Email - Swipe Mail · Legal

Privacy Policy

Last updated: August 19, 2026

This policy is for the Email - Swipe Mail mobile app. It is separate from the Koderead company website policy because Swipe Mail is a mail client: it connects to your existing provider and keeps mail on your device.

Who we are

Koderead Solutions LLP (“we”, “us”) publishes Email - Swipe Mail (the “App”). This policy explains how the App handles information when you download, install, and use it on iOS or Android.

Contact: contact@koderead.com · https://koderead.com/swipemail

In short

  • Swipe Mail is a mail client that talks to your existing provider. We do not host your mailbox.
  • Message content, subjects, attachments, and on-device AI output stay on your device. They are not uploaded to a Swipe Mail server.
  • Sign-in uses OAuth 2.0 with PKCE in the system browser (Google and Microsoft) or an app password you create (Yahoo, iCloud, and other IMAP hosts).
  • Access tokens and IMAP credentials are stored only in the device Keychain (iOS) or Keystore (Android).
  • We do not sell personal information. We do not use Gmail, Microsoft, or IMAP data for advertising. We do not train models on your mail.

Information the App processes

The App processes information on your device in order to provide a mail client. Depending on which accounts you connect and which optional permissions you grant, that may include:

  • Account identifiers: email address, display name, and provider account id.
  • Mail metadata and content: senders, recipients, subjects, labels/folders, dates, snippets, full message bodies, and attachments you open or attach.
  • Authentication secrets: OAuth refresh/access tokens or IMAP/SMTP app passwords, stored in secure device storage.
  • App preferences: swipe mappings, theme, rules, blocked senders, snooze times, and biometric lock setting — stored locally.
  • Optional device features you enable: Face ID / biometrics (to unlock the App only), calendar writes (when you add an event from a message), contacts (when you pick recipients), and local notifications (snooze and new-mail alerts).

How Swipe Mail uses Google user data

If you connect a Google account, the App requests only the Gmail API scopes required to operate as a mail client: gmail.modify (read, send, and apply labels such as Inbox, Archive, and Trash) and gmail.settings.basic (unsubscribe and related mailbox settings). The App does not request the full mail.google.com scope and does not permanently delete messages — delete is always a move to Trash.

Google user data is used solely to provide and improve user-facing mail features in the App: showing your inbox, searching, sending, organizing, and related actions you initiate.

Swipe Mail’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do not transfer Google user data to others except as necessary to provide the App features you request (for example, sending a message through Gmail), for security, or as required by law.
  • We do not use Google user data to serve advertisements.
  • We do not allow humans to read Google user data unless you give us explicit consent for a support case, it is necessary for security, or we are required to by law.
  • We do not use Google user data to train generalized AI or ML models.

Microsoft accounts

If you connect Outlook, Hotmail, or Microsoft 365, sign-in uses the Microsoft identity platform (OAuth 2.0 + PKCE). Mail is accessed to display, send, and organize your messages. Microsoft’s own privacy statement also applies to data Microsoft holds.

IMAP and SMTP accounts

For Yahoo, iCloud, AOL, and custom IMAP hosts, you provide an email address and (typically) an app-specific password. Those credentials are stored only on-device. The App connects directly to your provider’s IMAP/SMTP servers. Your provider’s privacy policy governs the data they store.

On-device AI

Summaries, smart replies, compose assistance, categorisation, and sender checks run on your device (or via Apple/Google on-device model APIs when available). Mail content used for these features is not sent to a Swipe Mail backend. A “generated on your device” marker is shown for AI summaries.

Local storage and security

A local SQLite cache (including a full-text search index) is kept on the device so the inbox opens quickly and works offline. Tokens never appear in app models or logs. You can sign out of an account or delete local data from Settings. Uninstalling the App removes the local cache.

We do not sell or share for ads

We do not sell personal information. The App does not include third-party advertising SDKs. We do not share mail content with data brokers.

Children

The App is not directed to children under 13 (or the equivalent age in your region). We do not knowingly collect personal information from children.

Your choices and rights

You can disconnect an account, turn off optional permissions in system settings, disable notifications, and uninstall the App at any time. Depending on where you live, you may have rights to access, correct, delete, or export personal information we hold. For Swipe Mail, that information is primarily on your device; email us and we will help you exercise those rights.

Privacy requests: contact@koderead.com

Retention

Local cache and tokens remain until you sign out, clear local data, or uninstall. We do not operate a mail-content database. Support emails you send us are kept as needed to resolve your request.

Changes

We may update this policy. The “Last updated” date at the top will change, and the current version will always be published at https://koderead.com/swipemail/privacy.

Koderead Solutions LLP · Email - Swipe Mail · contact@koderead.com