Privacy Policy
This policy explains what data the MailArc application handles, with particular attention to data obtained from Google APIs.
Last updated: 31 August 2026
In short
MailArc runs on your own computer and stores your mail in an archive folder on that computer. There is no MailArc server and no user account. Your messages travel from your mail provider directly to your device and are never transmitted to, stored on, or processed by any infrastructure operated by the developer. Nothing is sold, shared, used for advertising, or used to train machine-learning models.
Who is responsible
MailArc is developed and published by Jens Rehpöhler, Gütersloh, Germany. Full provider details are given in the Impressum.
Because MailArc processes your mail locally on your own device, you remain in control of that content throughout. The developer neither receives nor has any means of accessing it.
Google user data MailArc accesses
When you connect a Google account, MailArc requests the following OAuth scopes and no others:
- https://www.googleapis.com/auth/gmail.readonly — read-only access to the messages, attachments and labels of your Gmail mailbox. This is the only scope MailArc requests. It is a restricted scope, and it is required because an archive must read a message in full to store it as it actually arrived: the narrower gmail.metadata returns headers and labels but no message bodies, while gmail.labels would grant a write permission the importer does not use. The scope confers no ability to send, alter or delete your mail, and MailArc performs no such operations.
- The address of the connected mailbox is read from Gmail's own profile endpoint, which gmail.readonly already covers. MailArc therefore requests no separate sign-in, profile or userinfo scope.
How that data is used
Data obtained through this scope is used for one purpose only: building and updating the local mail archive you asked for. Concretely, MailArc downloads your messages and attachments, stores the original bytes on your disk, records the structure the messages already carry — senders, recipients, threads, labels, attachments — in a local database, and makes the result searchable offline on your own machine.
Your Google user data is never used for advertising, profiling, market research, resale, or the training or improvement of machine-learning or AI models. It is not transferred to any third party. No human being — including the developer — reads it.
Limited Use disclosure
MailArc's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Where data is stored
The archive is stored on your own device. In the packaged macOS application it lives under ~/Library/Application Support/de.rehpoehler.mailarc/, which holds the original message bytes, the graph data and a single SQLite file for mailboxes, credentials and jobs. OAuth tokens issued by Google are stored locally in that same location so a later import does not have to ask you to sign in again.
Securing the device itself — disk encryption, screen lock, backups of the archive folder — is your responsibility, in the same way as for any other local file.
Retention and deletion
The developer retains no Google user data at all, so there is nothing on the developer's side to delete. Your archive persists for as long as you keep the folder; deleting that folder permanently removes every copy MailArc created. Disconnecting the account additionally discards the stored OAuth tokens.
Withdrawing access
You can revoke MailArc's access to your Google account at any time at Google Account · Third-party access. Access ends immediately; any archive already written to your disk remains yours and is unaffected.
This website
These pages are static and hosted on Amazon Web Services in the EU (Ireland). No cookies are set, and no analytics or tracking services are used. As with any web server, requests may be recorded in technical access logs containing the IP address, timestamp and requested resource, processed on the basis of Art. 6(1)(f) GDPR for security and operation. Web fonts are loaded from Google Fonts, which involves a request to a Google server.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and objection, and the right to lodge a complaint with a supervisory authority. Since the developer holds none of your mail data, such requests can only meaningfully concern the contact correspondence described below.
Children
MailArc is not directed at children and is not intended for use by anyone under 16 years of age.
Changes to this policy
This policy may be updated as the application changes. The date at the top always reflects the current version, and material changes will be announced on this page.
Contact
Jens Rehpöhler
E-Mail: