MailTwin
Privacy

Privacy policy

Last updated: 25 July 2026

Summary in one paragraph

MailTwin runs on your Mac. When you ask a cloud AI provider to act on an email, the necessary message or draft and any selected style examples go directly from your Mac to that provider; they never pass through a MailTwin AI server. Provider API keys stay in macOS Keychain and are presented only to the provider you chose. Apple Intelligence and Ollama can run locally. MailTwin's separate update, configuration, licensing, and optional telemetry traffic is listed below.

Inbox Cleanup stays local. It examines sender, subject, date, mailbox, and read/flagged state for up to 150 messages on your Mac. Bodies and attachments stay unopened, and cleanup data is not sent to an AI provider or any new MailTwin network service.

Service traffic and processors

Apart from AI requests you explicitly initiate, MailTwin makes only these service requests:

Data that stays on your Mac

Data that goes to the AI provider you chose

When you trigger an AI action (reply, summarize, improve draft, etc.), we send to the provider:

The provider's privacy policy applies to that traffic. Your API key with that provider is what authenticates the call; from the provider's perspective the request looks identical to any other request from your account.

MailTwin never sends to the provider: any mail beyond the message, draft, and style samples listed above, content from your other accounts, your Keychain, your license key, or the name and email you entered at onboarding.

Auto-update (updates.mailtwin.ai)

MailTwin uses Sparkle 2 to check for updates roughly every 24 hours. The check fetches an XML appcast from https://updates.mailtwin.ai/appcast.xml. The fetch carries a User-Agent of the form MailTwin/<build>. Cloudflare (which serves the file) records the request IP and User-Agent in standard CDN logs. We do not associate update fetches with any other identifier.

Updates are signed with an EdDSA private key held by Smilodon AS. Sparkle verifies the signature against the public key embedded in MailTwin before installing — even if our update host were compromised, an attacker couldn't ship you a malicious update.

Remote configuration (updates.mailtwin.ai)

MailTwin fetches a small JSON document at https://updates.mailtwin.ai/config.json roughly every four hours. Its purpose is to flip a kill-switch on a specific provider/model combination if a third-party API ships a breaking change. The fetch carries the same User-Agent as the appcast above and no other client information.

Opt-in telemetry (telemetry.mailtwin.ai)

Opt-in only — off by default. If you enable telemetry in Settings → Privacy, MailTwin sends pseudonymous product-usage events to https://telemetry.mailtwin.ai/events. A record contains an event name and a strictly limited set of properties (such as action, provider, duration, or error class), a random rotating installation UUID, the MailTwin build, macOS version, and an ISO timestamp. The UUID can distinguish one installation until it is rotated, so it is pseudonymous rather than anonymous; it is not linked to your name, email, license, or purchase.

Cloudflare necessarily processes the source IP at its edge to deliver and rate-limit the request and derives a two-letter country code. The MailTwin Worker stores the country code, but writes neither the IP nor User-Agent to D1. MailTwin and Smilodon AS do not persist the source IP.

Telemetry never includes email content, addresses, subjects, prompts, AI responses, your name, or your email. The accepted event and property schema is fail-closed. The local audit is available in Settings → Privacy → “Show what's been sent”.

Accepted records are stored in Cloudflare D1 for no more than 90 days. A daily scheduled purge deletes older rows using the server-side receipt time. They are used only to understand feature use, reliability, and app/macOS compatibility; they are not sold or rented.

Turning telemetry off clears the unsent local queue and local audit, rotates the current UUID, and stops future sends. It does not instantly erase records already received; you can request deletion using the current UUID, or they expire automatically within 90 days.

Crash reports

MailTwin writes crash dumps locally to ~/Library/Logs/MailTwin/. This release has no crash-upload mechanism: MailTwin does not send those files anywhere. A diagnostics report lists crash filenames and sizes only, never crash contents. You can inspect or delete the local files at any time.

Payments and licensing (LemonSqueezy)

Purchases are handled by LemonSqueezy as the merchant of record. When you buy a license, LemonSqueezy collects the data needed for payment processing and tax compliance (your name, email, country, and payment details). Their privacy policy applies.

License activation calls https://api.lemonsqueezy.com/v1/licenses/* from your Mac with your license key and a hashed machine fingerprint (derived from IOPlatformUUID plus the bundle id). The fingerprint is used to enforce the seat limit.

What we never collect

Your rights (GDPR, CCPA)

You can export your local settings (Settings → Privacy → Export settings) and delete local MailTwin data (Settings → Privacy → Wipe everything). For purchase or license data held by Smilodon AS or LemonSqueezy, email [email protected]. We will respond within the period required by applicable law.

Telemetry is pseudonymous and is not linked to your name or purchase email, so an email address alone cannot locate those rows. To request deletion before the automatic 90-day expiry, include your current installation UUID. You can retrieve it on your Mac with defaults read ai.mailtwin.app telemetryInstallId; support can help you do this.

Turning telemetry off rotates that UUID. Rows received under an older, rotated UUID cannot then be linked back to you or recovered from your email address; the 90-day automatic deletion is the backstop.

Children

MailTwin is not directed at children under 13. We don't knowingly process data from anyone under 13.

Changes to this policy

Material changes will be posted here and noted in the app's release notes. The "Last updated" date at the top reflects the most recent change.

Contact

Smilodon AS
Norway
[email protected] for privacy questions, [email protected] for product questions.