iHeartMail is an application published by Practical Dev Studio ("we", "us"). This policy explains what the app does with your email and your Google account data.
iHeartMail reads your Gmail and analyses it on your own computer. Your email content is never sent to us, and we operate no server that receives it. We cannot read your mail.
The app does contact us for two limited things — checking for updates, and (if you allow it) sending anonymous crash reports. Neither carries your email. Both are described below.
When you connect your Google account, iHeartMail requests these permissions:
| Permission | What it allows | Why iHeartMail needs it |
|---|---|---|
gmail.modify |
Read your mail; add and remove labels; move messages to Trash; send mail | Reading and categorising your mail; marking messages read or unread; moving messages to Trash; sending, replying, and following up |
openid, userinfo.email,
userinfo.profile |
Your basic Google profile and email address | Showing which account is connected |
iHeartMail requests the narrowest Gmail permission that supports its
features. It does not request full-access permission
(https://mail.google.com/), because it never permanently
deletes mail — "delete" moves a message to Gmail's Trash, exactly as
the Gmail web interface does, and Gmail's own retention rules apply
from there.
You can revoke access at any time from your Google Account permissions page, or by signing out inside the app.
Your email travels between Google's servers and the iHeartMail application on your device. It goes nowhere else.
The analysis that categorises and summarises your mail is performed by a language model that runs inside the iHeartMail application process on your own computer. It is not a cloud service. Nothing is sent anywhere to be analysed.
We operate no server that receives your email. Your email content, subject lines, sender addresses, and attachments are never transmitted to us or to any third party.
iHeartMail keeps a local cache in a database file on your computer, so the app can show your mail instantly and work offline. This cache holds:
iHeartMail does not store full email bodies. When you open a message, its full content is fetched from Gmail at that moment, displayed, and not written to the local database.
iHeartMail does not store sent mail. Messages you send are held by Gmail only.
Your Google access and refresh tokens are stored in your operating system's secure credential store (Windows Credential Manager, macOS Keychain), not in the app's database or in plain text.
Many emails reference images hosted on the sender's own servers — logos, banners, and sometimes invisible "tracking pixels." Loading them tells the sender that you opened the message and when, and reveals your IP address to the server hosting the image.
iHeartMail does not load these images by default. Unless you choose to load them, no request is made to the sender's servers and neither disclosure occurs.
You can turn images on in Settings → Privacy, or load them for an individual message. When you do, images are fetched directly from the sender's host, and that host can see your IP address. iHeartMail has no server to route those requests through — the same design choice that keeps your mail off our infrastructure — so this connection is between your device and the sender's host. It does not involve us, and we learn nothing from it.
iHeartMail periodically checks whether a new version of the application, or of the language model it uses, is available.
An update check sends only what is needed to answer the question: the current application version, and your operating system and processor architecture. It sends no email data, no account identifier, and no Google user data.
Downloaded application and model files are verified cryptographically before they are installed or used, so a tampered file is rejected.
iHeartMail does not currently send crash reports or any diagnostic data. The app contains no telemetry and no analytics.
We may add optional crash reporting in a future version, so that we can find and fix faults. If we do, we commit that it will:
We will update this policy, and the list of network connections below, before any such feature ships.
For transparency, this is the complete list:
iHeartMail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
Your email data lives on your device and is under your control.
Because we hold no copy of your email, there is no deletion request to make of us for it. If we introduce optional crash reporting in the future, that section of this policy will state how long reports are kept and when they are deleted.
Local database files are protected by your operating system's user account permissions. If other people can log into your computer as you, they can read your mail — as they could with any local email client. Use full-disk encryption and a strong account password.
iHeartMail is not directed at children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect their data.
practicaldevstudio.com is a static, hand-written website. It carries no analytics, no cookies, and no third-party scripts, apart from the contact form on this page. If you use that form, the name, email address, and message you enter are sent directly to our inbox by email so we can reply — we keep no other copy of it, and nothing about your visit to the site is otherwise collected or stored.
If we change this policy we will update the date at the top, and material changes will be noted in the app or on this page.
Questions about this policy or about privacy in iHeartMail? Contact us.