1. Operator and scope
SmartMail is operated by 王以禧, an independent developer based in Singapore. Contact the operator at support@yoursmartmail.com for support and privacy questions.
This policy covers this website and the desktop Gmail core edition’s reading, searching, organizing, attachments, and sending functions. A separate SmartMail service account is not needed for these mailbox functions. Development builds with cloud AI are outside this edition; AI will require updated disclosures before it is enabled in a public release.
Your mailbox provider, websites you open from email, and external image hosts have their own privacy policies. Connecting a mailbox does not transfer ownership of it or its contents to SmartMail.
2. Information we handle
| Information | Purpose and location |
|---|---|
| Google account identifier, email address, and basic profile | Identify the mailbox you authorize. Google supplies the identity during sign-in; account information is stored on your device. |
| OAuth tokens and connection settings | Authorize direct Gmail API access from your desktop. Mail credentials use the operating system’s secure-storage mechanism. |
| Messages, senders, recipients, subjects, bodies, attachments, labels, and mailbox status | Display, search, and organize mail, retrieve attachments, synchronize read and starred status, and send messages. Mail is retrieved from Google and cached locally; outgoing messages are sent to Google. |
| Drafts, preferences, and related local email records | Support email features on your device. Exports and saved attachments are stored in locations you choose. Previewing an attachment can also create a temporary copy in the operating system’s temporary directory. |
| Website requests and information you send to support | Hosting and security can process IP addresses, request headers, and errors. Support receives information you choose to send. The website does not request Gmail mailbox access. |
The Gmail core edition does not upload email content or Gmail tokens to a SmartMail server or model provider. Connect and process only mailboxes and information you are authorized to use.
3. Gmail permissions and use
SmartMail requests openid, https://www.googleapis.com/auth/userinfo.email, and https://www.googleapis.com/auth/userinfo.profile to identify the account, plus https://www.googleapis.com/auth/gmail.modify for Gmail API access.
The mail permission supports reading and caching messages, retrieving attachments, marking messages read or starred, applying labels, archiving, moving messages to Trash, and sending messages you compose, replies, forwards, and calendar responses. Read-only access cannot support changes or sending; send-only access cannot display and organize mail. SmartMail does not implement immediate permanent deletion and does not request the full https://mail.google.com/ scope.
Google hosts sign-in and consent. Your Google password stays with Google. The desktop completes authorization through a temporary local callback using PKCE. The connection does not request Google Contacts or Workspace Directory access. Other mailbox providers continue to use their existing protocols.
SmartMail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used to provide the email functions described here. It is not sold, used for advertising, or used to train generalized AI models. The core edition has no cloud AI processing of Gmail data.
The developer does not receive access to your local mailbox cache through these functions. Do not send private email content, passwords, or authorization tokens to support. Gmail connection details explain authorization and revocation.
4. Cloud AI is disabled in this edition
Cloud summaries, AI writing, translation, and mailbox assistants are planned for a later release. They are not included in the Gmail core edition’s OAuth application or active data flow. OpenAI API is a provisional supplier choice; no production model, processing region, or retention configuration has been activated for this edition.
A United States server has been prepared for future SmartMail services, but it receives no Gmail email content from the core edition. Its location does not establish where a future model provider will process information.
Before enabling cloud email AI, SmartMail will disclose the actual provider, data sent, processing locations, retention and deletion arrangements, and required permissions, and complete any applicable Google review. This policy does not promise a future provider’s zero retention or a particular processing region.
6. Your choices
- Remove a mailbox in Settings → Account to remove its saved connection and associated local app data. This does not delete your Google account or undo messages already sent.
- Revoke SmartMail’s authorization through Google Account connections. Revocation stops future authorized access; it does not automatically erase data cached on your device.
- Use Settings → Safety → Load remote images to control external images. Loading them can reveal network information to the image host. Opening email links contacts the destination website.
- Review recipients, attachments, and message contents before sending. Archiving, labels, read status, stars, and moving a message to Trash affect your connected mailbox.
7. Storage, retention, and security
Mail caches and related records remain on your device until removed through the app or its local data is cleared. Removing a mailbox clears its associated cached messages, drafts, related insights, to-dos, and conversations in that app database. Attachment preview copies are outside that database; startup and normal exit attempt to remove them, but cleanup is best effort. Other installations, devices, saved files, temporary preview copies, and backups require separate removal.
Gmail tokens use platform secure storage. The local cache is not a promise of encrypted storage for every downloaded file or backup; protect your device and use operating-system security controls. Network mailbox operations use HTTPS with Google.
Google continues to store and process your mailbox under its own policies. The core edition has no SmartMail cloud copy of Gmail messages to retain or delete. If you contact support, provide only the information needed for your request; contact the operator to request removal of information you supplied.
8. Privacy requests and contact
Contact support@yoursmartmail.com for access, correction, or deletion requests concerning information you supplied to SmartMail, or for help removing local app data. We may need to verify that a request concerns your own information. Do not include passwords, access tokens, or private message contents.
Mailbox information held by Google is controlled through your Google account. Removing the desktop connection and revoking Google authorization are separate actions. See Support for current connection and local data controls.
This policy will be updated when the edition’s data handling changes, including before any public cloud AI feature is enabled. Material changes will be described here with an updated revision date.