Privacy policy

Effective August 26, 2026

PKOM Mail Control is a private, local application used to manage Google accounts that its operator owns or is authorized to access. This policy explains how the app handles Google user data.

Google user data the app accesses

After an account owner grants OAuth permission, the app may access:

The app requests the gmail.modify OAuth scope so it can read mailbox state, add or remove labels, mark messages read, and send mail when directed by the authorized operator.

How the data is used

Google user data is not used for advertising, profiling, credit decisions, or training general-purpose machine-learning models.

Storage and retention

OAuth client information and per-account refresh tokens are stored in the operator's macOS Keychain. Short-lived access tokens are held only in process memory.

The local state file stores account addresses, Gmail message IDs, operation plans, and operation results. It does not store Google passwords, OAuth tokens, client secrets, downloaded Gmail message bodies, or email subjects. The state file is restricted to the local macOS user.

Credentials remain until the account is disconnected, access is revoked through Google, or the operator removes the corresponding Keychain entry. Local metadata remains until the operator removes the state file or requests its deletion.

Sharing and disclosure

PKOM Mail Control does not sell, rent, or share Google user data with advertisers, data brokers, or unrelated third parties. Data is sent to Google APIs only as needed to perform the operator's requested action.

Security

The app uses Google's OAuth desktop flow with PKCE. It stores reusable credentials in the macOS Keychain, binds the OAuth callback to the local computer, and keeps its metadata state file readable only by the local macOS user.

Google API Services User Data Policy

PKOM Mail Control's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Your choices

An account owner can revoke PKOM Mail Control at any time from the Google Account third-party connections page. To request removal of locally stored credentials or metadata, email pk@pkom.me.

Changes to this policy

This policy will be updated if the app's data access or handling changes. The effective date above will be revised when an update is published.

Contact

Questions about this policy can be sent to pk@pkom.me.