer. imaily has no analytics, no telemetry, no crash reporting and no account system.
Google user data
When Sign in with Google is available, imaily will request the https://mail.google.com/ scope, which is required to read and send mail over IMAP and SMTP. That access is used only to show you your own mail inside imaily, to produce your briefing, to move or mark messages you ask it to, and to send mail you write. Google user data is processed on your Mac and is not transferred to any imaily server, because none exists. It is shared with third parties only as described above (your configured AI provider, with your key) and is never used for advertising, sold, or used to build profiles.
imaily's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke imaily's access at any time at myaccount.google.com/permissions; removing the account inside imaily also deletes the stored token from your Mac.
Your rights (GDPR)
Because your data stays on your computer, you exercise most rights yourself: remove an account in Settings to delete its credentials, delete the local database to erase everything imaily learned. If you emailed us, you can ask us to delete that correspondence at any time. Supervisory authority for Greece: the Hellenic Data Protection Authority (dpa.gr).
This website
imaily.app is a static site served through Cloudflare. It sets no cookies and loads nothing from third parties — fonts are served from this site. We use Cloudflare Web Analytics, which is cookieless and does not fingerprint or track you across sites; it tells us page views and referrers, nothing about you. Cloudflare may process connection data (such as your IP address) to serve and protect the site, under its own privacy policy. There is no Google Analytics or other third-party tracking.
Changes
If this policy changes, the date at the top changes and the application's What's new log will say so.