Terms and privacy

Privacy policy

Where your data is processed, and how you can manage it.

Updated October 20, 2026 · For Mailwake 1.0

Scope and contact

This policy is published by the Mailwake operator. In this policy, “we” means the Mailwake operator. Contact: mailwake@oritx.com.

This policy covers three types of services, each involving different data processing:

  • Mailwake Core Self-Hosted Software: Open-source software running on your own server. We do not collect, process, or access any data from your self-hosted instance. All mailbox credentials, email content, monitoring configurations, notification records, and other data are stored on your server and fully controlled by you. The data collection terms in this policy do not apply to self-hosted software.
  • iOS Application: The official client software. The application itself does not collect or upload your email content, but will interact with our cloud services when you choose to use Pro services for device pairing and push functionality.
  • Pro Optional Services: Cloud services operated by us, including native encrypted push and device pairing. Only when you explicitly choose and purchase these services will we process the related data described in this policy.

Your self-hosted Core software may connect to your chosen mailbox servers and third-party notification services (such as Bark, Pushover). Data processing by these services is governed by your arrangements with those service providers.

Mailboxes and message content

Data storage in self-hosted software: Your mailbox address, connection settings, and mailbox credentials are stored in your own server’s data directory. Your self-hosted software connects to your mailbox, watches selected folders, and processes new messages. It encrypts stored mailbox credentials with a local key. This data never leaves your server and we cannot access or process it. Protect the data directory, key, and backups together.

When using Pro native push (only when you choose and purchase Pro services): Your self-hosted software may read new messages to identify verification codes. It encrypts notification content such as the sender, subject, and code before sending it through our push services for decryption on your device. Our push services process ciphertext and the identifiers, timestamps, and status needed for delivery; they cannot decrypt message content.

Read-only body feature (optional): When you open a read-only message body, the iOS application retrieves it directly from your authorized self-hosted service over HTTPS and displays it in memory for the reading session. The body does not pass through our services or enter the application’s notification history. Your self-hosted service parses bodies in memory; delivery tasks, history summaries, and notification content follow their own storage rules on your server.

Third-party notification services: When you select Bark, Pushover, or a webhook, your configured recipient receives the corresponding notification content from your self-hosted service. Review that service’s privacy policy and preview settings. The encryption description above for native push applies only to Mailwake official Pro services.

For technical implementation and encryption design details, see the security and encryption documentation.

Devices, purchases, and notifications

Only when you use Pro services, our services process the following data:

Device management: We use a random service identity, device identifiers, public keys, session token hashes, and recovery code hashes for registration, authentication, and recovery. We also process self-hosted service identifiers, pairing relationships, device identifiers required by Apple’s push service, language, encrypted payloads, and delivery status. Live Activities use their corresponding start, update, and end tokens.

Purchase processing: Apple processes purchases. We store verified transaction identifiers, products, purchase and expiry times, and refund or revocation status to provide, restore, and reconcile entitlements. Mailwake does not receive your payment card details.

If you have not purchased or are not using Pro services, we do not collect any of the above data. You can use only the self-hosted Core software and third-party notification services without any interaction with our servers.

Notification history is stored on your device with system file protection. You can adjust retention or clear history in the application, and disable notifications in system settings. Decrypted notifications, codes, and Live Activities may appear on your lock screen; adjust system previews to suit your needs.

Website, voting, and support

The website uses your browser language to select Chinese or English pages. The hosting interest poll stores a random identifier and your choice in browser storage, and submits that identifier, choice, page language, and timestamps to update your browser’s vote and measure demand. Clearing website data removes the local record; the server-side vote remains.

Cloudflare hosts the website and APIs. IP addresses and request information are processed for delivery, security, rate limiting, and diagnostics; the poll uses Turnstile verification. The voting database stores only the voting fields listed above. The current website has no advertising or marketing tracking scripts.

When you contact support, we receive the email address, message, and attachments you provide. Remove passwords, recovery codes, tokens, and unrelated message content before sending diagnostics.

Providers and processing locations

Cloudflare provides website hosting, official APIs, storage, and security. Apple provides purchases and system push delivery. These providers process network information, purchase information, or encrypted pushes and delivery metadata as needed for their roles. Processing locations depend on their infrastructure and may be outside your country or region.

See the Cloudflare privacy policy and Apple privacy policy. The locations of your self-hosted service, mailbox, and backups depend on your choices and providers.

Retention and deletion

Data in self-hosted software: Your self-hosted service’s administrator delivery history normally retains successful records for about 7 days and failed records for 30 days. Task payloads are cleared after the channel accepts a request; final native push failures also clear payloads. Failed third-party tasks retain payloads for manual retries. All mailbox configurations, monitoring rules, backups, and other data are stored on your server and managed by you.

Data in Pro services (only when you use them): Our services clear notification ciphertext when delivery reaches a terminal state. Terminal Live Activities clear their ciphertext, and tokens needed to end an activity are cleared after cleanup. Device notification history follows your selected retention period and can also be cleared manually.

Deleting a Pro service identity disables its identity and devices, removes sessions and recovery codes, and synchronizes pairing revocation and associated ciphertext and token cleanup with our services. Failed synchronization is retried. Associated identities, device public keys and revocation records, purchases, and delivery status records may be retained for entitlement reconciliation, duplicate processing prevention, and diagnostics. The current version has not established uniform automatic deletion periods for these records and website poll votes.

To access, correct, or delete data we hold, contact us at the email below; we will verify the relationship between your request and your data, and explain what can be handled and what must be retained under applicable law. Deleting a Pro service identity does not delete your self-hosted service, mailbox, device local history, or backups, nor does it automatically cancel Apple subscriptions.

Your choices and requests

You can stop folder monitoring, remove mailbox settings from your self-hosted service, unpair devices, revoke devices, clear local history, or stop using a feature. For a website vote, providing the identifier in your browser’s local voting record can help us locate it. Never send session tokens or recovery codes.

Send data and privacy requests to mailwake@oritx.com. We handle requests under applicable rules. Use the service when you can consent to data processing yourself or have any necessary consent from a parent or guardian.

Policy updates

We will update this page and its date when processing changes. Where a change requires a separate notice or consent, we will provide the appropriate notice or obtain consent. Please also read the terms of service.