Privacy Policy
Last updated: September 2026
Your Data Stays on Your Device
SagaMail is a native macOS application. Your emails, contacts, account credentials, and preferences are stored locally on your Mac in an SQLCipher-encrypted database. We do not operate cloud servers that relay, store, or process your email content. Your emails never leave your Mac, except when sent or received through your own email provider.
What We Collect
When you purchase a license or create an account on app.sagamail.app, we collect:
- Email address (for license delivery and account management)
- Name (optional, for personalization)
- License key and activation status
- Payment information (processed by Stripe — we never see your full card number)
What the SagaMail App Doesn't Collect
The SagaMail desktop app does not collect:
- Email content, attachments, or metadata
- Contact lists or address books
- Email account passwords or OAuth tokens
- Usage analytics or telemetry from the desktop app
- Browsing history or IP-based tracking from within the app
This section is about the SagaMail app. This website (sagamail.app) is a separate surface with its own, much narrower data practices — see "How This Website Measures Visits" below.
OAuth Authentication (Google & Microsoft)
When you sign in to a Gmail or Microsoft 365 account, OAuth 2.0 happens directly between your Mac and the provider. SagaMail receives the access token and refresh token from Google or Microsoft and stores them exclusively in the macOS Keychain on your device. These tokens are never transmitted to or stored on SagaMail servers.
During OAuth, the provider returns:
- An access token (short-lived) used to call the provider's API
- A refresh token (long-lived) used to renew the access token
- The authenticated account's email address
We store only those three values, locally, in the Keychain. You can revoke SagaMail's access at any time through your Google Account or Microsoft Account security settings, which immediately invalidates the tokens. Removing a Gmail account from SagaMail revokes SagaMail's access with Google as well as deleting the tokens from the Keychain.
Gmail access. When you connect a Gmail account, SagaMail connects from your Mac directly to Gmail's IMAP and SMTP servers (imap.gmail.com,smtp.gmail.com) using OAuth 2.0, to: read and display your messages and threads; read and manage folders and labels; send email on your behalf; and update message state (read/unread, starred, archived, trash).SagaMail's use of Gmail data is limited solely to providing the in-app email client experience. Gmail data is never used for advertising, profiling, training AI models on our behalf, or any purpose unrelated to delivering email management features directly to you. No Gmail content is transmitted to or processed on SagaMail servers at any time.
Google API Services User Data Policy
SagaMail's use and transfer of information received from Google APIs to any other app will adhere to theGoogle API Services User Data Policy, including the Limited Use requirements.
SagaMail requests one Google OAuth scope:
https://mail.google.com/— the scope Google requires for IMAP and SMTP access. SagaMail is a complete mail client: it synchronises folders, moves and copies messages between labels, sends mail, and keeps an encrypted offline copy of your mailbox on your Mac.
Under the Limited Use requirements, we affirm that:
- Google user data is used only to provide and improve the email features you see in the app.
- We do not transfer Google user data to anyone, except as needed to provide a feature you asked for, for security purposes, or to comply with applicable law. SagaMail stores mail on your Mac, so in normal operation no transfer occurs at all.
- We do not sell Google user data, and we do not use it for advertising, credit assessment, or lending.
- No human at Vohux reads your Google user data. We cannot — message content never leaves your device and we operate no server that receives it.
- Google user data is never used to train AI models, ours or anyone else's. The optional AI features run against an API key you supply, on text you explicitly select.
AI Features (Bring Your Own Key)
All AI features in SagaMail are BYOK (Bring Your Own Key). You supply your own API key from Anthropic, OpenAI, or Google. When you use an AI feature (summarization, AI Chat, Smart Compose, writing assistant, calendar extraction, PHIPA scanning), the relevant email content is sent directly from your Mac to your chosen AI provider using your own API key.
SagaMail does not intermediate, proxy, log, or store this data. The conversation is governed entirely by the privacy and retention policies of the AI provider you have chosen, under the account you control.
Email Open Tracking
Email open tracking (read receipts via tracking pixel) is opt-in only and disabled by default. When you explicitly enable it for a specific outgoing email, SagaMail embeds a 1×1 transparent image referencing a per-email URL.
When a recipient's mail program loads that image, our relay at sagamail.app records only the per-email identifier and the time of the open, so that your Mac can collect it. We do not record the recipient's IP address or browser details. The result is visible only to you, in SagaMail on your Mac. You can disable tracking globally at any time from Settings.
Third-Party Services
Sender logos and avatars. Sender logos are on by default. SagaMail asks Clearbit, Google's favicon service, or DuckDuckGo's icon API for the logo of a sender's domain (for example example.com); the request carries the domain only, never an email address or any message content, and is made directly from your Mac. Turn it off under Settings → Privacy → Show Sender Logos, and no logo requests are made. Gravatar avatars are a separate setting, off by default: when you turn on Allow Gravatar Avatars, SagaMail sends Gravatar an MD5 hash of the sender's email address.
Breach monitoring. Optional breach checks use theHave I Been Pwned (HIBP)API. It runs only if you enter your own HIBP API key. SagaMail then sends each of your own account email addresses to HIBP to look up known breaches. No message content is sent.
Hosting and payments. Cloudflare provides hosting and DDoS protection for our marketing site and license server. Payment processing is handled by Stripe. Neither service has access to your email content.
PHIPA & Healthcare Accounts
For users in regulated healthcare environments, SagaMail includes an outgoing email scanner that flags potential Personal Health Information (PHI) before sending. The scanner is on by default and runs on your Mac; turn it off under Settings → Privacy → PHIPA Scan on Outgoing Mail.
No PHI is transmitted to SagaMail servers. When using a local-only scanning model, content stays on your Mac. When configured to use a cloud AI provider for scanning, content is sent to that provider under your own API key (see the AI Features section above) — SagaMail still does not see, store, or log the content.
Web App (app.sagamail.app)
The web app portal is used for license management and account settings. Authentication uses secure, HTTP-only cookies. Session data is encrypted at rest. The web portal does not have access to your local email database.
Data Deletion & Uninstalling
Uninstalling SagaMail by dragging the app to the Trash removes the application but leaves your local data behind. To fully remove all SagaMail data from your Mac:
- Quit SagaMail.
- Move
/Applications/SagaMail.appto the Trash. - Delete the data folder:
~/Library/Application Support/SagaMail/ - Open Keychain Access, search for "SagaMail" or your account email, and delete any matching entries (these are your OAuth tokens and IMAP/SMTP passwords).
- Optionally, remove preferences:
~/Library/Preferences/com.sagamail.app.plist
To delete your license account on app.sagamail.app, contact us and we will permanently erase your account record within 30 days.
How This Website Measures Visits
Nothing loads until you accept. On your first visit you are asked whether we may use these tools. If you decline, or simply ignore the banner, not one of them is requested: no script is fetched, no cookie is set, and no data leaves your browser — declining is the absence of the request, not a request carrying a flag. Your choice is stored on your own device, and you canchange it at any time. The three tools are Google Analytics and Growify, which show which pages and which links bring people here, and TruConversion, which shows how pages are used.
This website, which is separate from the SagaMail app, uses third-party tools to understand how visitors use our pages and which links or advertisements bring them here. These tools may see: the pages you view, how long you stay, and the website, link or advertisement that brought you here (including campaign identifiers in the link); how you interact with a page (clicks, taps, scrolling and mouse movement), which may be kept as a replay of your visit with anything you type hidden; and your browser type, device type, screen size, language, time zone and country (not your city — our page-analytics tool is set not to store your IP address). Our advertising-measurement tool sets a cookie that recognises your browser on later visits for up to one year and may store its data on servers in the United States. None of these tools receive what you type into forms, your email address, or anything from inside the SagaMail app. Tools we use to improve how our pages appear in search engines and AI assistants work only with our public page content and receive no information about you. You can block or delete cookies in your browser settings at any time.
Contact
Questions about privacy? Emailinfo@vohux.com.