Informations légales et licences

Politique de confidentialité

Où vos données sont traitées et comment les gérer.

Cet article est actuellement disponible en anglais et en chinois simplifié. Le texte anglais est affiché ci-dessous. English · 简体中文

Updated October 11, 2026 · For Mailwake 1.0

Scope and contact

Mailwake is developed and operated by an independent developer. In this policy, “we” refers to that developer. For questions about your data, contact mailwake@oritx.com.

This policy explains data processing for the Mailwake website, iOS application, and official services, and distinguishes it from processing on your own Core server.

  • Self-hosted Core: You operate Core and manage its configuration, credentials, and records. Core connects to your chosen mailbox and notification providers. Enabling official service integration also sends the pairing, delivery, and authorization data described below to Mailwake services.
  • iOS application: The app connects to your authorized Core server, handles notifications on your device, and communicates with official services for device registration, pairing, purchase verification, and recovery.
  • Official services: We process data needed for the features you use. Device registration, pairing, tests, and service identity recovery can involve data processing before a Pro purchase. Pro features require the corresponding entitlement, including an eligible active trial.

Your mailbox provider, self-hosting provider, and chosen third-party notification services also process data under their own terms and policies.

Mailboxes and message content

Data stored by Core: Your mailbox address, connection settings, and credentials are stored in your server’s data directory. Core encrypts stored credentials with a local key and uses them to authenticate with your mailbox provider over TLS. It reads messages to monitor selected folders. Authorized app access and notification delivery send the relevant data to their configured recipients, as described below. Protect your data directory, key, and backups together.

Native encrypted push: Core can read new messages to identify verification codes. It encrypts notification content, such as the sender, subject, and code, for your paired device before sending it through our push services. Those services process ciphertext and the identifiers, timestamps, and status needed for delivery; they hold no device decryption keys. New-mail push requires Pro entitlement. Pairing and test notifications also involve device and delivery data.

Read-only body feature (optional): When you open a read-only message body, the iOS application retrieves it directly from your authorized self-hosted service over HTTPS and displays it in memory for the reading session. The body does not pass through our services or enter the application’s notification history. Your self-hosted service parses bodies in memory; delivery tasks, history summaries, and notification content follow their own storage rules on your server.

Third-party notification services: When you select Bark, Pushover, or a webhook, your configured recipient receives the corresponding notification content from your self-hosted service. Review that service’s privacy policy and preview settings. The encryption description above for native push applies only to Mailwake official Pro services.

For technical implementation and encryption design details, see the security and encryption documentation.

Devices, purchases, and notifications

The following processing depends on the official features you use; it also applies to device and identity operations that occur before a purchase:

Device management: We use a random service identity, device identifiers, public keys, session token hashes, and recovery code hashes for registration, authentication, and recovery. We also process self-hosted service identifiers, pairing relationships, device identifiers required by Apple’s push service, language, encrypted payloads, and delivery status. Live Activities use their corresponding start, update, and end tokens.

Purchase processing: Apple processes payments. We associate verified transactions with your random service identity and store transaction identifiers, products, purchase and expiry times, and refund or revocation status to provide, restore, and reconcile Pro and Supporter purchases. Mailwake does not receive your payment card details.

Purchase notifications: After verifying an Apple server notification, our service forwards the original signed notification to Pockit, our purchase notification provider, for developer purchase alerts. Depending on the event, it can include transaction and product identifiers, your random purchase association identifier (appAccountToken), purchase or renewal status, times, price, currency, and App Store region. This notification contains purchase data; it does not include your mailbox password or email message content.

Notification history is stored on your device with system file protection. You can adjust retention or clear history in the application, and disable notifications in system settings. Decrypted notifications, codes, and Live Activities may appear on your lock screen; adjust system previews to suit your needs.

Website, voting, and support

The website uses your saved language choice first and your browser language at language-neutral entries. Choosing a language stores a language preference cookie for one year. Explicit language URLs keep their language. The hosting interest poll stores a random identifier and your choice in browser storage, and submits that identifier, choice, page language, and timestamps to update your browser’s vote and measure demand. Clearing website data removes the local record; the server-side vote remains.

Cloudflare hosts the website and APIs. IP addresses and request information are processed for delivery, security, rate limiting, and diagnostics. The poll uses invisible Turnstile verification, which runs in the background when you submit a vote. See Cloudflare’s Turnstile Privacy Addendum for how verification information is processed. The voting database stores only the voting fields listed above. The current website has no advertising or marketing tracking scripts.

When you contact support, we receive the email address, message, and attachments you provide. Remove passwords, recovery codes, tokens, and unrelated message content before sending diagnostics.

Providers and processing locations

Cloudflare provides website hosting, official APIs, storage, and security. Apple provides purchases and system push delivery. Pockit receives the purchase notifications described above. These providers process network information, purchase information, or encrypted pushes and delivery metadata as needed for their roles. Processing locations depend on their infrastructure and may be outside your country or region.

See the Cloudflare privacy policy and Apple privacy policy. The locations of your self-hosted service, mailbox, and backups depend on your choices and providers.

Retention and deletion

Data in self-hosted software: Your self-hosted service’s administrator delivery history normally retains successful records for about 7 days and failed records for 30 days. Task payloads are cleared after the channel accepts a request; final native push failures also clear payloads. Failed third-party tasks retain payloads for manual retries. All mailbox configurations, monitoring rules, backups, and other data are stored on your server and managed by you.

Data in official services (only when you use them): Our services clear notification ciphertext when delivery reaches a terminal state. Terminal Live Activities clear their ciphertext, and tokens needed to end an activity are cleared after cleanup. Device notification history follows your selected retention period and can also be cleared manually.

Deleting an official service identity disables its identity and devices, removes sessions and recovery codes, and synchronizes pairing revocation and associated ciphertext and token cleanup with our services. Failed synchronization is retried. Associated identities, device public keys and revocation records, purchases, and delivery status records may be retained for entitlement reconciliation, duplicate processing prevention, and diagnostics. The current version has not established uniform automatic deletion periods for these records and website poll votes.

To access, correct, or delete data we hold, contact us at the email below; we will verify the relationship between your request and your data, and explain what can be handled and what must be retained under applicable law. Deleting an official service identity does not delete your self-hosted service, mailbox, device local history, or backups, nor does it automatically cancel Apple subscriptions.

Your choices and requests

You can stop folder monitoring, remove mailbox settings from your self-hosted service, unpair devices, revoke devices, clear local history, or stop using a feature. For a website vote, providing the identifier in your browser’s local voting record can help us locate it. Never send session tokens or recovery codes.

Send data and privacy requests to mailwake@oritx.com. We handle requests under applicable rules. Use the service when you can consent to data processing yourself or have any necessary consent from a parent or guardian.

Policy updates

We will update this page and its date when processing changes. Where a change requires a separate notice or consent, we will provide the appropriate notice or obtain consent. Please also read the terms of service.