Privacy and security

This page says what MailPush does with your Gmail and your data, in plain words. Every promise on it matches what the software does, and an automated test checks the promise about email content on every build.

In short: your email passes through MailPush on its way to your device and is not saved. MailPush keeps a list of your message ids and labels, your label names and, if you turn on Calendar, the names of your calendars, and the access Google gave it, which is encrypted. You can delete all of it at any time.

What MailPush asks Google for

When you connect, Google shows you what MailPush asks for. It asks for two things:

If you turn on Calendar, it asks for two more permissions, which the Calendar section below describes.

MailPush uses this access only to do what your device asks: to learn about new mail, to fetch a message when your device opens it, to change a message when you change it on your device, and to send the mail you send.

Your email passes through and is not saved

Email content is only in transit. It passes through the MailPush server while it is delivered to your device, and it is never saved in MailPush's database, in its files or in its logs, apart from the exception below. That covers message text, attachments, subjects, senders, recipients and dates.

When your device opens a message, the server holds it in memory for up to 10 minutes so that its attachments load without asking Gmail again. It is never written to disk.

One short lived exception: while your device sends a message of about 16 KB or more, the web server holds it in a temporary file until that request ends, which usually takes a few seconds. A large calendar change is handled the same way.

Apple Mail keeps copies of the mail it downloads on your device, as it does for any account.

What MailPush keeps

To work, the server keeps this about you:

Logs outside MailPush

MailPush is reached through the website in front of MailPush, a reverse proxy that the operator runs. It keeps its own access log, which MailPush does not control and does not delete. That log holds the full address of every page that was visited, with anything after a question mark, and the visitor's internet address and the time. So it holds the one time links from MailPush emails, the page Google sends you back to after you allow access, and the address your phone uses to sync, which contains your Gmail address and your device id. A link from an email stops working once it is used, and in any case after 10 minutes for signing in, 30 minutes for confirming a request and 7 days for an invitation. How long that log is kept, and whether it is kept at all, is the operator's choice. The operator's instructions for MailPush say how to limit it or turn it off.

Calendar

Calendar is optional. When you turn it on, Google asks for two more permissions: to see and change the events of your calendars, and to see your list of calendars. They are called calendar.events and calendar.calendarlist.readonly. MailPush never asks for the wider calendar permission. It asks for these two only from people who turn Calendar on.

Event content passes through MailPush only in memory. That means titles, start and end times, time zones, repeat rules, places, notes, guests, organizers, alerts, and attachment and video call links. It is never written to the database, to files or to logs. The one exception is the short lived temporary file of a large request, which the section Your email passes through and is not saved describes. No title, place, note or guest of an event is stored. While MailPush answers your device's date window, the answer is kept in memory as item ids and version values only.

What MailPush keeps in its database for Calendar is bookkeeping:

For a changed or deleted occurrence of a repeating event, Google's id contains the date and time of that occurrence, so those dates are kept in the ids.

The names of your calendars are kept like label names: they are the folder names on your device, so they are in the database and in your devices' folder state on the server. They are never written to a log. MailPush asks Google to tell it when a calendar changes. The notices from Google carry no event content, and MailPush ignores any notice it cannot match to one of its own subscriptions.

Turning Calendar off removes your calendars from your devices, stops the notifications and deletes this data. Google cannot take back the calendar permission alone without also taking back mail access, so the permission stays until you delete your account or remove MailPush in your Google Account settings, which also stops mail.

What the person who runs MailPush can see

The person who runs MailPush uses an admin page. It shows:

It never shows your email: no text, subjects, senders, recipients or attachments. The operator can also read the server's logs, which hold times, ids, addresses and errors.

MailPush holds your Google access

So that it can work while your phone is asleep, the server holds the access Google gave MailPush for your account. It is encrypted, but whoever controls the server could technically use that access to read your Gmail, and, if Calendar is on, to read and change your calendar events. MailPush's code uses it only to deliver and change mail as your device asks.

You can take the access away at any time. Delete your account here, or remove MailPush from the list of apps with access to your account in your Google Account settings.

Deleting your account

You can delete your account on your account page. MailPush emails you a code first, and you type your Gmail address to confirm. The person who runs MailPush can also delete accounts. Deleting an account does this:

What remains after deletion

If you come back, you can ask for access again.

Your note and the emails MailPush sends

The note you can write when you ask for access is emailed to the person who runs MailPush, who reads it before deciding. MailPush deletes its own copy when you connect, the request is declined or it expires. A request you confirmed keeps it until the operator decides. The copy in the operator's mailbox stays there until the operator deletes it.

A message you send on the Contact us page is emailed to the person who runs MailPush, with your address as the reply address. MailPush does not store the message and does not write it to its logs. The copy in the operator's mailbox stays there until the operator deletes it.

MailPush sends its own emails to you (confirmation codes, invitations and sign in codes) through the operator's email provider.

How MailPush protects your data

Google API Services User Data Policy

MailPush's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In plain words, about the data MailPush gets from your Google account:

Contact

For a question about privacy or security, or to report a problem, use the Contact us page.