1. Application
This Privacy Policy applies to MailPivot ARM64, a native ARM64 desktop email client for Windows 11 on Arm.
2. Google OAuth 2.0 and Gmail API
MailPivot ARM64 uses Google OAuth 2.0 to let a user authorize access to the user's own Gmail account. MailPivot ARM64 uses the Gmail API and requests the gmail.modify scope to provide Gmail mail-client functions.
Google user data that MailPivot ARM64 may access as needed for those functions includes:
- message bodies in plain text or HTML;
- message headers;
- sender and recipient information;
- message dates;
- labels/folders and read/unread state;
- attachments and attachment metadata;
- the signed-in account email address.
3. Purpose and use of Google user data
Google user data is used only to provide user-facing email functionality in MailPivot ARM64, including displaying messages, organizing mail, changing read/unread state and labels when requested by the user, composing replies and forwards, handling attachments, and sending messages through explicit user actions.
MailPivot ARM64 does not use Google user data for advertising and does not sell Google user data.
4. Storage, processing, and data protection
MailPivot ARM64 is a native desktop application. Gmail data is processed locally on the user's Windows device as needed to provide the mail-client functions selected by the user. MailPivot ARM64 does not route Gmail message content through a developer-operated MailPivot email relay server.
Google OAuth authorization tokens and other authentication-related information are stored locally on the user's Windows device and are encrypted at rest using the Windows Data Protection API (DPAPI) with CurrentUser scope. This protection is designed so that the encrypted authorization data can be decrypted only within the same Windows user context.
MailPivot ARM64 does not store Google OAuth access tokens or refresh tokens as unprotected plain-text JSON during normal operation.
Communications between MailPivot ARM64 and Google services use Google's HTTPS/TLS-protected API endpoints.
MailPivot ARM64 accesses and processes Google user data only as necessary to provide the user-facing email functions selected or requested by the user.
When the user creates a MailPivot complete backup, sensitive backup content, including authentication-related secret data, is protected separately using AES-256-GCM encryption. The backup encryption key is derived from the user's backup passphrase using PBKDF2-SHA256. DPAPI-protected authorization data is not simply copied as a device-bound encrypted blob into the portable backup; sensitive data is re-protected for backup using the backup encryption mechanism.
Users are responsible for maintaining the security of their Windows account, device, and backup passphrase.
OAuth authorization information may be retained so the user can remain signed in and continue using the connected Gmail account until the user signs out, removes the account, revokes access, or the authorization otherwise expires.
5. No transfer of Google user data to AI services
MailPivot ARM64 does not transmit Google user data obtained through Google OAuth 2.0 or the Gmail API to OpenAI or other third-party AI services.
6. Sharing and disclosure
MailPivot ARM64 uses Google user data only as needed to provide the user-facing mail-client functions requested by the user, including transmitting a user-composed message to its intended recipients through Gmail.
MailPivot ARM64 does not transmit Google user data obtained through the Gmail API to OpenAI or other third-party AI services. MailPivot ARM64 does not sell Google user data or disclose it to third parties for targeted advertising.
7. Google API Services User Data Policy
MailPivot ARM64's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. User control and deletion
Users can stop MailPivot ARM64 from accessing a Gmail account at any time by removing the account from MailPivot ARM64 and/or revoking the application's access through Google Account security settings.
When a Gmail account is removed from MailPivot ARM64, the locally stored OAuth authorization data associated with that account, including DPAPI-protected authentication tokens and related authentication cache data, is removed from the application's local storage.
Users may also delete MailPivot ARM64's local application data from their Windows device.
Revoking MailPivot ARM64's access from the user's Google Account prevents the application from obtaining further access to that Gmail account using the revoked authorization.
Portable MailPivot backup files, if created by the user, are separate from the application's normal local storage. Backup files containing sensitive authentication-related data are protected using the backup encryption mechanism described in Section 4. Users are responsible for deleting backup files they no longer wish to retain.
9. Changes
This policy may be updated when MailPivot ARM64's features, data practices, or legal requirements change. The current version is always published at this URL.