Privacy Policy

Privacy Policy

Effective date: October 9, 2026

This Privacy Policy applies to all software applications published by [Publisher Name]
("we", "us", "our"). This includes desktop, mobile, and web apps and their websites (each an
"App"). It explains what information our Apps handle, where it goes, and the choices you have.

Our default approach is simple: your data stays on your device or with the services you choose to
connect. We don’t sell it, we don’t track you, and we don’t use it for advertising.
Where an App
works differently, the difference is listed in Appendix A
or in the App itself.

1. Information we collect

Information you give us

  • Support requests. If you email us or file an issue, we receive your message, your email
    address, and anything you choose to attach, such as screenshots or logs.
  • Purchases. If an App is sold, payment is handled by the store or payment processor (for
    example, the Apple App Store or Stripe). We receive only limited information from them, such as
    confirmation of the purchase and, where applicable, your email address. We never receive your full
    card details.

Information processed by the Apps on your device

Most of our Apps store their data locally, on your device. That data never reaches us. Depending on
the App, it can include documents, settings, cached content, and sign-in tokens. Sign-in tokens are
kept in the operating system’s secure storage, such as the macOS Keychain.

Information from third-party services you connect

Some Apps let you connect an account with another service, such as Google, Apple, GitHub, or
Dropbox. When you do, you sign in on that service’s own page, and the App receives only the access
you approve. The App uses that access only to provide the features you use. Data goes directly
between your device and that service
, unless Appendix A says otherwise.

Information collected automatically

By default, our Apps do not include analytics, advertising SDKs, or tracking. If an App
collects crash reports or anonymous usage statistics, Appendix A says so, and where possible the
App lets you turn it off. Like any website, our websites’ hosting provider may keep standard server
logs, such as IP address, browser type, and pages visited, for security and reliability.

2. How we use information

We use information only to:

  • provide, maintain, and improve the Apps;
  • respond to support requests;
  • process purchases and licenses;
  • protect against fraud, abuse, and security threats; and
  • comply with legal obligations.

We do not sell or rent personal information. We do not use it for advertising. We do not use
your content to train artificial-intelligence models.

3. How information is shared

We share information only:

  • with service providers that help us run our business, such as hosting, email, and payment
    processing. They act on our instructions and are bound to protect the data;
  • when required by law, or to protect the rights, safety, or property of our users or others;
  • in a business transfer, such as a merger or acquisition. In that case this policy continues
    to apply to information already collected; or
  • with your consent.

4. Third-party account data (including Google user data)

When an App accesses data through a third-party API, its use of that data follows the provider’s
policies. For Google APIs, our Apps’ use and transfer of information received from Google APIs
complies with the
Google API Services User Data Policy,
including the Limited Use requirements:

  • data is used only to provide or improve user-facing features of the App;
  • data is not transferred to others, except as needed to provide those features, to comply with
    law, or as part of a merger or acquisition with notice to you;
  • data is not used for advertising; and
  • humans do not read the data, except with your explicit consent, for security purposes, to comply
    with law, or when the data is aggregated and anonymized for internal operations.

You can revoke an App’s access at any time in the provider’s account settings. For Google, that is
myaccount.google.com/permissions.

5. Data retention and deletion

  • Data on your device stays until you delete it in the App or uninstall the App. Some operating
    systems keep app data after you uninstall. Appendix A lists where each App stores its data.
  • Support emails are kept as long as needed to help you and for our records, and are then
    deleted.
  • Purchase records are kept as long as tax and accounting law requires.

You can ask us to delete any personal information we hold about you by contacting us (see
Section 10).

6. Security

We use reasonable safeguards appropriate to each App: encrypted connections (HTTPS/TLS), the
operating system’s secure credential storage, and sandboxing where available. No method of
transmission or storage is perfectly secure. You also help protect your data by keeping your device
locked and up to date.

7. Your rights

Depending on where you live, for example in the EU/UK under the GDPR or in California under the
CCPA/CPRA, you may have the right to:

  • access the personal information we hold about you;
  • correct it or have it deleted;
  • object to or restrict certain processing;
  • receive a portable copy; and
  • withdraw consent you previously gave.

To use any of these rights, contact us. We will respond within the time the law requires. We will
not discriminate against you for exercising them. Where the GDPR applies, our legal bases are
performance of a contract (providing the App), legitimate interests (security and support), legal
obligation, and consent where we ask for it.

8. International transfers

We and our service providers may process information in countries other than yours. Where required,
we use appropriate safeguards for those transfers, such as Standard Contractual Clauses.

9. Children

Our Apps are not directed to children under 13, or the minimum age in your country, and we do not
knowingly collect their personal information. If you believe a child has given us information,
contact us and we will delete it.

10. Contact

[Publisher Name]
[Postal address — optional unless required where you operate]
Email: [contact email]

11. Changes to this policy

We may update this policy. When we do, we will change the effective date above. If a change is
material, we will give notice on our website, in the App, or in release notes before it takes effect.


Appendix A: App-specific disclosures

Each App’s entry describes what it accesses beyond the defaults above. If an App is not listed, the
defaults apply: data stays on the device, and there is no analytics or tracking.

LightMail (macOS email client)

Connected serviceGoogle (Gmail), scope https://www.googleapis.com/auth/gmail.modify: read, organize, and send mail. The App cannot permanently delete mail outside the Trash.
Where data goesDirectly between your Mac and accounts.google.com, oauth2.googleapis.com, and gmail.googleapis.com. There is no publisher server.
Stored on your deviceCopies of messages, labels, and a search index in ~/Library/Application Support/LightMail. Opened attachments in ~/Library/Caches/LightMail. Autocomplete contacts drawn from your mail. Sign-in tokens in the macOS Keychain. Preferences in macOS user defaults.
Analytics / trackingNone.
Remote contentOpening an email may load images from the sender’s server, which can reveal to the sender that the message was opened, along with your IP address.
DeletionPreferences › Accounts › Remove Account… deletes that account’s mail, index, and credentials, and clears the attachment cache. Contacts are cleared with the last account. Nothing is deleted from Gmail.