Privacy Policy

Last updated: September 22, 2026

Premail is designed to help you manage your inbox while keeping your email private. Premail processes email on your own computer whenever possible and does not operate servers that receive, store, or process your email message content.

This policy explains what information Premail accesses, how that information is used, how it is stored, and what choices you have. For Gmail users, this policy also explains how Premail accesses, uses, stores, protects, shares, retains, and deletes Google user data.

Information Premail collects or accesses

Premail may collect or access the following types of information depending on how you use the app.

Account information

If you create a Premail account or purchase a license, Premail may collect basic account information such as your email address, license status, subscription status, and authentication identifiers needed to manage your account.

Linked email accounts

When you connect an email account, Premail may access the data needed to provide its email management features. This may include message metadata, headers, sender information, recipient information, subject lines, labels, folders, unsubscribe information, and message bodies.

Premail uses this information only to provide the features you enable, including inbox review, rule-based filtering, archiving, trashing, labeling, marking messages as read, unsubscribing, and other email cleanup actions.

Local app data

Premail may store app settings, rules, account configuration, email processing state, local logs, and related app data on your device so the app can function properly.

Payment information

Payments are processed by third-party payment providers. Premail does not store full payment card numbers. Payment providers may provide Premail with limited billing information such as subscription status, transaction identifiers, plan type, and renewal status.

Diagnostics and support information

If you contact Premail for support, you may choose to provide diagnostic information, screenshots, logs, or other information needed to investigate your request. Premail only uses this information to provide support and improve reliability.

Feedback and optional contact information

You may submit product feedback anonymously. An email address is not required. If you explicitly ask Premail to contact you about a specific submission, Premail collects the address you voluntarily provide and uses it only for that feedback or support interaction.

Follow-up permission is separate from marketing consent. Providing an address does not enroll you in marketing, newsletters, or general product outreach. Premail does not sell it or share it for advertising.

Website cookies and analytics

Premail uses Google Analytics on this website to understand aggregate traffic, checkout, and download behavior. Advertising storage, Google Signals, ad user data, and ad personalization are disabled. Activation credentials, license tokens, form values, and email addresses are not sent to analytics.

For visitors in the EEA and United Kingdom, analytics remains off until Allow all is selected. California visitors may see analytics load before making a choice and can stop it with Reject unnecessary. When location cannot be resolved, analytics remains off. Other visitors can use Privacy choices in the footer at any time.

The choice is stored in local storage on this browser. Reject unnecessary disables analytics, clears Google Analytics cookies, and records a one-way revocation so later subscription, payment-failure, cancellation, or refund events are not reported. The browser retries that withdrawal on a later visit if the first request is interrupted. Clearing site data forgets the choice. Necessary payment, security, App Check, and authentication storage continues to work. Analytics page URLs keep only approved campaign parameters and bounded checkout state; other query values and URL fragments are removed before reporting.

To select the applicable consent behavior, Premail uses hosting-provided country and region headers when available. Otherwise, a same-origin function asks GeoJS to resolve the request IP to country and region. Premail does not store the IP or lookup response.

A verified Stripe webhook may report a purchase or refund to Google Analytics only when the originating browser has a current analytics grant. The server stores only a one-way hash of the browser's random consent identifier, uses a one-way transaction identifier that cannot retrieve a license, and never exposes its Measurement Protocol secret.

Optional desktop product analytics

Anonymous product analytics in the Premail desktop app is off by default. Premail asks once during onboarding, and you may enable or disable it at any time from the toggle in the app footer. If enabled, the app sends a limited event allowlist to PostHog for onboarding, activation, reliability, first-value, and retention analysis.

These events use an anonymous installation identifier and bounded categories or counts. They do not include email content, sender, subject, recipient, email address, account ID, API key, prompt, rule text or ID, custom domain, folder or label name, checkout session, activation credential, license token, or raw error. PostHog persistence is kept in memory. Disabling analytics stops further capture and deletes the local anonymous analytics identifier and transmitted milestone markers. A local-only first-open timestamp remains so a later opt-in can measure retention from Premail's local measurement baseline rather than from the consent click; it is never transmitted while analytics is disabled. PostHog Cloud does not currently provide Premail with a project-level product-event expiration setting, so submitted events remain under the vendor's account and project lifecycle until Premail deletes them or closes the project. Access is limited to the product owner and designated maintainer, who review continued need monthly. Contact Support before opting out if you want to request access to or deletion of data associated with the anonymous identifier; after opt-out, that identifier is no longer available locally.

Google user data

If you connect a Gmail account to Premail, Premail uses Google OAuth to access only the Gmail data needed to provide the email filtering, cleanup, unsubscribe, labeling, archiving, trashing, and inbox review features that you choose to use.

Depending on the permissions you grant, Premail may access Gmail message metadata, headers, labels, sender information, recipient information, subject lines, message bodies, unsubscribe information, and related mailbox data so the app can classify messages, apply your rules, and take the actions you request.

Premail processes Gmail data locally on your computer. Gmail OAuth tokens are stored only on your device. Premail does not operate servers that receive, store, log, or process your Gmail message content, Gmail mailbox data, or Gmail OAuth tokens.

Premail uses Gmail data only to provide and improve user-facing Premail features that are visible in the app. Premail does not use Gmail data for advertising, retargeting, personalized ads, credit decisions, lending, resale, data brokerage, or training AI models.

Premail does not sell, rent, transfer, or disclose Gmail data to third parties.

If you choose to use a bring-your-own-key AI provider such as OpenAI or Anthropic, email content may be sent directly from your computer to that provider for classification or rule processing. Those requests do not pass through Premail servers, and the provider's own privacy policy applies. To keep Gmail content fully local, use the local Ollama option.

Premail may take actions in your Gmail account only when configured by you, triggered by rules you create or enable, or initiated by you in the app. These actions may include applying labels, archiving messages, moving messages to trash, marking messages as read, or unsubscribing when available.

Because Premail stores Gmail data locally, you can remove locally stored Gmail data by deleting the linked Gmail account inside Premail or uninstalling Premail. You can also revoke Premail's Google access at any time from your Google Account security settings. If you delete your Premail account, Premail removes your subscription or account record from its authentication provider. Premail has no server-side Gmail message content to delete.

Premail protects Google user data by storing account tokens locally on your device, using encrypted connections to Google APIs, and limiting access to the minimum Gmail permissions needed for the features you enable.

How Premail uses information

Premail uses information to:

  • Connect to email accounts you authorize
  • Display and organize your inbox
  • Classify email according to built-in rules and custom rules you create
  • Apply actions you request, such as archive, trash, label, mark as read, or unsubscribe
  • Maintain your app settings and preferences
  • Manage licenses, subscriptions, and account status
  • Provide customer support
  • Diagnose bugs, crashes, and reliability issues
  • Improve Premail's user-facing features

Premail does not use your email content for advertising, resale, data brokerage, or AI model training.

Local processing

Premail is designed as a local-first desktop app. Email processing happens on your computer whenever possible.

Your email credentials, OAuth tokens, account configuration, rules, and local processing data are stored on your device. Premail does not run a cloud service that ingests or stores your email message content.

AI processing options

Premail may offer AI-assisted email classification or rule processing. You control which AI option you use.

Local AI

If you use a local AI option such as Ollama, email content is processed locally on your computer and is not sent to Premail or to a third-party AI provider.

Bring-your-own-key AI providers

If you configure Premail to use a third-party AI provider such as OpenAI or Anthropic with your own API key, Premail may send relevant email content directly from your computer to that provider so the selected feature can run.

Those requests do not pass through Premail servers. The third-party provider's own privacy policy, data handling terms, and API terms apply to that processing.

Premail does not use email content to train AI models.

What Premail never does

Premail does not:

  • Sell your email content
  • Rent your email content
  • Use your email content for advertising
  • Use your email content for retargeting or personalized ads
  • Use Google user data for credit decisions or lending purposes
  • Use Google user data for resale, data brokerage, or creating unrelated databases
  • Use your email content to train AI models
  • Send your email content to Premail servers for processing
  • Share your Gmail message content or OAuth tokens with third parties
  • Access your email accounts except to provide the features you authorize

Referral and affiliate program data

This section covers people who join Premail’s affiliate/referral program (see the referral program page and its affiliate terms). Joining is optional and separate from ordinary local-first Premail use: an affiliate identity is never linked to, or joined against, any customer’s mailbox data or license/account records in Premail’s reporting or analytics.

At enrollment, Premail collects the email address and optional display name you provide, the version and time of the affiliate terms you accepted, and your country (used to check program eligibility and payout method availability). Referral links and codes are attributed to a purchase using a first-party record on Premail’s servers, not a third-party ad-tech tracker.

Attribution storage and the explicit-code fallback: opening a referral link stores the referral code in this browser’s local storage only if you have accepted analytics cookies (see “Website cookies and analytics” above); otherwise it is kept only in this tab’s session storage, which is cleared when the tab closes. Either way, a referral code you type in yourself at checkout always works and always overrides a previously stored code; entering a code directly does not require cookie consent. A referral code is not automatically a discount; it only identifies who referred you.

If you are approved for payouts, Premail uses Stripe’s Global Payouts product to send money to you. Bank account, card, and identity-verification details you provide during payout onboarding are collected directly by Stripe’s hosted onboarding flow and are never received, stored, or logged by Premail: Premail stores only a Stripe recipient reference and a readiness status. Any tax-reporting document you provide (for example a W-9 or W-8) is collected through a dedicated secure workflow described in Premail’s tax-operations process, never by email or through a support ticket; Premail’s own records store only a status (pending, cleared, or blocked) and an opaque reference to that workflow, never a taxpayer identification number or the document itself.

Premail retains affiliate enrollment, attribution, commission, and payout records for as long as needed to calculate and pay commissions, resolve disputes, and satisfy financial recordkeeping and tax-reporting obligations, even after an affiliate account is closed or a deletion request is made. Deleting an affiliate’s account removes the optional profile information (display name), but Premail cannot delete the financial ledger entries (commissions, adjustments, payouts) a completed transaction already created, for the same reason a completed purchase’s billing record cannot be deleted on request.

Enrolling in the affiliate program does not opt you in to marketing email. Affiliates receive only transactional messages about their own enrollment, commissions, payouts, and required program notices (such as a terms or privacy update). To ask about your affiliate data, or to request deletion of the parts of it Premail can delete, contact support@premail.pro.

Sharing and disclosure

Premail does not sell, rent, or disclose your email content to third parties.

Premail may share limited non-email account information with service providers only as needed to operate the app and business. For example, Premail may use service providers for authentication, licensing, payments, hosting, analytics, crash reporting, or customer support.

These providers may process limited information such as account identifiers, payment status, license status, or diagnostic information. They are not used to process your email message content unless you separately choose to send email content to a third-party AI provider through your own configuration.

Premail may disclose information if required by law, legal process, or to protect the rights, safety, and security of Premail, users, or others.

Data storage and retention

Premail stores most app and email-related data locally on your device.

Locally stored data may remain on your device until you delete it, remove a linked account, reset the app, or uninstall Premail.

Premail may retain limited account, license, subscription, payment, and support records as needed to provide the service, comply with legal obligations, resolve disputes, prevent abuse, and maintain business records.

Feedback submissions are retained for 180 days from submission, including any optional contact address and optional diagnostic context attached to that submission. Expired records are hidden from the admin inbox immediately and scheduled for deletion.

Premail does not retain Gmail message content on Premail servers because Premail does not receive or store Gmail message content on Premail servers.

Feedback diagnostics

The desktop app may offer optional diagnostic context with feedback and shows the categories before you submit. This context is limited to privacy-safe app and environment details needed to understand the report.

Premail does not intentionally attach email contents, sender or recipient information, credentials, API keys, OAuth tokens, app passwords, or other sensitive mailbox data to feedback. The website feedback form does not collect diagnostic context. Feedback messages and contact addresses are not sent to website or product analytics.

Deleting your data

You can delete local Premail data by removing linked accounts inside the app, deleting local app data, or uninstalling Premail.

You can revoke Gmail access at any time through your Google Account security settings.

You can request deletion of your Premail account by contacting Premail support. When you delete your Premail account, Premail will delete or de-identify account records that are not required for legal, billing, fraud prevention, security, or compliance purposes.

Because email content is stored locally and not on Premail servers, deleting your Premail account does not delete email content from your own email provider account. To delete emails from Gmail, iCloud, Outlook, or another provider, you must delete those messages through that provider or through Premail actions you initiate.

Security

Premail uses reasonable technical and organizational measures to protect information. These measures include local storage of email tokens, encrypted connections to email providers, OAuth-based authentication where available, and limiting access to the permissions needed to provide Premail features.

No method of storage or transmission is perfectly secure. You are responsible for maintaining the security of your device, operating system account, email accounts, and any third-party API keys you configure.

Email provider permissions

Premail requests email provider permissions only to provide the features you use.

For Gmail, requested permissions may allow Premail to read messages and metadata, manage labels, archive messages, move messages to trash, mark messages as read, and perform other mailbox actions you configure or initiate.

For other providers such as iCloud, Outlook, or IMAP-based accounts, Premail may use the permissions or credentials needed to connect to your mailbox and perform the actions you request.

You can revoke access through your email provider account settings at any time.

Children's privacy

Premail is not intended for children under 13. Premail does not knowingly collect personal information from children under 13.

International users

Premail is operated from the United States. If you use Premail from outside the United States, your information may be processed in the United States or other countries where Premail or its service providers operate.

Changes to this policy

Premail may update this Privacy Policy from time to time. When changes are made, the updated policy will be posted on the Premail website with a revised “Last updated” date.

Contact

If you have questions about this Privacy Policy or want to request deletion of your Premail account, contact Premail at support@premail.pro.