Privacy policy
Effective date: 6 October 2026
This policy covers Gregory Sinclair’s personal Omamail desktop installation and its Google OAuth application, identified as “omamail”, together with this information website at omamail.shinytinyapps.com. It does not describe every installation of the upstream Omamail project or offer a public hosted email service. For questions, contact shinytinyapps@gmail.com.
Google data and permissions
When an account owner connects a Google account, the desktop app uses Google’s authorization flow and APIs. Google handles the account password; this website does not receive it. The desktop app requests Gmail permissions to read and manage mail and send messages, and calendar-event permissions to view and manage events.
Data accessed can include the account’s email address and profile information; message headers, senders, recipients, subjects, bodies, attachments, labels and read status; drafts and outgoing messages; and calendar-event details such as titles, dates, descriptions, locations and attendees. The authorization screen shows the permissions being requested.
How the data is used
Google data is used to provide the account owner’s email and calendar functions: displaying and searching mail, composing and sending messages, managing labels and message state, downloading attachments, showing notifications, displaying calendar events and managing events or invitations when requested. Email address suggestions may be derived from local mail information.
Google user data is not sold, used for advertising, supplied to data brokers, or used by this installation’s operator to train general-purpose AI models. Access is limited to operating these user-facing functions and resolving problems at the account owner’s request.
Storage and security
The desktop app keeps account settings, cached mail and calendar data, draft or outbox state, and optional assistant history on the computer where it runs. Downloaded attachments and files saved by the account owner also remain in the locations they choose. Google refresh tokens are stored in the operating system’s credential store. The app exchanges data with Google over encrypted HTTPS connections.
This website’s Cloudflare hosting does not receive mailbox contents or the desktop app’s Google tokens. It serves these information pages. Local file permissions and the system credential store protect application data, but cached messages should not be assumed to have separate application-level encryption. Device security and any device backups also affect the protection and retention of that data.
Sharing and optional AI features
Sending messages, accepting invitations or changing calendar events communicates the relevant data to Google and, where applicable, the intended recipients or attendees. Loading remote images or opening links can contact the sender’s or another third party’s servers and disclose normal connection information. Remote images may load automatically if the account owner enables that setting.
If the account owner uses AI assistance, relevant selected message or draft content and the request are passed to the AI service configured in the desktop environment, through its installed client. In this Omamail version, the supported background client is Claude. The destination and its processing, retention and account controls depend on that client’s configuration and the service provider’s terms. AI assistance is optional. If automatic calendar suggestions are enabled, relevant message text may also be sent to the configured AI service in the background when a message is opened. Disable that setting to prevent those background requests.
Local tools, device backups or services configured by the account owner may also handle application data. This policy does not promise that third-party providers retain no data. The operator does not share Google data for unrelated purposes.
Retention, disconnection and deletion
Local data is retained for the app’s operation until the app’s cache management removes it or the account owner deletes it. Different records have different retention rules; there is no single fixed deletion deadline for every local record.
The account owner can sign out in Omamail or revoke this app’s access in Google Account connections. Signing out removes the app’s stored credential for that account, but does not necessarily erase cached messages, downloaded attachments, drafts, assistant history or backups. Uninstalling the plugin also does not automatically erase all local data. To remove those copies, delete the relevant local Omamail data and any saved files or backups separately. Disconnecting the app does not delete email or calendar events from Google.
Website visitors
These pages contain no application analytics scripts, advertising, forms, Google sign-in or tracking cookies set by this site’s code. Cloudflare delivers and protects the website and may process connection and request information, such as IP addresses, browser information and requested URLs, under its privacy policy. If you email the contact address, your email and its contents are handled through that mailbox to respond to your enquiry.
Google API Limited Use
This installation’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Changes and contact
This page will be updated when the installation’s relevant data practices change. The effective date above identifies the current policy. Questions about access, local data or this policy can be sent to shinytinyapps@gmail.com.