1. Scope
This Privacy Policy applies to the Dumka Mail desktop application, this website, and related support interactions. Dumka Mail is an independent open-source project maintained by Maksim Korolyov (contact: mail-support@dumka.dev). It is not affiliated with Google LLC.
Dumka Mail is designed as a local-first application. The project does not operate a hosted mail backend that receives, stores, or processes your Gmail content.
2. Google user data we access
Dumka Mail requests the following information and permissions:
- Gmail data: messages, threads, headers, labels, attachments, drafts, send state, and mailbox history through the
https://www.googleapis.com/auth/gmail.modifyscope. - Basic profile data: email address, display name, and profile image through the
userinfo.emailanduserinfo.profilescopes so the app can identify the connected account. - Optional Calendar data: calendar lists, events, and free/busy data through
calendar.calendarlist.readonly,calendar.events, andcalendar.freebusy, requested only when you enable Calendar. - Optional Contacts data: contact names and addresses through
contacts.readonly, requested only when you enable Contacts.
3. How we use Google user data
Google user data is used only to provide user-facing Dumka Mail features:
- Synchronize and display your mailbox in the desktop application.
- Search, organize, label, archive, trash, and change read state.
- Compose, draft, reply, forward, schedule, and send messages you control.
- Build local briefings, follow-up signals, cleanup suggestions, and review queues.
- Show Calendar and Contacts features after you separately enable them.
- Provide optional AI-assisted summaries, search, drafting, and proposals after you enable an AI provider and allow the relevant context.
Dumka Mail does not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train or improve generalized AI or machine learning models.
4. Legal basis for processing
Where data-protection law such as the EU/UK GDPR applies, Dumka Mail relies on the following legal bases:
- Consent: connecting a Google account, and separately enabling optional Calendar, Contacts, or AI features, rely on your consent. You can withdraw that consent at any time by disabling the feature or disconnecting the account.
- Legitimate interests:operating and securing this website — for example, the hosting provider's request logs described in the website-data section — relies on our legitimate interest in providing a reliable, secure site, balanced against your rights.
Because Dumka Mail is local-first, most processing happens on your own device under your direct control rather than on a Dumka Mail server.
5. Local storage and credentials
Mailbox data, messages, drafts, reminders, settings, sync state, action history, local security analysis, AI conversation history, and optional semantic-search vectors are stored in a local SQLite database in the application-support directory on your computer.
Google OAuth refresh tokens are stored in macOS Keychain on macOS. On supported Windows and Linux systems, they are stored with Electron safeStorage when operating system encryption is available; otherwise, the app uses memory-only storage for that runtime. OAuth tokens are not stored by this website.
6. Data sharing and optional AI providers
The desktop application communicates directly with Google APIs. If you enable an AI feature, the app may send the bounded message content, snippets, or metadata necessary to fulfill your request to the AI provider you configured. This transfer occurs only to provide the visible feature you requested and is subject to that provider's terms and privacy policy.
MCP servers and external search tools are disabled for AI requests by default. If you enable them, they are available only for eligible interactive requests and not for background triage or proposal generation. Dumka Mail does not transfer Google user data to data brokers, advertising platforms, or information resellers.
7. International data transfers
Dumka Mail does not operate its own servers that receive your Gmail content. If you enable an optional AI provider, or when you access this website, data may be processed in countries outside your own, including outside the European Economic Area.
Any transfer to an AI provider happens only to deliver the feature you requested, is directed by your choice of provider, and relies on that provider's own terms, privacy policy, and transfer safeguards. This website's hosting provider may process request logs in the regions where it operates.
8. Human access
Project maintainers do not have access to the local database on your device. Do not post mailbox content, tokens, secrets, or credentials in public support requests. A maintainer will review specific user data only when you intentionally provide it for support, when required for security or legal reasons, or with your explicit consent.
9. Data retention and deletion
Local data remains on your device until you remove it. Dumka Mail can revoke the Google OAuth token, delete the locally stored credential, and purge account-scoped cached data when you disconnect an account with cache purging enabled. You can also revoke access from your Google Account permissions page.
See the data deletion guidefor exact steps. Support information you submit through GitHub is retained according to GitHub's policies and the lifecycle of that issue or security report.
10. Your rights
Depending on your location, you may have rights under laws such as the GDPR or the CCPA/CPRA, including the rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. Because Dumka Mail is local-first:
- For data stored on your device — your mailbox cache, drafts, settings, and history — you exercise these rights directly. You can view, change, export through Gmail, or delete this data locally at any time, including by disconnecting an account or removing the application data described in the data-deletion guide.
- For the limited data handled off-device — public support requests on GitHub and hosting-provider request logs — contact us at mail-support@dumka.dev and we will respond as required by applicable law.
You also have the right to lodge a complaint with your local data-protection supervisory authority.
11. Children's data
Dumka Mail is a general-audience productivity tool and is not directed to children. The app is not intended for use by anyone under the age of 13, or the higher minimum age of digital consent in your jurisdiction (for example, 16 in some European countries). Dumka Mail does not knowingly collect personal data from children. Because the app connects to a Google account you provide, account eligibility is also governed by Google's own age requirements.
12. Website data
This public website does not connect to your Google account and does not use advertising or analytics cookies. The hosting provider may process standard request information such as IP address, user agent, requested URL, timestamp, and diagnostic logs to operate and secure the site. This website never receives your Gmail content or OAuth refresh token.
13. Security
Dumka Mail uses a system browser with OAuth PKCE, OS-backed credential storage where available, Electron context isolation, a sandboxed renderer, and disabled Node.js integration in the renderer. No system is perfectly secure. Please report suspected vulnerabilities using the security reporting process.
14. Your choices
- Do not connect a Google account if you do not want to grant Gmail access.
- Leave Calendar and Contacts disabled; their permissions are incremental.
- Leave AI features disabled or choose a provider with suitable data controls.
- Block remote images and tracking pixels using the app's privacy settings.
- Disconnect an account, revoke Google access, and delete local cached data.
15. Changes and contact
This policy will be updated when Dumka Mail's data practices change. Material changes will be reflected by the date at the top of this page and, where applicable, by an in-product notice or renewed consent.
For privacy questions or requests — including data-subject requests under the GDPR, CCPA, or similar laws — email mail-support@dumka.dev or use the support page. Never include tokens, credentials, or real mailbox content in a public issue or in your first message.