Privacy Policy
Effective October 5, 2026
Who we are
Mailroom is made by Anton Savytski, a sole proprietor carrying on business as Anatoli Labs in Toronto, Ontario, Canada (“Anatoli Labs”, “we”, “us”). This policy covers the Mailroom app for macOS (“Mailroom”) and this website. Questions go to hello@anatolilabs.com.
What we collect
Through Mailroom, nothing. Mailroom has no analytics, telemetry, crash reporting, usage statistics or advertising identifiers, and it never sends your mail, contacts, calendar, passwords or settings to us. We can’t see what you do in Mailroom, and we couldn’t share or sell your information because we don’t have it.
If you email us, we receive your email address and what you write, and use them only to reply. We keep that correspondence only as long as we need it to help you.
What Mailroom keeps on your Mac
To work, Mailroom stores the following on your Mac, in your user account’s Library:
- A copy of your mail, folders, tags, calendars and contacts, so they open quickly and can be read offline.
- Your account settings, and your passwords, sign-in tokens and API keys.
- Your preferences, such as theme, signatures and AI instructions.
The copy of your mail is kept in an encrypted database. Passwords, sign-in tokens and keys are encrypted too. The keys for all of it are kept in your macOS Keychain. None of this data leaves your Mac except as described below.
Connections Mailroom makes for you
Mailroom connects to other services only to do what you ask. Each of these services is run by someone else, under its own terms and privacy policy, which we don’t control.
- Your mail, calendar and contacts servers (for example Gmail, iCloud, Fastmail or Purelymail), over IMAP, SMTP, CalDAV and CardDAV, and Microsoft Graph for Outlook calendars, to sync your data and send your messages.
- Google, Microsoft or Yahoo, if you choose to sign in with them instead of a password, for mail or to connect Google Calendar or Outlook. Mailroom signs in through an app registered with them, Mailroom’s own or one you register yourself, and receives a sign-in token, never your password.
-
Account setup lookups. When you type an address at a domain Mailroom
doesn’t know, it looks up where that domain’s mail is handled (its DNS records), and
asks for the domain’s published mail settings: from the domain itself
(
autoconfig.and/.well-known/addresses) and from Mozilla’s Thunderbird provider database. Only the domain is sent, never your address. - AI services, only when you ask. When you click Reply with AI, Translate, Summarize or Proofread, the text of that message, conversation or draft (no attachments or images) goes to the AI service you set up: OpenRouter, which Mailroom asks to use only providers that don’t store or train on prompts, or a model server you run yourself, such as Ollama. Nothing is sent to an AI service unless you click.
- Remote images, only when you allow them. Mailroom blocks images stored on other servers until you choose to load them. When you do, those servers can see your IP address and that the message was opened.
- Links and unsubscribing. Web links you open go to your web browser, and email links open a new message in Mailroom. When you confirm Unsubscribe, Mailroom sends the mailing list’s own unsubscribe request.
Some things that may look like they need a server happen on your Mac: search, the guess that a message is in another language, and the warnings about misleading links and unconfirmed senders.
Google user data
If you sign in with Google, Mailroom asks Google for:
-
Gmail (
https://mail.google.com/), to download your mail to your Mac over IMAP; to keep what you read, star, move and delete in step with Gmail; to save your drafts there; and to send the mail you write, over SMTP. -
Google Calendar (
https://www.googleapis.com/auth/calendar), only if you connect it, to show your calendars and events, and to save the events you make, change, delete or answer. -
Your name and email address (
openid,email,profile), to tell which Google account you signed in to.
This data goes only between your Mac and Google. Mailroom has no server that receives it, and Anatoli Labs never sees it. Mailroom keeps a copy on your Mac, encrypted with a key in your Keychain, so your mail and calendar open quickly and work offline. Mailroom doesn’t use Google user data for advertising, doesn’t sell it, doesn’t let anyone read it, and doesn’t use it to train AI models. It only leaves your Mac for somewhere other than Google when you click an AI feature: then the text of that message, conversation or draft goes to the AI service you set up, as described above.
Mailroom’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
To delete it, remove the account in Mailroom’s Settings, which deletes its mail and calendar from your Mac, and remove Mailroom’s access in your Google account at myaccount.google.com/permissions.
This website
This website doesn’t use cookies or advertising, has no analytics or tracking scripts, and doesn’t load fonts or other resources from third parties. The help center’s search and help bot work in your browser: what you type there isn’t sent anywhere or kept. It counts how many times each version of Mailroom is downloaded each day, and keeps only those totals, nothing about who downloaded it. It’s hosted by Cloudflare, which processes technical information such as IP addresses to deliver and protect the site, under Cloudflare’s privacy policy. If you download Mailroom from a third-party service such as GitHub, that service’s privacy policy applies to the download.
Shortly after Mailroom opens, and every four hours while it’s open, it asks this website whether there’s a new version, and downloads it from here if there is. The request includes the version you have. We don’t count or keep these checks or the update downloads.
Children
Mailroom isn’t directed at children under 13. It doesn’t collect information from anyone, including children.
Your choices
- Remove an account in Mailroom’s Settings to delete its mail and settings from your Mac. Your mail on the server isn’t affected.
- To remove everything, quit Mailroom, delete it from Applications, and delete the folder
~/Library/Application Support/Mailroom. The “Mailroom Safe Storage” item can be removed in Keychain Access. - To stop AI requests, don’t use the AI features, or remove your API key in Settings › AI.
Security
Mailroom connects over encrypted connections and checks servers’ certificates. Each message is shown in an isolated view with no scripts. Your data on your Mac is encrypted, with keys held by your Keychain. No method of storing or sending information is completely secure, and keeping your Mac, its password and its updates secure is up to you.
Where information goes
We don’t transfer your information anywhere, because we don’t receive it. The services you connect Mailroom to may store and process your information in other countries, under their own policies.
Changes to this policy
If we change this policy, we’ll update it here and change the date at the top. If a change affects what Mailroom does with your information, we’ll say so in the release notes of the version that makes the change.
Contact
Questions or concerns: hello@anatolilabs.com, Anatoli Labs, Toronto, Ontario, Canada. You can also contact the Office of the Privacy Commissioner of Canada about how a business handles personal information.