Privacy Policy
Epistles ("we", "us") builds a cross-platform email client. This policy explains how we collect, use, disclose, and safeguard information when you use our websites, apps, and related services (the "Services"). Read it alongside our Terms of Service.
1. Information we collect
1.1 Account and product data
When you register or use Epistles, we may process:
- Account identifiers such as email address and profile details you provide.
- Authentication and session data needed to keep you signed in securely.
- Diagnostic, performance, and crash data you choose to share with us.
- Support communications when you contact us.
1.2 Email content and provider data
Epistles connects to your email providers to synchronize messages, attachments, contacts, and settings according to the features you enable. Your messages are stored on your own device for offline access and search. We do not store the content or bodies of your email on our servers. Where a feature needs server support, such as sending you a notification that new mail has arrived, our relay handles only the limited metadata required for that feature (for example the sender and subject line) and does not retain your message content.
1.3 Sign-in with third parties
When you authenticate with a provider such as Google, Microsoft, Fastmail, or Apple, we receive identifiers and profile information according to that provider's consent screen, and we request only the scopes needed for the email, contacts, and calendar features you use. For Google accounts, please also read section 2 on Google user data and Limited Use.
2. Google user data and Limited Use
If you connect a Google account, Epistles requests access through Google OAuth and uses that access only to provide the email features you turn on. The Google data we work with includes:
- Gmail messages, so the app can sync your mail, search it on your device, and let you read, organize, and send email.
- Google Contacts, so the app can show and manage the people you correspond with.
- Google Calendar, so the app can show and manage your events and reminders.
- Basic profile information such as your name and email address, used to identify the connected account.
Your Gmail messages are processed to deliver these features and are stored on your own device for offline access and search. We do not keep the content or bodies of your email on our servers. To notify you of new mail while your device is asleep, our relay handles a small amount of metadata such as the sender and subject line for the moment it takes to send the notification, and it does not retain that content afterward. Connection credentials are held in encrypted form so the app can stay signed in, and the cross-device Cloud Vault stores only data that is encrypted on your device with a key we cannot read.
We do not sell Google user data, we do not use it for advertising, and we do not use it to train generalized or standalone artificial intelligence or machine learning models. We do not let humans read your Google data except where you give explicit consent for a specific request, where it is necessary for security purposes such as investigating abuse, or where we are required to do so by law.
Limited Use
Epistles' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use information
- Provide, operate, maintain, and improve the Services.
- Authenticate users, prevent fraud and abuse, and protect security.
- Provide customer support and respond to inquiries.
- Comply with legal obligations and enforce our terms.
4. Sharing and subprocessors
We do not sell your personal information
We do not sell, rent, or trade your personal information to data brokers. We may share information with service providers who assist us (for example hosting, email delivery, analytics, or error reporting), subject to contractual obligations consistent with this policy.
We may disclose information if required by law, legal process, or to protect the rights, safety, and security of users, Epistles, or the public.
5. Retention
We retain information for as long as needed to provide the Services, comply with law, resolve disputes, and enforce agreements. Retention of email content on your devices is controlled by your app settings and storage. When you disconnect an account or delete your Epistles account, we delete the connection credentials we hold for it and ask the provider to revoke our access, so the data associated with that connection is removed from our servers.
6. Security
We implement technical and organizational measures to protect information, including encryption in transit where supported by providers and features. No method of transmission or storage is completely secure.
7. International transfers
We may process information in countries where we or our service providers operate. Where required, we use appropriate safeguards for cross-border transfers.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. You may also unsubscribe from marketing communications where applicable. Contact us to exercise these rights; we may need to verify your request.
9. Children
The Services are not directed to children under the age where parental consent is required in their jurisdiction. We do not knowingly collect personal information from children in violation of applicable law.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date.
11. Contact
For privacy questions or requests, contact:
Product: Epistles
Email: support@epistles.com
By using Epistles, you acknowledge that you have read this Privacy Policy.