Privacy Policy
Last updated August 2026
InkMail keeps your email on your own device. In plain language, here is the small amount of data the InkMail website and app handle.
Your mail stays with you
The app talks to your own email provider — there is no middleman and no tracking. Your messages and passwords stay on your computer; we never see or receive them, and there is no InkMail server they could be sent to.
Two things do reach the wider internet, and both are listed here rather than buried: the Pro licence check, if you bought Pro, and — only when you send encrypted mail — a lookup for your recipient's public key. Neither carries anything about your messages. Nothing else in InkMail contacts us: no analytics, no crash reporting, no update pings.
Signing in with Microsoft
You can connect an Outlook account with Sign in with Microsoft instead of typing a password. The sign-in happens directly between your computer and Microsoft — InkMail has no server in the middle. The access and refresh tokens it returns are kept only in your operating system's secure keyring on your own device; they are never sent to, or stored on, any InkMail server.
InkMail uses this access for one purpose only: to read, write, send, and delete your mail over IMAP and SMTP, locally on your device, when you ask it to. It does not read your mailbox in the background for any other reason, and no one at InkMail ever sees your messages.
To be explicit about what that means for your account data:
- No Data Transfer: We do not transfer, share, or sell your account data to any third parties, except as strictly necessary to run the app locally on your own device or where legally required.
- No Advertising: We do not use your account data to serve advertisements, including retargeting, personalized, or interest-based advertising.
- No AI/ML Training: We do not use, transfer, or analyze your account data to develop, improve, or train artificial intelligence (AI) or machine learning (ML) models.
- No Human Readability: Because InkMail is a local-only desktop application and stores all your data exclusively on your own device, we have no technical means to access, collect, or read it. No human (including InkMail developers) will ever have access to or read your emails under any circumstances.
Read receipts and tracker statistics
InkMail can ask for a read receipt when you send a message. This is the ordinary email standard (RFC 8098), not a hidden tracking pixel: your message carries a header asking the recipient's email app to confirm, that app asks them, and their answer comes back to you as a normal email. It travels between your mail server and theirs — no InkMail server is involved and we never see it. If someone asks you for a receipt, InkMail shows you the choice; it never answers on your behalf, and has no code that could.
Tracker Shield counts the tracking pixels InkMail blocks in the mail you receive and, with Pro, names the companies behind them. All of that is worked out on your own computer and stored in your local cache. Nothing about who emails you, what they send, or who tracks them is ever uploaded — the list of known trackers ships inside the app itself, so InkMail never has to ask us anything to recognise one.
How we protect your data
- Encrypted in transit. All connections to your email provider use TLS/SSL, and Microsoft sign-in happens over HTTPS. Nothing is sent in the clear.
- Credentials encrypted at rest. Sign-in tokens and passwords are stored only in your operating system's own encrypted, per-user credential vault — Windows Credential Manager, the macOS Keychain, or the Secret Service on Linux. They never leave your device.
- Stored on your device only. Downloaded mail is cached locally in your own user profile. Nothing is uploaded to InkMail — there is no server to breach.
- You stay in control. Removing an account erases its cached mail and stored credentials, and you can revoke InkMail's access anytime from your Microsoft account app permissions.
Removing InkMail
Uninstalling InkMail deletes its cached mail, your settings and its local log along with the app. One thing does not go automatically: the passwords and sign-in tokens for your accounts. Windows, macOS and Linux keep those in the operating system's own credential vault, which sits outside the app, so removing the app does not remove them.
Clearing them is a single action, and InkMail does not have to be uninstalled first: removing an account under Settings → Accounts erases its cached mail and its stored credentials together, and Settings → About → Uninstalling InkMail does the same for every account at once. You can also inspect or delete the entries yourself at any time — they are named ink-mail in Windows Credential Manager, the macOS Keychain or your Linux keyring.
Your licence key is deliberately left in place, so reinstalling doesn't spend one of your three device activations. Settings → Upgrade → Deactivate this device removes it and frees the slot when you actually mean to.
Buying Pro
If you buy InkMail Pro, the payment is handled by Stripe. We receive your email address so we can send your license key and receipt. We never see your card details.
Your license
When you unlock Pro on a device, the app checks your key with us so it stays within the three-device limit, and re-checks about once a month afterwards. This is the only routine call InkMail makes to us, and it only happens if you bought Pro — the free app never contacts us at all.
Each check sends your license key and a few basic details about the device, and nothing else:
- Your license key, which is what identifies the purchase.
- Which device it is — a device name, a scrambled code that stands for that computer, the operating system ("Windows 11", "Windows 10", "macOS" or "Linux") and the InkMail version. The code is worked out on your own machine and mixed with your licence key before it is sent, so it can't be traced back to your computer or matched against anything else — it exists only so your three devices can be told apart, and so the right slot is freed when you replace one. Nothing here identifies you. On Windows, which edition you are on is worked out on your own machine too, and only that answer is sent — the exact build number never leaves it.
Like any request to any website, that check reaches us from an IP address. We do not store it. What we keep instead is a one-way fingerprint of the surrounding network — never the address itself — and we use it for exactly one thing: counting how many different networks a single licensed device turns up on, which is how a license key that has been copied and passed around gets noticed. It is a count and nothing else. It cannot be turned back into an address, it says nothing about where you have been, and it is forgotten after 30 days.
What it never sends: anything at all about your mail, your accounts, your email addresses or who you write to. If you buy Pro and later use Deactivate this device, that device's record is deleted outright, together with everything above.
Finding someone's encryption key
If you send an end-to-end encrypted message, InkMail has to find the recipient's public key first. It looks in mail they already sent you, then asks their own email domain, then a public keyserver (keys.openpgp.org) — the standard OpenPGP places. Those lookups go directly from your computer to that domain or that keyserver over HTTPS; no InkMail server is involved and we are not told about them. They happen only when you compose encrypted mail, never in the background, and ordinary unencrypted email never triggers one.
Feedback
If you send feedback — from inside the app or the feedback form on this site — we receive your message (and, from the app, its version). Adding your email is optional and used only to reply. To curb abuse we keep a one-way hashed fingerprint of your IP address, never the address itself.
Website
Our website counts visits in aggregate so we know roughly how many people drop by. No cookies, no personal data, and no following you around the web.
Contact
Questions? Email us at support at rovo.it.