隐私与 Google 用户数据Privacy & Google user data

隐私政策Privacy Policy

本政策说明 Mine Mail 如何在桌面设备上访问、使用、存储和删除邮箱数据,也说明 Google 用户数据不会流向哪里。 This policy explains how Mine Mail accesses, uses, stores, and deletes mailbox data on your desktop—and where Google user data does not go.

生效日期:2026 年 7 月 25 日Effective: July 25, 2026 运营者:Tantless(个人开发者)Operator: Tantless (independent developer)

1. 概览

Mine Mail 是一款本地优先的桌面邮件客户端,由个人开发者 Tantless 运营。它没有开发者运营的邮件中转、同步或分析服务器。应用从你的设备直接连接 Google Gmail、163 邮箱或你配置的标准 IMAP/SMTP 服务。

除非你主动向支持邮箱发送资料,开发者不会接收你的邮箱 token、邮件、附件、联系人、草稿或本地数据库。Mine Mail 不出售个人信息,不投放广告,也不上传产品使用遥测。

2. Mine Mail 处理的数据

类别用途保存位置
账户身份邮箱地址、显示名称、服务商类型和账户配置,用于显示账户并连接正确的邮箱服务。设备本地应用数据目录。
授权资料Gmail OAuth token 或其他邮箱的授权密码,用于 IMAP/SMTP 登录。操作系统凭据存储;不会保存到网页或 Mine Mail 服务器。
邮箱内容邮件头、正文、附件信息、文件夹、草稿、发件箱项目、已读/星标等状态,用于完整邮件客户端功能和离线访问。邮箱服务商与设备本地 SQLite 缓存;凭据除外。
本地联系人从缓存邮件头派生的通信人、收藏、备注与用户选择的头像,用于通讯录和名称显示。设备本地 SQLite 数据库。
偏好设置主题、同步间隔、通知、远程图片和开机启动等设置,用于按你的选择运行应用。设备本地 SQLite 数据库。
本地诊断日志启动、同步模式和错误类别等事件,用于本机排查;不记录邮箱地址、主题、收发件人、正文、token 或完整路径。设备本地日志目录。

3. Google 用户数据

请求的权限

  • openid 和 email:确认你授权的 Google 账户与邮箱地址。
  • https://mail.google.com/:通过 Gmail IMAP 与 SMTP 使用 XOAUTH2 读取、同步、整理和发送邮件。

为什么不能使用更窄的权限

Mine Mail 的核心架构使用标准 IMAP/SMTP,而不是 Gmail REST API。Google 对 Gmail 的 IMAP、POP 和 SMTP OAuth 访问要求使用 https://mail.google.com/。只读或单项 Gmail API scope 无法用于 IMAP/SMTP 身份验证,也不能维持草稿、文件夹状态、星标和发信等完整客户端能力。

用途限制

Google 用户数据只用于提供你明确请求的邮件客户端功能,包括显示和搜索本地同步的邮件、同步邮件状态和草稿、发送邮件,以及在你的设备上生成邮件通知。不会用于广告、用户画像、信用或贷款、监控、向人类审阅者开放,或训练通用 AI/机器学习模型。

Google API Limited Use:Mine Mail 对从 Google API 接收的信息的使用以及向任何其他应用的传输,将遵守 Google API Services User Data Policy,包括 Limited Use 要求。

4. 本地存储与安全

  • OAuth token 与邮箱授权密码保存在操作系统凭据存储中,而不是 React 界面、网站或 SQLite 邮件缓存中。
  • 账户元数据、邮件缓存、正文、草稿、发件箱、联系人和设置保存在应用数据目录的 SQLite 数据库中。
  • 当前 SQLite 数据库没有整库加密。能够读取你操作系统用户文件的攻击者可能读取缓存邮件。请使用设备登录密码、磁盘加密和受信任的本机账户。
  • HTML 邮件作为不可信内容处理:危险内容会被清理、脚本被禁用,复杂内容在无脚本隔离区域中显示。
  • 本地诊断日志按大小轮转,启动时清理七天前的历史文件,并限制总占用;日志设计上不包含邮件内容或身份信息。

远程图片

远程图片默认自动加载,也可在设置中改为“询问”或“阻止”。加载远程图片会让图片服务器看到你的 IP 地址、客户端网络信息和大致打开时间。这些请求由你的设备直接发往发件人指定的第三方服务器,不经过 Mine Mail 开发者。

没有任何软件能保证绝对安全。如果发现可能影响 Mine Mail 用户数据的安全问题,请通过本政策末尾的邮箱联系。

5. 共享与传输

Mine Mail 不向开发者服务器传输邮箱数据,也不出售、出租或将其用于广告。为完成你请求的功能,数据可能在以下有限情形中由你的设备直接处理或发送:

  • 邮箱服务商:连接、同步和发送所必需,例如 Google Gmail 或你配置的 IMAP/SMTP 服务器。
  • 操作系统:保存授权凭据、显示通知以及运行桌面应用所必需。
  • 远程内容服务商:仅当邮件中的远程图片被允许加载时,图片 URL 会由设备直接请求。
  • 你选择的收件人:当你点击发送时,邮件内容和附件按你的指示交给邮箱服务商投递。
  • 法律要求:开发者仅能披露实际持有的信息;由于邮箱数据不在 Mine Mail 服务器上,通常不存在可供披露的服务器端邮箱副本。

6. 数据保留与删除

邮箱服务商上的原始数据按该服务商的政策保留。设备上的 Mine Mail 缓存会一直保留,直到你在移除账户时选择删除本地邮件缓存,或执行完整本地数据删除。

应用会明确区分删除范围:“仅断开”会删除 Mine Mail 账户记录和操作系统凭据,但保留 Google 授权与本地邮件缓存;“撤销授权并移除”会先请求 Google 撤销 Mine Mail 的 OAuth 授权,再删除本机凭据。你还可以勾选“同时删除本地邮件缓存”,删除该账户的 SQLite 邮件、草稿与发件队列缓存。

只有在 Google 确认撤销后,应用才会报告授权已撤销;本地缓存清理未完成时会显示明确警告。若应用无法启动,或你还要删除设置、联系人、头像与日志,请按数据删除指南完成手动步骤。

Windows 本地数据位于 %LOCALAPPDATA%\com.minemail.desktop。卸载程序可能因版本或系统安装行为而保留应用数据;若要确保删除,请在退出 Mine Mail 后手动删除该目录。

7. 网站与支持通信

本网站不设置广告或分析 cookie,也不使用第三方行为分析脚本。网站服务器和网络服务商可能为建立 HTTPS 连接、交付页面及保障安全而处理 IP 地址、请求时间、浏览器信息和请求路径等标准网络数据。

如果你主动向 tantless8@gmail.com 发送支持邮件,开发者会收到你提供的邮箱地址和内容,并仅用于回应请求、诊断问题或履行删除请求。请勿发送密码、OAuth token 或完整私人邮件。你可以要求删除支持通信中由开发者持有的资料。

8. 你的选择与权利

  • 随时停止同步或从 Mine Mail 移除账户。
  • 随时通过 Mine Mail 的“撤销授权并移除”,或 Google 账户连接页面撤销 Mine Mail 授权。
  • 删除本地应用数据目录,以清除 Mine Mail 在设备上的缓存、设置、联系人和日志。
  • 将远程图片设置为自动、询问或阻止。
  • 就支持通信中由开发者持有的数据提出访问、更正或删除请求。

Mine Mail 不面向所在地区法定数字同意年龄以下的儿童,开发者也不会有意收集其个人信息。

本政策可能随功能、法律要求或发布状态更新。重大变化将在本页以新的生效日期说明。

9. 联系方式

数据控制者与应用运营者:Tantless(个人开发者)

隐私与支持邮箱:tantless8@gmail.com

网站:https://minemail.tantless.online/

1. Overview

Mine Mail is a local-first desktop email client operated by Tantless, an independent developer. It has no developer-operated mail relay, synchronization, or analytics server. The app connects directly from your device to Google Gmail, 163 Mail, or a standard IMAP/SMTP service you configure.

Unless you voluntarily send material to the support address, the developer does not receive your mailbox tokens, messages, attachments, contacts, drafts, or local database. Mine Mail does not sell personal information, display advertising, or upload product-usage telemetry.

2. Data Mine Mail handles

CategoryPurposeStored where
Account identityEmail address, display name, provider type, and account configuration identify the account and connect to the correct service.Your device’s local app-data directory.
Authorization materialGmail OAuth tokens or authorization secrets for other providers authenticate IMAP/SMTP sessions.The operating-system credential store; never the website or a Mine Mail server.
Mailbox contentHeaders, bodies, attachment metadata, folders, drafts, outbox items, and read/starred state provide full-client and offline functionality.Your mail provider and the device-local SQLite cache, except credentials.
Local contactsCorrespondents derived from cached headers, favorites, remarks, and user-selected avatars support the contacts workspace and name display.The device-local SQLite database.
PreferencesTheme, sync interval, notifications, remote-image mode, and autostart operate the app as you choose.The device-local SQLite database.
Local diagnostic logsEvents such as startup, sync mode, and error category support on-device troubleshooting. Logs exclude addresses, subjects, recipients, bodies, tokens, and complete paths.Your device’s local log directory.

3. Google user data

Permissions requested

  • openid and email: identify the Google account and email address you authorize.
  • https://mail.google.com/: authenticate to Gmail IMAP and SMTP with XOAUTH2 so Mine Mail can read, synchronize, organize, and send mail.

Why narrower permissions are not sufficient

Mine Mail’s core architecture uses standard IMAP/SMTP rather than the Gmail REST API. Google requires Gmail IMAP, POP, and SMTP OAuth access to use https://mail.google.com/. Read-only or task-specific Gmail API scopes cannot authenticate IMAP/SMTP and cannot preserve full-client behavior for drafts, folder state, stars, and sending.

Use limitations

Google user data is used only to provide mail-client features you explicitly request: displaying and searching locally synchronized mail, synchronizing message state and drafts, sending messages, and creating on-device mail notifications. It is not used for advertising, profiling, credit or lending, surveillance, access by human reviewers, or training generalized AI or machine-learning models.

Google API Limited Use: Mine Mail’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Local storage and security

  • OAuth tokens and mail authorization secrets are stored in the operating-system credential store, not in the React interface, this website, or the SQLite mail cache.
  • Account metadata, mail cache, bodies, drafts, outbox, contacts, and settings are stored in SQLite under the app-data directory.
  • The current SQLite database is not encrypted as a whole. An attacker able to read files belonging to your OS user may read cached mail. Use an OS login password, disk encryption, and trusted local accounts.
  • HTML mail is treated as untrusted input: dangerous content is sanitized, scripts are disabled, and complex content is shown in a no-script isolated area.
  • Local diagnostic logs rotate by size, remove history older than seven days at startup, and have a total-size limit. They are designed not to contain mail content or identity data.

Remote images

Remote images load automatically by default, and you can change the setting to Ask or Blocked. Loading an image can reveal your IP address, client network information, and approximate open time to the image host. Your device makes these requests directly to the sender-selected third party; they do not pass through the Mine Mail developer.

No software can guarantee absolute security. Please use the contact address below to report a security issue that may affect Mine Mail user data.

5. Sharing and transfer

Mine Mail does not transmit mailbox data to developer servers and does not sell, rent, or use it for advertising. To perform a feature you request, data may be handled or sent directly from your device in these limited circumstances:

  • Your mail provider: as necessary to connect, synchronize, and send—for example, Google Gmail or the IMAP/SMTP server you configure.
  • Your operating system: as necessary to protect credentials, display notifications, and run the desktop app.
  • Remote-content hosts: only when remote images in a message are allowed to load and the device requests their URLs.
  • Recipients you choose: when you click Send, your provider receives the content and attachments you instructed it to deliver.
  • Legal requirements: the developer can disclose only information actually held. Because mailbox data is not stored on a Mine Mail server, there is ordinarily no server-side mailbox copy to disclose.

6. Retention and deletion

Original data at your mail provider is retained under that provider’s policies. Mine Mail’s on-device cache remains until you select local mail-cache deletion while removing the account or perform a complete local-data deletion.

The app distinguishes each deletion scope: “Disconnect only” removes the Mine Mail account entry and OS credential while retaining the Google grant and local mail cache. “Revoke authorization and remove” first asks Google to revoke Mine Mail’s OAuth grant, then removes the device credential. You may also select “Delete local mail cache” to delete that account’s SQLite mail, draft, and outbox cache.

Mine Mail reports authorization as revoked only after Google confirms it, and displays an explicit warning if local cache cleanup is incomplete. If the app cannot start, or if you also want to remove settings, contacts, avatars, and logs, follow the manual steps in the Data Deletion Guide.

On Windows, local data is under %LOCALAPPDATA%\com.minemail.desktop. An uninstaller may preserve app data depending on the release and OS behavior. To ensure deletion, quit Mine Mail and manually remove that directory.

7. Website and support communications

This website sets no advertising or analytics cookies and uses no third-party behavioral-analytics scripts. The web server and network providers may process standard network data—such as IP address, request time, browser information, and path—to establish HTTPS connections, deliver pages, and protect the service.

If you voluntarily email tantless8@gmail.com, the developer receives the address and content you provide and uses it only to respond, diagnose the issue, or fulfill a deletion request. Do not send passwords, OAuth tokens, or complete private messages. You may ask for deletion of support material held by the developer.

8. Your choices and rights

  • Stop synchronization or remove an account from Mine Mail at any time.
  • Revoke Mine Mail either through “Revoke authorization and remove” in the app or from your Google Account’s connected-apps page at any time.
  • Delete the local app-data directory to clear Mine Mail’s device cache, settings, contacts, and logs.
  • Set remote images to Automatic, Ask, or Blocked.
  • Request access, correction, or deletion of support data actually held by the developer.

Mine Mail is not directed to children below the age of digital consent in their jurisdiction, and the developer does not knowingly collect their personal information.

This policy may be updated as features, legal requirements, or release status change. Material revisions will appear here with a new effective date.

9. Contact

Data controller and app operator: Tantless (independent developer)

Privacy and support email: tantless8@gmail.com

Website: https://minemail.tantless.online/