Skip to content
Dumka Mail
ProductData usePrivacySupportGitHub↗

Dumka Mail · Trust center

Privacy Policy

How the Dumka Mail desktop app and website handle personal information and Google user data.

Last updated July 23, 2026

1. Scope

This Privacy Policy applies to the Dumka Mail desktop application, this website, and related support interactions. Dumka Mail is an independent open-source project maintained by Maksim Korolyov (contact: mail-support@dumka.dev). It is not affiliated with Google LLC.

Dumka Mail is designed as a local-first application. The project does not operate a hosted mail backend that receives, stores, or processes your Gmail content.

2. Google user data we access

Dumka Mail requests the following information and permissions:

  • Gmail data: messages, threads, headers, labels, attachments, drafts, send state, and mailbox history through the https://www.googleapis.com/auth/gmail.modify scope.
  • Basic profile data: email address, display name, and profile image through the userinfo.email and userinfo.profilescopes so the app can identify the connected account.
  • Optional Calendar data: calendar lists, events, and free/busy data through calendar.calendarlist.readonly, calendar.events, and calendar.freebusy, requested only when you enable Calendar.
  • Optional Contacts data: contact names and addresses throughcontacts.readonly, requested only when you enable Contacts.

3. How we use Google user data

Google user data is used only to provide user-facing Dumka Mail features:

  • Synchronize and display your mailbox in the desktop application.
  • Search, organize, label, archive, trash, and change read state.
  • Compose, draft, reply, forward, schedule, and send messages you control.
  • Build local briefings, follow-up signals, cleanup suggestions, and review queues.
  • Show Calendar and Contacts features after you separately enable them.
  • Provide optional AI-assisted summaries, search, drafting, and proposals after you enable an AI provider and allow the relevant context.

Dumka Mail does not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train or improve generalized AI or machine learning models.

4. Legal basis for processing

Where data-protection law such as the EU/UK GDPR applies, Dumka Mail relies on the following legal bases:

  • Consent: connecting a Google account, and separately enabling optional Calendar, Contacts, or AI features, rely on your consent. You can withdraw that consent at any time by disabling the feature or disconnecting the account.
  • Legitimate interests:operating and securing this website — for example, the hosting provider's request logs described in the website-data section — relies on our legitimate interest in providing a reliable, secure site, balanced against your rights.

Because Dumka Mail is local-first, most processing happens on your own device under your direct control rather than on a Dumka Mail server.

5. Local storage and credentials

Mailbox data, messages, drafts, reminders, settings, sync state, action history, local security analysis, AI conversation history, and optional semantic-search vectors are stored in a local SQLite database in the application-support directory on your computer.

Google OAuth refresh tokens are stored in macOS Keychain on macOS. On supported Windows and Linux systems, they are stored with Electron safeStorage when operating system encryption is available; otherwise, the app uses memory-only storage for that runtime. OAuth tokens are not stored by this website.

6. Data sharing and optional AI providers

The desktop application communicates directly with Google APIs. If you enable an AI feature, the app may send the bounded message content, snippets, or metadata necessary to fulfill your request to the AI provider you configured. This transfer occurs only to provide the visible feature you requested and is subject to that provider's terms and privacy policy.

MCP servers and external search tools are disabled for AI requests by default. If you enable them, they are available only for eligible interactive requests and not for background triage or proposal generation. Dumka Mail does not transfer Google user data to data brokers, advertising platforms, or information resellers.

Dumka Mail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. International data transfers

Dumka Mail does not operate its own servers that receive your Gmail content. If you enable an optional AI provider, or when you access this website, data may be processed in countries outside your own, including outside the European Economic Area.

Any transfer to an AI provider happens only to deliver the feature you requested, is directed by your choice of provider, and relies on that provider's own terms, privacy policy, and transfer safeguards. This website's hosting provider may process request logs in the regions where it operates.

8. Human access

Project maintainers do not have access to the local database on your device. Do not post mailbox content, tokens, secrets, or credentials in public support requests. A maintainer will review specific user data only when you intentionally provide it for support, when required for security or legal reasons, or with your explicit consent.

9. Data retention and deletion

Local data remains on your device until you remove it. Dumka Mail can revoke the Google OAuth token, delete the locally stored credential, and purge account-scoped cached data when you disconnect an account with cache purging enabled. You can also revoke access from your Google Account permissions page.

See the data deletion guidefor exact steps. Support information you submit through GitHub is retained according to GitHub's policies and the lifecycle of that issue or security report.

10. Your rights

Depending on your location, you may have rights under laws such as the GDPR or the CCPA/CPRA, including the rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. Because Dumka Mail is local-first:

  • For data stored on your device — your mailbox cache, drafts, settings, and history — you exercise these rights directly. You can view, change, export through Gmail, or delete this data locally at any time, including by disconnecting an account or removing the application data described in the data-deletion guide.
  • For the limited data handled off-device — public support requests on GitHub and hosting-provider request logs — contact us at mail-support@dumka.dev and we will respond as required by applicable law.

You also have the right to lodge a complaint with your local data-protection supervisory authority.

11. Children's data

Dumka Mail is a general-audience productivity tool and is not directed to children. The app is not intended for use by anyone under the age of 13, or the higher minimum age of digital consent in your jurisdiction (for example, 16 in some European countries). Dumka Mail does not knowingly collect personal data from children. Because the app connects to a Google account you provide, account eligibility is also governed by Google's own age requirements.

12. Website data

This public website does not connect to your Google account and does not use advertising or analytics cookies. The hosting provider may process standard request information such as IP address, user agent, requested URL, timestamp, and diagnostic logs to operate and secure the site. This website never receives your Gmail content or OAuth refresh token.

13. Security

Dumka Mail uses a system browser with OAuth PKCE, OS-backed credential storage where available, Electron context isolation, a sandboxed renderer, and disabled Node.js integration in the renderer. No system is perfectly secure. Please report suspected vulnerabilities using the security reporting process.

14. Your choices

  • Do not connect a Google account if you do not want to grant Gmail access.
  • Leave Calendar and Contacts disabled; their permissions are incremental.
  • Leave AI features disabled or choose a provider with suitable data controls.
  • Block remote images and tracking pixels using the app's privacy settings.
  • Disconnect an account, revoke Google access, and delete local cached data.

15. Changes and contact

This policy will be updated when Dumka Mail's data practices change. Material changes will be reflected by the date at the top of this page and, where applicable, by an in-product notice or renewed consent.

For privacy questions or requests — including data-subject requests under the GDPR, CCPA, or similar laws — email mail-support@dumka.dev or use the support page. Never include tokens, credentials, or real mailbox content in a public issue or in your first message.

Dumka Mail

Local-first email decisions, with the user in control.

ProductFeaturesGoogle data useSource code ↗
TrustPrivacy policyTerms of serviceData deletionSecurity
HelpSupportGitHub issues ↗
© 2026 Maksim Korolyov. Released under the MIT License.Dumka Mail is not affiliated with Google LLC.