1. Scope
This Privacy Policy describes how the MailPivot ARM64 Windows desktop application accesses, uses, stores and shares information. MailPivot ARM64 is independent software. The developer does not operate a mail relay server for the application.
2. Mail service connections
MailPivot connects from the user's Windows PC directly to services selected by the user, including Google Gmail, Microsoft mail services, Yahoo, iCloud, and standards-based IMAP/SMTP servers. Mail message bodies, attachments, OAuth tokens and mail passwords are not routed through a MailPivot developer-operated relay server.
3. Google user data
For Gmail, MailPivot uses Google OAuth 2.0 and the Gmail API. The requested scope is https://www.googleapis.com/auth/gmail.modify. MailPivot uses Gmail data only to provide or improve visible email-client features requested by the user, including reading and displaying mail, composing and sending mail, search, message state, labels, archiving, trash/restore operations, attachments, reply and forward workflows.
Depending on the requested function, MailPivot may access message bodies (plain text and HTML), headers, sender and recipient fields, dates, labels/folders, read state, attachment metadata and downloaded attachment content, and the connected account email address.
MailPivot's use of information received from Google APIs is intended to comply with the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising, creditworthiness, surveillance, or unrelated model training.
4. Local storage on the user's PC
Application data is stored under the user's Windows profile, primarily in %LOCALAPPDATA%\MailPivot_ARM64. This may include:
- Google OAuth tokens for connected Gmail accounts.
- Microsoft OAuth/MSAL token cache data.
- Mail account settings and account identifiers.
- IMAP/SMTP passwords encrypted with Windows DPAPI for the current Windows user.
- The optional user-supplied OpenAI API key, encrypted with Windows DPAPI for the current Windows user.
- Display/cache data for messages, downloaded attachments, thumbnails, settings backups and local diagnostic logs.
Google OAuth client registration information required by the installed desktop application is embedded in the application build; users do not need to supply a Google client-secret JSON file.
5. Optional OpenAI API features
MailPivot's AI features are optional and use an OpenAI API key supplied by the user. These features can include summary, translation, grammar assistance, drafting and related user-facing functions.
Gmail-specific behavior: MailPivot does not automatically send Gmail API-derived message content to OpenAI. Received Gmail views do not automatically run cloud AI, and batch automation does not automatically transmit Gmail API-derived content to cloud AI. However, if the user copies, pastes or otherwise places Gmail-derived content into a compose, reply or forward editor and then explicitly invokes an AI feature from the user interface, the text in that editor—including Gmail-derived text when present—is transmitted directly from MailPivot to the OpenAI API to perform the requested feature.
The MailPivot developer does not operate an intermediate AI relay server. OpenAI processes API requests under OpenAI's own terms and data policies. According to OpenAI's current API/business data documentation, API inputs and outputs are not used to train OpenAI models by default unless the API customer explicitly opts in. Users should review OpenAI's current policies because third-party practices may change.
Clipboard copy/paste actions themselves are local Windows operations and do not invoke AI or transmit data to OpenAI. AI transmission occurs only when the user explicitly invokes an AI feature that uses the editor content.
6. Sharing and transfers
MailPivot does not sell mail data or personal data. Data is shared with a third party only when necessary for a user-requested visible feature—for example, the selected mail provider to read/send mail, or OpenAI when the user explicitly invokes an optional AI operation as described above—or when required by law.
7. Retention and deletion
MailPivot does not maintain a developer-operated server-side copy of users' mail. Local caches and credentials remain on the user's PC until removed by the user or by account-removal/uninstall cleanup actions. Removing an account from MailPivot removes that account's local credentials and cache where implemented; it does not delete mail stored on the mail provider's server.
To remove all MailPivot local data, close the application and delete %LOCALAPPDATA%\MailPivot_ARM64. Google authorization can also be revoked from the user's Google Account connected-app settings. Microsoft and other provider authorization can be revoked using the respective provider's account/security controls.
8. Mailbox actions
Actions such as send, mark read/unread, archive, move to trash and restore are performed only as part of user-facing mail functions. MailPivot does not provide a permanent-delete command for mail. Batch workflows do not provide automatic sending; sending requires the user to use the normal Send control.
9. Security
MailPivot stores data inside the user's Windows profile and uses Windows DPAPI for supported secrets such as IMAP/SMTP passwords and the OpenAI API key. Other local caches and Google token-store files rely on the security of the user's Windows account, filesystem and device. Users should protect their Windows account and device, use disk encryption where appropriate, and avoid sharing a Windows profile with untrusted users.
10. Website
This official static website does not intentionally include advertising or third-party analytics scripts. Hosting and network providers may process ordinary connection metadata according to their own policies.
11. Changes
This policy may be updated when MailPivot's functionality or data practices change. The current version will be published at this same URL.
12. Contact
Privacy and support contact information will be provided through the official Apps ARM64 / MailPivot distribution and support channels. The developer does not ask users to send passwords, OAuth tokens, or API keys for support.
References: Google Workspace API User Data and Developer Policy · OpenAI business data privacy