Trust
Updated October 9, 2026
In short: Mailroom keeps your mail on your Mac and talks straight to your mail
provider. There’s no Mailroom account and no Mailroom server, so nothing in your mail ever reaches
us. This page sums up how Mailroom protects it; the Privacy Policy has the
details.
Where your data goes
- Your mail, calendar and contacts go only between your Mac and your provider, over IMAP, SMTP, CalDAV and CardDAV, and Microsoft Graph for Outlook calendars. There’s no relay or sync service in between.
- Sign-ins happen on Google’s or Microsoft’s own page. Mailroom gets a sign-in token, never your password, and only ever sends that token to the provider’s own mail servers.
- AI, if you turn it on, goes to the service you set up: OpenRouter with your own key, which Mailroom asks to use only providers that don’t store or train on prompts, or a model running on your Mac. The Assistant changes nothing until you approve it.
- Chats are read on your Mac: iMessage from Messages’ own database, read-only, and other networks through Beeper Desktop on your Mac. Mailroom keeps no copy of them.
- This website serves downloads and update checks, and counts downloads. It sets no cookies and runs no tracking scripts.
How Mailroom protects it
- Encrypted on your Mac. Mailroom’s copy of your mail is an SQLCipher database encrypted with a random 256-bit key, and that key is itself encrypted with a key in your macOS Keychain. Passwords, sign-in tokens and API keys are encrypted the same way.
- Encrypted on the network. Mailroom connects with TLS 1.2 or newer and checks each server’s certificate. It connects without encryption only to software on your own Mac, such as Proton Mail Bridge.
- Email is treated as untrusted. Messages are cleaned with DOMPurify and shown in a sandboxed frame where scripts can’t run. Remote images wait until you allow them, tracking pixels never load, and Mailroom warns before opening a link that hides where it goes.
- A hardened app. Mailroom’s windows run in Chromium’s sandbox with no access to your system, under a strict content security policy, and the main process checks every request they make. Only a separate sync process talks to your mail servers and opens the database. The installed app refuses to start with the debugging switches another program could use to control it.
- Signed and notarized. Every release is signed with a Developer ID (Anton Savytski, AZ9XRC6929) and notarized by Apple, and Mailroom installs an update only if it’s signed by the same developer.
- No tracking. The app has no analytics, telemetry or crash reporting.
Sign in with Google and Microsoft
- Google. Mailroom’s Sign in with Google is in Google’s verification review. Until it’s finished, Google’s page first warns that the app isn’t verified: click Advanced, then Go to Mailroom. Mailroom asks for your Gmail and, if you leave it ticked, your Google Calendar. How it uses what it gets from Google is in the Privacy Policy.
-
Microsoft. Mailroom’s own Microsoft app asks to read and send your mail over IMAP and
SMTP and, for Outlook Calendar, to use your calendars. Its publisher domain, getmailroom.dev, is
verified with Microsoft. Microsoft 365 administrators can find it by its
Application (client) ID,
43ec613f-4d72-44c8-bc6e-3e417dfb04fa, and approve it for their organization. - An app of your own instead. If your organization prefers, Mailroom can sign in through an app you register yourself: Settings › Accounts › Use Your Own….
Services behind Mailroom
None of these receive your mail.
- Cloudflare hosts this website, the downloads and the update checks.
- GitHub builds and signs each release, and Apple notarizes it.
- Purelymail receives what you send to support@getmailroom.dev.
The services you connect yourself, such as your mail provider, Beeper or an AI service, work under their own terms.
Reporting a security issue
Email support@getmailroom.dev with “Security” in the subject. A person reads every message. Please give us a chance to fix a problem before you publish it. The same contact is in this site’s security.txt.
Questions
Write to support@getmailroom.dev. See also the Privacy Policy, the Terms of Use and Help › Privacy.