Privacy Policy
bytemail is a mail client for macOS. It runs on your Mac and talks directly to your mail provider. We — Sergey Karakhanyan, the developer and operator of bytemail and of this website ("bytemail", "we") — do not run servers that receive, store or process your mail. This policy explains exactly what the app and this website do with data.
The short version. Your mail, contacts, passwords and sign-in tokens stay on your Mac and with your mail provider. We never receive them, so we cannot read, sell, share or lose them. The app has no analytics and no advertising. This website sets no cookies and loads nothing from third parties.
1. Data the bytemail app handles
To work as a mail client, the app accesses the following on your behalf. All of it is processed and stored locally on your Mac:
- Mail content — messages, headers, attachments, folders, read/unread state and drafts from the accounts you add. A local cache is kept in an SQLite database in
~/Library/Application Support/ByteMailso mail can be read offline and searched on-device. - Account details — your email address, the display name your provider reports, server settings, and the label and colour you choose.
- Credentials — app passwords and OAuth refresh tokens are stored only in the macOS Keychain. bytemail never sees your Google or Microsoft password; sign-in happens in your browser on the provider's own page.
- Contact photos (optional) — if you allow access to Contacts, the app looks up a sender's photo on your Mac by email address. Nothing from your address book is transmitted anywhere.
None of this is sent to bytemail or to any third party. We have no ability to access it.
2. Network connections the app makes
- Your mail provider, over IMAP and SMTP with TLS, to read and send your mail.
- Google or Microsoft sign-in endpoints, only if you add an account with "Sign in with Google" or "Sign in with Microsoft", to obtain and refresh access tokens. No mail content is sent to these endpoints.
- A sender's own website, to fetch its public icon for the sender's avatar. The request carries no identifiers and nothing about you or the message. It is never made for mail in Spam.
- Image hosts referenced inside a message, only after you choose to load remote images for that message or turn on "Always load remote images". Loading remote images can tell the sender that you opened the message; that is why it is off by default.
- bytemailapp.com, to check whether a newer version of the app exists. The request contains the app version and macOS version and no identifier tied to you.
That is the complete list. The app contains no analytics, advertising or tracking SDKs and sends no crash reports automatically.
3. Google user data
If you connect a Google account, bytemail requests these scopes:
https://mail.google.com/— to read, organise, send and delete mail over IMAP and SMTP, which is the core function of a mail client;userinfo.emailanduserinfo.profile— to know which address signed in and to fill in your name as the sender name.
Google user data is used only to provide the mail features you see in the app, on your device. It is stored only on your Mac (mail cache) and in your macOS Keychain (tokens). It is not transferred to us or to anyone else, not used for advertising, not sold, not used to train AI or machine-learning models, and not read by any human other than you.
bytemail's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke bytemail's access at any time at myaccount.google.com/permissions.
4. Microsoft user data
If you connect an Outlook, Microsoft 365 or Exchange Online account, bytemail requests IMAP.AccessAsUser.All, SMTP.Send, offline_access and basic sign-in scopes (openid, email, profile). The same rules apply: the data is used only on your device to provide the mail client, stays on your Mac, and is never sent to us. You can revoke access at account.microsoft.com (personal accounts) or through your organisation's administrator.
5. Keeping and deleting data
- Removing an account in Settings deletes its local mail cache and its Keychain entry.
- Deleting the app's folder in
~/Library/Application Support/ByteMailremoves all cached mail and drafts. - Mail on your provider's servers is governed by your provider's own policy; bytemail only changes it when you ask it to (for example by deleting or moving a message).
- If you turn on "Send even when bytemail is closed", a small background item on your Mac delivers scheduled messages. It runs locally and can be turned off at any time in the app or in System Settings › Login Items.
6. This website
bytemailapp.com sets no cookies, uses no analytics and loads no third-party scripts, fonts or images. Like any web server, ours (a virtual server managed through Laravel Forge) processes your IP address, browser user-agent and the pages requested in order to deliver the site and protect it against abuse. These technical logs are kept for a short period — normally no longer than 30 days — and are not combined with anything else.
The waitlist. If you join the waitlist, we store the email address you enter, which form you used and when, on that same server. We use it for one thing: to tell you that bytemail is available to download. It is not shared, sold or used for any other mailing, and it is deleted once the waitlist has served its purpose or as soon as you ask — write to support@bytemailapp.com. The site's admin area, used only by us, sets a sign-in cookie for us; visitors never receive one.
7. When you contact us
If you email us for support, we receive your address and whatever you choose to write, and keep the conversation for as long as needed to help you and to keep a record of it. Please do not send passwords or the contents of private mail.
8. Your rights
Because we do not hold your mail or account data, there is normally nothing for us to export, correct or erase — you control it directly on your Mac. For data we do hold (your waitlist address, support correspondence, short-lived server logs) you may ask for access, correction, deletion or restriction, and you may object to processing, under the GDPR, UK GDPR, CCPA and similar laws. Write to support@bytemailapp.com. You also have the right to complain to your local data-protection authority.
9. Children
bytemail is not directed at children under 13 (or the minimum age in your country), and we do not knowingly collect their data.
10. Security
Connections to mail providers use TLS. Credentials are kept in the macOS Keychain. Message HTML is displayed with scripts disabled. The app is signed with an Apple Developer ID and notarised by Apple. No system is perfectly secure; keeping macOS up to date and using FileVault protects the local mail cache.
11. Changes
If this policy changes, the new version is published on this page with a new date. Material changes to how the app handles Google or Microsoft user data will also be shown in the app before they take effect.
12. Contact
Sergey Karakhanyan · support@bytemailapp.com