The short version
- JustMail does not collect, store, or transmit any of your data to us or any third party.
- Your email credentials are stored only on your device.
- All email processing happens entirely on your device.
- The app connects only to servers you choose — your mail server, plus any optional services you turn on (sign-in, cloud storage, translation).
- Optional device pairing transfers your setup directly between your own devices over your local network, end-to-end encrypted — it never passes through our servers.
- No analytics, no advertising, no tracking of any kind.
1. Information we collect
We collect nothing. JustMail does not collect, transmit, or store any personal information on our servers. There are no servers operated by HackitzLabs that receive any data from the app.
The following information is processed and stored locally on your device only:
- Email account credentials — your email address, username, and password (or, for accounts you sign in to with OAuth, an access token) are stored in your device’s local app storage to allow the app to connect to your mail server. They are never sent anywhere except directly to the mail server or sign-in provider you specify.
- Email content — messages fetched from your mail server are cached locally on your device to provide offline access. This content never leaves your device except when synced back to your mail server.
- App settings and preferences — configuration choices (theme, notification settings, etc.) are stored locally in your device’s app storage.
- Contacts — if you import or auto-save contacts, they are stored locally in the app’s private storage and are never uploaded anywhere.
2. How your data is used
All data processed by JustMail is used solely to provide the core functionality of the app — sending and receiving email on your behalf using the account details you provide. Specifically:
- Your credentials are used to authenticate with your mail server (IMAP/SMTP).
- Email content is fetched from and sent to your mail server based on your actions.
- No data is used for advertising, profiling, analytics, or any purpose other than email functionality.
3. Network connections and third-party services
JustMail does not integrate with any analytics platforms, advertising networks, or data brokers. It makes network connections only to servers you choose, and only to provide features you use. These are:
- Your IMAP server — to fetch, sync, and manage your email messages.
- Your SMTP server — to send email on your behalf.
- Sign-in providers (OAuth) — if you add an Outlook or Microsoft 365 account, the app signs in via Microsoft’s OAuth service to obtain an access token for your mailbox. The token is stored only on your device.
- Cloud storage you connect (optional) — if you enable cloud storage for large attachments, the app uploads attachments you send (and saves attachments you choose) to a provider you connect: Nextcloud, Google Drive, or Microsoft OneDrive. Files go only to your own account on that service, using credentials or tokens stored on your device. HackitzLabs never receives these files.
- Google (on-device translation, optional) — if you use the message-translation feature, the app downloads offline language packs from Google’s ML Kit service. Translation runs entirely on your device; your message text is not sent to Google or anyone else.
- Unsubscribe links (optional) — only when you tap “Unsubscribe” on a mailing-list message, the app contacts the unsubscribe address provided by that sender in the message headers.
- OpenKeychain (optional) — if you enable OpenPGP, JustMail communicates with the separate OpenKeychain app installed on your device to decrypt or verify messages. Your private keys remain in OpenKeychain and are never accessed by or transmitted through HackitzLabs.
All of these connections are configured and initiated by you. HackitzLabs has no visibility into, access to, or control over them or the data exchanged.
Google API Services — Limited Use
JustMail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The Google Drive integration uses only the drive.file scope, which grants access solely to
files that JustMail itself creates. This access is used exclusively to upload large email attachments you
send and to save attachments you choose to your Drive. JustMail does not transfer this data to others
except as needed to provide that feature, does not use it for advertising, and does not sell it. No
human reads this data, and it is not used to train generalized AI/ML models.
4. Data sharing and disclosure
We do not share your data with any third party, because we never receive your data in the first place. There is no central server, no cloud storage operated by us, and no telemetry.
The only parties who can access your email data are:
- You, on your own device.
- Your email provider, through the standard IMAP/SMTP protocols you configured.
- Any optional service you explicitly connect (sign-in provider or cloud storage), acting on your own account.
5. Data storage and security
All app data (credentials, cached messages, settings) is stored in your device’s private app storage, which is only accessible to JustMail and protected by Android’s application sandbox. Other apps on your device cannot access this data. OAuth and cloud-storage tokens are kept in encrypted storage backed by the Android Keystore.
Network connections to your mail server use the settings you configure in the app. We strongly recommend enabling SSL/TLS on both your incoming (IMAP) and outgoing (SMTP) connections, which is the default setting in JustMail.
We do not operate any servers and therefore cannot experience a server-side data breach affecting your information.
6. Backups
JustMail’s optional backup feature exports your app settings and account configuration (without passwords) to a file stored in a location you choose on your device or a cloud storage provider you have connected (such as Google Drive or OneDrive). This export is entirely under your control. HackitzLabs does not have access to these backup files.
Android system backups (if enabled in your device settings) may include app settings data as managed by Android’s own backup system, which is subject to Google’s privacy policy.
7. Device pairing & sync
JustMail includes an optional feature that lets you set up another device (for example, adding JustMail on a new phone or on your Windows PC) by copying your existing configuration to it. This feature only ever runs when you deliberately start it.
How it works. One device displays a QR code that contains a freshly generated, one-time encryption key. The other device scans that code with its camera. The two devices then connect directly to each other over your local network (Wi-Fi/LAN) to transfer the data. No outside server, relay, or cloud service is involved — the connection never leaves your local network, and HackitzLabs operates no server that participates in it.
What is transferred. Your email account setup (server addresses, ports, usernames), your account passwords, and your app settings (such as signatures, spam and mail-handling rules, quiet senders, templates, theme, and general preferences). Your cached email messages and your contacts are not transferred.
How it is protected. The transfer is end-to-end encrypted using AES-256-GCM. The encryption key exists only on the two devices and travels only from the on-screen QR code into the scanning device’s camera — it is never sent over the network. Each pairing session is single-use and expires after one transfer. Because the data goes straight from one of your devices to another, it is never exposed to us or to any third party.
Your control. Pairing happens only when you initiate it and confirm the import on the receiving device. After pairing, each device keeps its own independent local copy of the data, which you can delete at any time.
8. Permissions
JustMail requests the following Android permissions:
- INTERNET — required to connect to your mail server.
- ACCESS_NETWORK_STATE — used to detect whether Wi-Fi or mobile data is active, to apply your sync preferences.
- CAMERA — used only to scan the pairing QR code when you set up device-to-device sync. JustMail does not take photos, record video, or access your photo library, and no camera data is ever stored or transmitted.
- POST_NOTIFICATIONS — used to display new-mail notifications.
- RECEIVE_BOOT_COMPLETED — used to restart background mail monitoring after a device reboot, if you have enabled that feature.
- USE_BIOMETRIC — used for the optional app lock feature (biometric or device credential authentication).
- READ_CONTACTS — used only if you choose to import contacts from your device’s contacts app. This is optional and only accessed when you explicitly request it.
- FOREGROUND_SERVICE / FOREGROUND_SERVICE_DATA_SYNC — used by the optional persistent background service that checks for new mail.
None of the data accessed through these permissions is transmitted to HackitzLabs or any third party.
9. Children’s privacy
JustMail is not directed at children under 13 years of age and we do not knowingly collect personal information from children. The app functions solely as an email client for general-audience use.
10. Changes to this policy
If we update this privacy policy, the new version will be published at this URL and the “Effective date” at the top of this page will be updated. Significant changes will also be noted in the app’s release notes.
Because JustMail does not collect personal data, any updates to this policy are unlikely to affect how your information is handled.
11. Contact
If you have any questions about this Privacy Policy or how JustMail handles your information, please contact us at hackitzlabs@hackitz.net.