YOUR MAIL, YOUR CONTROL
Privacy Policy
Effective date: September 27, 2026
This policy explains how Smail: Swipe mail ("Smail"), an iOS application maintained by Simin, handles information. It covers the app distributed by the maintainer and this website. Independently modified or hosted versions may have different practices.
Smail connects your device directly to Google. We do not operate a backend that receives your Gmail messages or Google access tokens. The app does not send your mail to AI services, sell it, or use it for advertising.
1. Information the app accesses
- Google account identity: Google Sign-In requests
openid,userinfo.email, anduserinfo.profile. The app uses your Google account identifier and email address to identify the signed-in account, show its email address, and keep local progress separate between accounts. Google's sign-in SDK may receive basic profile information as part of sign-in. - Gmail information: the app reads Inbox message identifiers, senders, subjects, snippets, received dates, labels, and message bodies to select and display unclassified messages. Supported embedded images may be fetched when you open a message.
- Authorization credentials: Google's iOS sign-in SDK handles the credentials used to authorize direct requests from the app to Google's APIs.
- Your choices: the app keeps the current batch, classification choices, previous Smail label membership needed for undo, pending changes, and your language preference on your device.
2. How the information is used
Smail uses this information only to provide its email-reading and sorting features: find up to ten of the newest unclassified Inbox messages, show their contents, apply classification labels, save progress, retry interrupted operations, and undo a choice.
The app requests https://www.googleapis.com/auth/gmail.modify. Google's permission is broader than Smail's features. Smail restricts its writes in code to creating the two custom labels Smail/Useful and Smail/NotUseful and changing message membership in those labels. It does not delete, trash, archive, or send mail, or change read/unread status.
3. Storage, retention, and protection
The current batch can include message text and HTML, message metadata, and classification history. This information and pending operations are saved in the app's local storage, isolated by Google account. Batch files use iOS file protection and are excluded from device backups. Credentials are managed by Google's sign-in SDK; they are not included in batch files or sent to the maintainer.
Saved batches remain until they are replaced by a new batch, removed through a successful in-app access revocation and cache cleanup, or deleted with the app's local data. Signing out intentionally retains local sorting progress. Switching accounts does not delete another account's saved batch. Displayed reader content and embedded images can also be held temporarily in memory while the app is in use.
Local file protection reduces unauthorized access while a device is locked, but no device or software can guarantee absolute security. Protect your device with an appropriate passcode and keep iOS up to date.
4. Sharing and external connections
Google receives the requests needed for sign-in, reading mail, and applying labels. Smail does not send your mailbox data to the maintainer's servers, analytics services, advertising services, or AI providers. The maintainer does not have routine access to the mail that the app reads.
Remote email images are blocked by default. If you enable them, your device contacts the image hosts specified by the message. Those hosts can receive your IP address and image-request information, including tracking identifiers in the image URL, and may infer that you opened the message. If you tap a link, its destination opens in a Safari view and is subject to that site's practices. Do not enable remote images or open links you do not trust.
5. Google API Limited Use
Smail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is not sold, used for personalized advertising, used to train generalized AI or machine-learning models, or transferred to data brokers. It is used to provide the user-facing features described in this policy. Smail does not provide the maintainer with a service for viewing users' mail.
6. Your controls and deletion
- Sign out: use Settings to sign out while retaining local classification progress.
- Revoke access and remove the current account's cache: use "Revoke Smail's Google Access" in Settings. This requires Google to confirm the revocation; the app then attempts to remove that account's local batch. If cleanup fails, the app displays an error. Pending writes must be resolved before this action is available.
- Revoke access through Google: remove Smail from your Google Account's third-party connections. This revokes permission but does not itself erase the app's local files.
- Remove local app data: delete Smail from your device (not merely offload it) to remove its app-container data, including saved batches for previously used accounts. Google permissions and any SDK-managed credentials should be managed separately through the Google connection controls.
Classification labels already applied remain in your Gmail account after you sign out, revoke access, or delete Smail. You can remove them in Gmail. The maintainer does not hold a server-side copy of your mailbox or local batch to delete on your behalf.
7. Website and support
This site is hosted on GitHub Pages. GitHub may process request information, such as IP addresses, under its privacy statement. The site does not add advertising or analytics trackers. It stores your selected site language in your browser's local storage, which you can clear in browser settings.
If you contact support, we receive the email and information you choose to send, and use it to respond to your request. Do not send access tokens, passwords, or private email contents. Support correspondence may be retained while needed to resolve the request and maintain a support record; contact us to request its deletion, subject to any applicable legal retention obligations.
8. Changes and contact
Changes to this policy will be posted here with an updated effective date. Material changes to how Google user data is handled will be disclosed before the new use and will require consent where applicable.
For privacy questions or support, contact Simin at simin.you.agent@gmail.com.