Privacy Policy

Last updated: August 20, 2026

Overview

Postmark is a macOS menu bar app that connects to your Gmail account so you can read, triage, and reply to email. Postmark runs entirely on your Mac. There is no Postmark server, and we operate no backend that receives, processes, or stores your email.

Google user data we access

When you sign in with Google, Postmark requests the following scopes, each used only to deliver a feature you can see in the app:

  • Gmail — read and modify messages (gmail.modify): to display your inbox and threads, mark messages read or unread, and archive them.
  • Gmail — labels (gmail.labels): to list your labels so you can choose which ones appear in the app.
  • Gmail — send (gmail.send): to send the replies you write in the app. Postmark never sends mail on your behalf without your action.
  • Contacts — read only (contacts.readonly): to match a sender address to their contact photo so messages are easier to scan. Postmark reads contact names, email addresses, and photo URLs only for this purpose.

Postmark does not use Google user data for advertising, profiling, credit assessment, resale, or training machine learning or AI models.

How we protect your data

Your email is sensitive, and Postmark is built so that the smallest possible amount of it is ever stored anywhere. The safeguards we apply:

  • No servers, no copies. Message content, attachments, and contact details are requested directly from Google by the app on your Mac and are never routed through, logged by, or stored on any Postmark infrastructure. No Postmark employee or contractor can access your Google user data, because no copy of it ever leaves your device.
  • Encrypted in transit. All communication with Google APIs uses HTTPS with TLS. Postmark makes no network requests carrying your Google user data to any other destination.
  • Credentials encrypted at rest. OAuth tokens are stored in the macOS Keychain, which encrypts them at rest under protections managed by the operating system. Each connected account gets its own separate Keychain entry. Tokens are never written to log files, preference files, or plain text on disk.
  • We never see your password. Sign-in happens through Google in your system browser using the OAuth 2.0 authorization code flow with PKCE (via the AppAuth library). Postmark never receives, handles, or stores your Google password, and cannot present a fake sign-in screen to capture one.
  • Message content stays in memory. Email bodies, subjects, and sender details are held in memory only while the app is running and are never written to disk. They are discarded when you quit the app.
  • OS-level isolation. Postmark runs inside the macOS App Sandbox, so its stored data is confined to its own container and is not readable by other apps. If you enable FileVault, that container is additionally encrypted at rest with full-disk encryption.
  • Least privilege. We request only the scopes listed above, and only at the point where the corresponding feature needs them.

Data retention and deletion

Postmark retains Google user data only for as long as it needs it to work on your Mac, and deletes it as described below. Because there is no Postmark server, there are no server-side copies, backups, or archives of your Google user data to retain.

  • Message content — not retained. Messages and threads are kept in memory only for the current session and are erased when you quit Postmark or sign out. Nothing is cached to disk.
  • Contact data — not retained. Sender photo lookups are held in memory for at most 15 minutes before being refreshed, and are erased when you quit the app.
  • Account details — retained until you remove the account. Postmark stores the email address, display name, and label preferences of each connected account in its sandboxed local preferences, so it can reopen your accounts the next time you launch it. This is deleted as soon as you remove the account or sign out.
  • OAuth tokens — retained until you sign out. Access and refresh tokens stay in the macOS Keychain so you do not have to sign in every time. They are deleted from the Keychain immediately when you sign out or remove the account.

You can delete your Google user data from Postmark at any time, in any of these ways:

  • Remove one account: open Settings in Postmark and remove the account. Its tokens and stored details are deleted right away.
  • Sign out entirely: signing out clears every account from local storage, deletes all OAuth tokens from the Keychain, and clears all message data from memory.
  • Revoke from Google: visit your Google Account permissions page and remove Postmark. This invalidates its tokens immediately, and Postmark loses all access to your data.
  • Delete the app: we recommend signing out before deleting Postmark, so its stored credentials are removed. If you have already deleted the app, revoking access from your Google Account permissions page renders any remaining stored tokens useless.

Limited Use disclosure

Postmark's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Third parties

Postmark does not sell, rent, or share your Google user data with any third party. The only service that receives your Google user data is Google itself, when the app calls the Gmail and People APIs on your behalf.

Postmark uses Google Firebase Analytics to understand how the app is used and to detect failures. Analytics records app events only — for example that a sign-in succeeded, that the inbox refreshed, or that a reply failed to send, along with a general error category such as "network." It never includes message content, subjects, recipients, contacts, email addresses, names, or OAuth tokens. Purchases are processed by Apple through the App Store; we do not receive or store your payment details.

Children's privacy

Postmark is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

If we change how Postmark handles your data, we will update this page and revise the date at the top. Material changes affecting Google user data will be reflected here before they take effect.

Contact

Questions about this policy, or about data protection and deletion? Reach us at hello@postmarkmailapp.com.