Privacy Policy
Effective October 4, 2026
Who we are
Mailroom is made by Anton Savytski, a sole proprietor carrying on business as Anatoli Labs in Toronto, Ontario, Canada (“Anatoli Labs”, “we”, “us”). This policy covers the Mailroom app for macOS (“Mailroom”) and this website. Questions go to hello@anatolilabs.com.
What we collect
Through Mailroom, nothing. Mailroom has no analytics, telemetry, crash reporting, usage statistics or advertising identifiers, and it never sends your mail, contacts, calendar, passwords or settings to us. We can’t see what you do in Mailroom, and we couldn’t share or sell your information because we don’t have it.
If you email us, we receive your email address and what you write, and use them only to reply. We keep that correspondence only as long as we need it to help you.
What Mailroom keeps on your Mac
To work, Mailroom stores the following on your Mac, in your user account’s Library:
- A copy of your mail, folders, tags, calendars and contacts, so they open quickly and can be read offline.
- Your account settings, and your passwords, sign-in tokens and API keys.
- Your preferences, such as theme, signatures and AI instructions.
The copy of your mail is kept in an encrypted database. Passwords, sign-in tokens and keys are encrypted too. The keys for all of it are kept in your macOS Keychain. None of this data leaves your Mac except as described below.
Connections Mailroom makes for you
Mailroom connects to other services only to do what you ask. Each of these services is run by someone else, under its own terms and privacy policy, which we don’t control.
- Your mail, calendar and contacts servers (for example Gmail, iCloud, Fastmail or Purelymail), over IMAP, SMTP, CalDAV and CardDAV, to sync your data and send your messages.
- Google, Microsoft or Yahoo, if you choose to sign in with them instead of a password. Mailroom uses your own app registration with them, and receives a sign-in token, never your password.
-
Account setup lookups. When you type an address at a domain Mailroom
doesn’t know, it looks up where that domain’s mail is handled (its DNS records), and
asks for the domain’s published mail settings: from the domain itself
(
autoconfig.and/.well-known/addresses) and from Mozilla’s Thunderbird provider database. Only the domain is sent, never your address. - AI services, only when you ask. When you click Reply with AI, Translate or Summarize, the text of that message or conversation (no attachments or images) goes to the AI service you set up: OpenRouter, which Mailroom asks to use only providers that don’t store or train on prompts, or a model server you run yourself, such as Ollama. Nothing is sent to an AI service unless you click.
- Remote images, only when you allow them. Mailroom blocks images stored on other servers until you choose to load them. When you do, those servers can see your IP address and that the message was opened.
- Links and unsubscribing. Links you open go to your web browser. When you confirm Unsubscribe, Mailroom sends the mailing list’s own unsubscribe request.
Some things that may look like they need a server happen on your Mac: search, the guess that a message is in another language, and the warnings about misleading links and unconfirmed senders.
This website
This website doesn’t use cookies, analytics, advertising or tracking scripts, and it doesn’t load fonts or other resources from third parties. It’s hosted by Cloudflare, which processes technical information such as IP addresses to deliver and protect the site, under Cloudflare’s privacy policy. If you download Mailroom from a third-party service such as GitHub, that service’s privacy policy applies to the download.
Children
Mailroom isn’t directed at children under 13. It doesn’t collect information from anyone, including children.
Your choices
- Remove an account in Mailroom’s Settings to delete its mail and settings from your Mac. Your mail on the server isn’t affected.
- To remove everything, quit Mailroom, delete it from Applications, and delete the folder
~/Library/Application Support/Mailroom. The “Mailroom Safe Storage” item can be removed in Keychain Access. - To stop AI requests, don’t use the AI features, or remove your API key in Settings › AI.
Security
Mailroom connects over encrypted connections and checks servers’ certificates. Each message is shown in an isolated view with no scripts. Your data on your Mac is encrypted, with keys held by your Keychain. No method of storing or sending information is completely secure, and keeping your Mac, its password and its updates secure is up to you.
Where information goes
We don’t transfer your information anywhere, because we don’t receive it. The services you connect Mailroom to may store and process your information in other countries, under their own policies.
Changes to this policy
If we change this policy, we’ll update it here and change the date at the top. If a change affects what Mailroom does with your information, we’ll say so in the release notes of the version that makes the change.
Contact
Questions or concerns: hello@anatolilabs.com, Anatoli Labs, Toronto, Ontario, Canada. You can also contact the Office of the Privacy Commissioner of Canada about how a business handles personal information.