PostForged — Privacy Policy

Last updated: 2026-07-16

PostForged is a personal email client that connects directly to your own email accounts (Google / Gmail and Microsoft / Outlook) and shows your mail in one unified, tag-based stream. The short version: your email content never passes through our servers. The only thing we hold is the push registration described below.

Who we are

PostForged is published by VSBIE (Vivid Software, Building Innovative Ecosystems). Contact: [email protected].

No backend, no data collection

PostForged runs entirely on your device and talks directly to Google and Microsoft over their official, encrypted APIs. There is no PostForged server in the middle.

What is stored, and where

Everything PostForged stores lives only on your device:

DataWhereWhy
Synced email (headers + bodies you open)Local app storage (IndexedDB)Speed & offline
Sign-in tokensOS Keychain / Keystore (native) or encrypted on-device (web)Stay signed in without re-entering your password
Your tags, rules, signatures, flags, tasks, contactsLocal storageYour organization system
Optional AI key (bring-your-own)Local storage on your device onlyOptional AI features at your own cost

You can erase all of it any time from Settings → Privacy → Erase all data, which permanently deletes the local data and disconnects your mailboxes.

Permissions we request, and why

When you connect a mailbox, your provider (Google or Microsoft) asks you to grant access. We request the minimum needed to be a functioning mail client:

You grant these directly to your provider through their own secure sign-in window. PostForged never sees or stores your email password. You can revoke access at any time in your Google or Microsoft account security settings.

Optional AI features (bring your own key)

AI features are optional. If you enable them, you supply your own API key (e.g. Google Gemini's free tier), stored only on your device and used to call the AI provider directly from your device. We never see your key or the content you process.

Google user data — Limited Use disclosure

PostForged's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What we request and why. With your permission PostForged uses gmail.modify to show your messages and let you mark them read/unread, tag, archive and delete them; gmail.send to send only the messages you write and send yourself; and calendar.events to create an invitation you attach to a message and to show your own upcoming events. We request nothing we do not use.

Where your mail lives. Your device talks to Google directly, using your own credentials. Message content, attachments, contacts and calendar entries are stored only on your device. We operate no mail server, database, search index or backup, and we keep no copy of your mail. Because your mail never reaches any system we control, no employee or contractor of ours can read it.

Specifically, we do not:

Push notifications. To tell your device that new mail has arrived, we operate one small service that stores only your email address paired with your device's push token. Google's notification tells us a mailbox changed — it contains no sender, subject or message content — and we send your device a generic "New mail" alert. Your device then fetches the message from Google itself. We store no messages, no message metadata, and no Google tokens. When you register a device we briefly receive a short-lived access token solely to confirm you control that mailbox; it is used once, in memory, and discarded — never written to disk or logged.

Revoking access and deleting data. Disconnecting a mailbox in PostForged deletes that account's cached mail from your device, removes its saved credentials from your operating system's keychain, and deletes its push registration from us. Deleting the app removes all remaining local data. You can revoke PostForged's access at any time at myaccount.google.com/permissions.

Third-party services

PostForged talks to a small number of outside services. None of them ever receive your message content. This is the complete list:

ServiceWhat it receivesWhyControl
Google / MicrosoftYour own credentials and mail requestsThey are your mailboxDisconnect the mailbox
unavatar.io A correspondent's email address, to look up a public profile picture Shows a photo instead of a blank initial Settings → Avatars (off disables it entirely)
icons.duckduckgo.comThe domain of a sender (e.g. example.com), never a person's address Shows a company logo for newslettersSame Avatars setting
LanguageTool The text of a draft you are writing, only when you tap “Fix writing” Grammar and spelling suggestionsDon't use the button; nothing is sent otherwise
Our push endpointYour email address and device push tokenTo tell your device new mail arrivedDisconnect the mailbox
Apple Push Notification serviceYour device token and a generic “New mail” alertDelivers the notificationTurn off notifications
Your chosen AI provider (optional)Only text you explicitly submit, using your own API keyOptional AI features, off by defaultDon't enable AI

We receive no payment, data, or benefit from any of these lookups, and none of them are used for advertising, profiling, or tracking you across apps or websites.

Settings sync

If you use PostForged on more than one device, your settings (tags, rules, signatures, category photos) are synced by writing a hidden message to yourself, inside your own mailbox. It never passes through us, and we operate no settings server. Deleting that message simply stops the sync.

Data retention

Push registrations (email address + device token) are kept while the mailbox is connected, and are deleted when you disconnect it, when the app is removed, or automatically when Apple reports the device token is no longer valid. Registrations inactive for more than 12 months are purged.

Who processes data on our behalf

The push endpoint runs on Vercel with a Supabase Postgres database, and delivers through Apple's Push Notification service. Those three handle the push registration described above. They never receive your mail.

Security incidents

If we ever discover a breach affecting the push registration data, we will notify affected users by email at the address registered, and any applicable regulator, without undue delay and within 72 hours of becoming aware.

Children

PostForged is not directed to children under 13, and we do not knowingly collect data from anyone under 13.

Changes

If this policy changes we'll update the date above and note it in the app's release notes.

Contact

[email protected]