Privacy Policy
Last updated October 3, 2026
Postmaster is an email client for macOS. It runs entirely on your Mac and connects directly to your email providers. Postmaster has no servers of its own, so your email, credentials and account data never pass through or are stored by us.
Data Postmaster accesses
When you add an account, Postmaster accesses only what it needs to work as your email client:
- Account details: your email address and name, used to identify the account and to fill in the sender of messages you write.
- Email: messages, attachments, drafts, folders and labels, used to show your mail, search it, and carry out actions you take such as reading, sending, replying, moving, labeling, archiving and deleting.
- Credentials: passwords or OAuth tokens, used only to sign in to your provider.
Google user data
If you sign in with Google, Postmaster asks for your basic profile (name and email address) and full access to Gmail (https://mail.google.com/). Full Gmail access is needed because Postmaster connects to Gmail over IMAP and SMTP, which accept only this permission, so it can read, organize, send and delete your mail when you ask it to.
Google user data is used only to provide Postmaster’s email features to you. Postmaster does not:
- send your Google user data to us or to any server other than Google’s;
- sell your data or transfer it to third parties, including advertising platforms, data brokers or information resellers;
- use your data for advertising, or to determine creditworthiness or for lending purposes;
- use your data to develop, improve or train generalized or non-personalized AI or machine learning models;
- allow any person to read your data. Only you can see your mail in the app.
Postmaster’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Storage and security
Passwords and OAuth tokens are stored in the macOS Keychain, which encrypts them on your device. Postmaster keeps a cache of your messages, attachments and settings in your user Library folder on your Mac so mail loads quickly and works offline. All connections to email providers use TLS encryption.
Other network connections
Apart from your email providers, Postmaster may connect to:
- Mail server discovery: when you add an account from a provider Postmaster doesn’t already know, it looks up the settings for your email domain from that domain’s autoconfiguration service and from Mozilla Thunderbird’s public configuration database. Only the domain or email address being set up is sent.
- Sender logos: Postmaster may download logos published by senders through BIMI, directly from the sender’s servers.
- Remote content: images and other remote content in emails load only if you choose to show them. Loading remote content can let a sender know you opened their message.
Postmaster contains no analytics, advertising or tracking, and does not collect crash reports or usage data.
Removing your data
Removing an account in Postmaster’s settings deletes its credentials from the Keychain and its cached mail from your Mac. Deleting the app and its data removes everything Postmaster stored. You can also revoke Postmaster’s access to your Google account at any time from Google Account permissions. Your mail itself remains with your email provider.
Children
Postmaster is not directed at children under 13 and does not knowingly collect their information.
Changes
If this policy changes, the updated version will be posted on this page with a new date.
Contact
For questions about this policy, open an issue on GitHub.