Privacy policy
PKOM Mail Control is a private, local application used to manage Google accounts that its operator owns or is authorized to access. This policy explains how the app handles Google user data.
Google user data the app accesses
After an account owner grants OAuth permission, the app may access:
- The connected Gmail address and account history identifier.
- Gmail message and thread identifiers.
- Gmail labels and message metadata needed to find a message and determine whether it is in Inbox or Spam.
- User-provided recipients and message content when the operator explicitly sends an email.
The app requests the gmail.modify OAuth scope so it can read mailbox state, add or remove labels, mark messages read, and send mail when directed by the authorized operator.
How the data is used
- Show mailbox counts and connection status.
- Find and classify messages requested by the operator.
- Carry out a reviewed mailbox action, such as moving selected Spam to Inbox or marking selected mail read.
- Send a message that the operator has specifically requested.
Google user data is not used for advertising, profiling, credit decisions, or training general-purpose machine-learning models.
Storage and retention
OAuth client information and per-account refresh tokens are stored in the operator's macOS Keychain. Short-lived access tokens are held only in process memory.
The local state file stores account addresses, Gmail message IDs, operation plans, and operation results. It does not store Google passwords, OAuth tokens, client secrets, downloaded Gmail message bodies, or email subjects. The state file is restricted to the local macOS user.
Credentials remain until the account is disconnected, access is revoked through Google, or the operator removes the corresponding Keychain entry. Local metadata remains until the operator removes the state file or requests its deletion.
Sharing and disclosure
PKOM Mail Control does not sell, rent, or share Google user data with advertisers, data brokers, or unrelated third parties. Data is sent to Google APIs only as needed to perform the operator's requested action.
Security
The app uses Google's OAuth desktop flow with PKCE. It stores reusable credentials in the macOS Keychain, binds the OAuth callback to the local computer, and keeps its metadata state file readable only by the local macOS user.
Google API Services User Data Policy
PKOM Mail Control's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Your choices
An account owner can revoke PKOM Mail Control at any time from the Google Account third-party connections page. To request removal of locally stored credentials or metadata, email pk@pkom.me.
Changes to this policy
This policy will be updated if the app's data access or handling changes. The effective date above will be revised when an update is published.
Contact
Questions about this policy can be sent to pk@pkom.me.