Privacy and security
This page says what MailPush does with your Gmail and your data, in plain words. Every promise on it matches what the software does, and an automated test checks the promise about email content on every build.
In short: your email passes through MailPush on its way to your device and is not saved. MailPush keeps a list of your message ids and labels, your label names and, if you turn on Calendar, the names of your calendars, and the access Google gave it, which is encrypted. You can delete all of it at any time.
What MailPush asks Google for
When you connect, Google shows you what MailPush asks for. It asks for two things:
- Read, organize and send your Gmail. MailPush needs this to show your mail in Apple Mail, to keep a list of your messages and labels up to date, to mark mail as read or flagged, to move it between folders and labels or to Trash, and to send the mail you write on your iPhone or iPad. This permission does not let MailPush delete mail for good, and MailPush never asks for the wider permission that would.
- Your basic sign in identity. This gives MailPush Google's permanent id for your Google account. MailPush uses it to count the Google accounts that have ever connected (see Deleting your account below) and to check that the account you choose is the one that was invited. It does not give MailPush your name, your photo or your contacts.
If you turn on Calendar, it asks for two more permissions, which the Calendar section below describes.
MailPush uses this access only to do what your device asks: to learn about new mail, to fetch a message when your device opens it, to change a message when you change it on your device, and to send the mail you send.
Your email passes through and is not saved
Email content is only in transit. It passes through the MailPush server while it is delivered to your device, and it is never saved in MailPush's database, in its files or in its logs, apart from the exception below. That covers message text, attachments, subjects, senders, recipients and dates.
When your device opens a message, the server holds it in memory for up to 10 minutes so that its attachments load without asking Gmail again. It is never written to disk.
One short lived exception: while your device sends a message of about 16 KB or more, the web server holds it in a temporary file until that request ends, which usually takes a few seconds. A large calendar change is handled the same way.
Apple Mail keeps copies of the mail it downloads on your device, as it does for any account.
What MailPush keeps
To work, the server keeps this about you:
- Your Gmail address and the state of your account.
- The access Google gave MailPush for your account, encrypted. The key is not stored with the data.
- A one way hash of your phone password. MailPush cannot read it back. It is shown to you once.
- A list of your messages. For each one it holds the Gmail id, the conversation id, the system labels (Inbox, Sent, Trash and so on), the ids of your own labels on it and its folder. It holds no text.
- Your label names. They are the one piece of your mail's content that MailPush keeps, because they are the folder names on your device. They are never written to a log.
- For each device: what it says about itself when it sets up the account (its type, name, model and system version and, if it sends them, a phone number or a hardware id), its sync state (message ids and whether each message is read or flagged), the Gmail ids of the messages it was given, and a one way hash of its device id and key with the time of its last sign in, which is forgotten after 90 days without one.
- For mail you send: one way hashes of the message identifiers for 7 days, or until it is settled when Gmail did not confirm the send, so the same message is never sent twice.
- For a message that Gmail keeps failing to return: its Gmail id, your device id and its folders, until Gmail returns it.
- From this site: your request and invitation, with the note you wrote until you connect, the request is declined or it expires (a request you confirmed waits for the operator's decision and keeps its note until then); your sign in sessions, which last 30 days, and your sign in codes and links, which last minutes. Sessions, codes and links are stored only as hashes.
- Counters that limit abuse: how many emails went to an address, kept as a one way hash, and how many requests or wrong passwords came from one internet address, kept in memory. The admin sign in also keeps the address and time of its recent wrong passwords in a small file.
- Logs. MailPush's own log files on the server hold times, ids, addresses and errors, and never email content. By default they are deleted after 90 days. The web server's access log is one of them: for each page request it holds the time, the internet address the web server sees, the page address without anything after a question mark, the status and size of the answer, and the name of your app.
Logs outside MailPush
MailPush is reached through the website in front of MailPush, a reverse proxy that the operator runs. It keeps its own access log, which MailPush does not control and does not delete. That log holds the full address of every page that was visited, with anything after a question mark, and the visitor's internet address and the time. So it holds the one time links from MailPush emails, the page Google sends you back to after you allow access, and the address your phone uses to sync, which contains your Gmail address and your device id. A link from an email stops working once it is used, and in any case after 10 minutes for signing in, 30 minutes for confirming a request and 7 days for an invitation. How long that log is kept, and whether it is kept at all, is the operator's choice. The operator's instructions for MailPush say how to limit it or turn it off.
Calendar
Calendar is optional. When you turn it on, Google asks for two more permissions: to see and change the events of your calendars, and to see your list of calendars. They are called calendar.events and calendar.calendarlist.readonly. MailPush never asks for the wider calendar permission. It asks for these two only from people who turn Calendar on.
Event content passes through MailPush only in memory. That means titles, start and end times, time zones, repeat rules, places, notes, guests, organizers, alerts, and attachment and video call links. It is never written to the database, to files or to logs. The one exception is the short lived temporary file of a large request, which the section Your email passes through and is not saved describes. No title, place, note or guest of an event is stored. While MailPush answers your device's date window, the answer is kept in memory as item ids and version values only.
What MailPush keeps in its database for Calendar is bookkeeping:
- for each calendar: Google's id for it (for a calendar shared with you this can contain the address of the person who shared it), its name, your access to it, whether it is your main calendar, its time zone and Google's change marker for it;
- for each event: Google's id for it, its version stamp, whether it is a single event, a series or a changed occurrence of one, the id of its series and a one way hash of its iCalendar id;
- for each of your devices and each event: the version last sent to it;
- for each change that your device makes: a record with ids, the version the change was based on and a keyed one way hash of the result, never the result itself, which is deleted 7 days after it finishes;
- for notifications: the id of each subscription with Google, Google's id for what it watches, a one way hash of its secret token and its end time.
For a changed or deleted occurrence of a repeating event, Google's id contains the date and time of that occurrence, so those dates are kept in the ids.
The names of your calendars are kept like label names: they are the folder names on your device, so they are in the database and in your devices' folder state on the server. They are never written to a log. MailPush asks Google to tell it when a calendar changes. The notices from Google carry no event content, and MailPush ignores any notice it cannot match to one of its own subscriptions.
Turning Calendar off removes your calendars from your devices, stops the notifications and deletes this data. Google cannot take back the calendar permission alone without also taking back mail access, so the permission stays until you delete your account or remove MailPush in your Google Account settings, which also stops mail.
What the person who runs MailPush can see
The person who runs MailPush uses an admin page. It shows:
- your Gmail address and the state of your account, and when you last signed in to this site;
- how many messages you have in each folder;
- your Gmail label names, which are the folder names on each of your devices;
- whether Calendar is on for you, how many calendars you have, and the calendar names on each of your devices;
- your devices: their type, id, app, last sync and the sync state of each folder;
- the note you wrote when you asked for access;
- errors, and the internet address of any device that sent a wrong phone password.
It never shows your email: no text, subjects, senders, recipients or attachments. The operator can also read the server's logs, which hold times, ids, addresses and errors.
MailPush holds your Google access
So that it can work while your phone is asleep, the server holds the access Google gave MailPush for your account. It is encrypted, but whoever controls the server could technically use that access to read your Gmail, and, if Calendar is on, to read and change your calendar events. MailPush's code uses it only to deliver and change mail as your device asks.
You can take the access away at any time. Delete your account here, or remove MailPush from the list of apps with access to your account in your Google Account settings.
Deleting your account
You can delete your account on your account page. MailPush emails you a code first, and you type your Gmail address to confirm. The person who runs MailPush can also delete accounts. Deleting an account does this:
- Your phone password stops working at once, and every sign in session ends.
- MailPush asks Google to remove its access to your account. If Google does not answer, MailPush tries again for up to 24 hours. If every try fails, the operator is told, so that you can remove MailPush in your Google Account settings yourself.
- Your message list, label names, device sync data on the server, known device records, request and invitation records and any set aside records are deleted. So are your calendar names and the ids and version stamps of your events, and the notifications from Google for your calendars are stopped. MailPush's database overwrites deleted data with zeros, so it is not left readable in the unused parts of the database file.
What remains after deletion
- A counted identity, forever. Google limits an app it has not verified to 100 Google accounts over its whole life, and removing someone does not free a place. So MailPush keeps a keyed one way hash of your Google account id. It cannot be turned back into your account, and it means that you do not use a second place if you come back.
- An audit record. It holds your Gmail address, the dates of your request, invitation, connection and deletion, who deleted the account (you or the operator) and the result of removing Google access. It stays until the operator removes it.
- The queued Google access. The encrypted copy of your Google access that waits to be revoked stays for at most 24 hours. A short record of that removal and of the clean up, with your address and the one way hash of your Google account id, stays for up to 90 days.
- Short working records. A record of a connection to Google that you started stays for 24 hours. The log of emails sent to you, which holds a one way hash of your address, the kind of email and the time, stays for 2 days.
- Copies outside the live data. These are the operator's backups of the server (a nightly encrypted copy of the whole database and your devices' sync state, kept on the server and, if the operator set it up, in storage away from it; the last 7 are kept, so a deleted account stays in them for about a week), the operator's notification emails, MailPush's own log lines with ids, addresses and times until they age out, which is 90 days by default, and the access log of the website in front of MailPush, which the operator controls (see What MailPush keeps).
- An unfinished send. If a message you sent was still unconfirmed when you deleted your account, a record of it stays until the operator resolves it. It holds one way hashes of the message identifiers and no content.
If you come back, you can ask for access again.
Your note and the emails MailPush sends
The note you can write when you ask for access is emailed to the person who runs MailPush, who reads it before deciding. MailPush deletes its own copy when you connect, the request is declined or it expires. A request you confirmed keeps it until the operator decides. The copy in the operator's mailbox stays there until the operator deletes it.
A message you send on the Contact us page is emailed to the person who runs MailPush, with your address as the reply address. MailPush does not store the message and does not write it to its logs. The copy in the operator's mailbox stays there until the operator deletes it.
MailPush sends its own emails to you (confirmation codes, invitations and sign in codes) through the operator's email provider.
How MailPush protects your data
- This site loads nothing from other websites. It has no trackers, no analytics, no ads, no outside fonts or scripts and no CAPTCHAs. Its cookies keep you signed in and protect its forms. A separate cookie remembers your Appearance choice (Auto, Light or Dark) for a year; it holds only that word and is not used for tracking.
- You sign in with a code or a link sent to your email. Each one works once and expires after 10 minutes (30 minutes to confirm a request), and five wrong entries end a code.
- Your Google access is encrypted, and your phone password, sessions, codes and links are stored as hashes, so a copy of the database alone cannot be used to sign in or to reach your Gmail.
- Wrong phone passwords are limited and blocked, and so are requests, sign in attempts and emails.
- Pages are served over HTTPS only, by the reverse proxy in front of MailPush.
Google API Services User Data Policy
MailPush's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In plain words, about the data MailPush gets from your Google account:
- MailPush uses it only to give you the features you see: your Gmail in Apple Mail, and your Google Calendar in the Calendar app if you turn Calendar on.
- MailPush does not transfer it to anyone else, except as needed to give you those features, to keep the service secure (which includes an encrypted nightly backup of its own data, copied to the operator's storage provider, which cannot read it) or to follow the law.
- MailPush does not use it for ads and does not sell it. It does not use it to train artificial intelligence or machine learning models.
- MailPush has no screen, log or tool that shows your email to anyone. It is not saved, and the admin page does not show it.
Contact
For a question about privacy or security, or to report a problem, use the Contact us page.