Privacy Policy

Orvia Mail does not sell mailbox data, build advertising profiles, or use your mail to train an Orvia model. This policy separates Classic from the App Store edition and explains what stays on your Mac, what may leave, and how to turn it off. Last updated 2026-09-18.

Your inbox is not Orvia's dataset

Orvia does not sync your mailbox into a server-side archive for analytics, advertising, data brokerage, or training an Orvia model. Mail stays on your Mac by default and communicates directly with the provider you choose. Only a feature you deliberately use—such as purchasing, license activation, account recovery, or optional cloud processing—handles the minimum data needed to perform that feature. Limited processing and redacted-result caching for optional cloud AI are described below.

Classic is a separate lifetime edition with optional Personal AI

Orvia Mail Classic is the independently distributed, one-time-purchase edition. It does not include Orvia-managed cloud AI or an Orvia subscription. Message bodies, attachments, indexes, and local-rule results stay on the Mac; mail connects directly to your provider. When you enable Personal AI and grant consent for a mailbox, only the task-limited text needed for summaries, replies, or writing passes the on-device privacy gateway and goes directly to the compatible provider you choose. Your provider key stays in macOS Keychain, and requests do not pass through Orvia AI Proxy. Classic uses limited network services for checkout, license activation, and software updates.

Classic BYOK keys stay in macOS Keychain

Classic Personal AI uses a provider key that you supply. Orvia does not put that key in files, logs, databases, CloudKit, KVS, or Orvia Account records, and does not receive or manage it. Before any task-limited text leaves the Mac, the on-device privacy gateway checks the mailbox consent and request; if the request is allowed, it goes directly to your selected provider.

Classic Personal AI connections and provider data controls

Classic Personal AI can use either your own OpenAI-compatible API key or endpoint, or signing in with your own ChatGPT or Grok account. Account connections run a bundled official provider runtime on your device; the runtime stores its own account credentials inside the Classic app container, and Orvia does not read, copy, synchronize, log, or export them. Consumer ChatGPT and Grok account data controls may allow the provider to train on or retain content; until an official API can report that state authoritatively, Orvia treats it as unknown and does not claim training is disabled. Disconnecting an account connection removes its local runtime data.

Gmail boundary for account connections

ChatGPT and Grok account connections are not available for Gmail mailboxes. Gmail cloud AI starts off and runs only after you explicitly enable it for that Gmail mailbox, and Gmail content is never transferred through a consumer account connection. Gmail personal AI uses an API or Custom OpenAI-compatible endpoint under that provider's terms.

Why the App Store says “Data Linked to You”

The label belongs to the App Store edition and combines every optional data path; it does not describe the separately distributed Classic edition. Purchase history supports Apple / RevenueCat entitlement checks. Email address and user ID support optional account and entitlement recovery. “Emails or Text Messages” is Apple's combined category—Orvia does not access SMS—and refers to redacted email text only after a user enables eligible cloud AI. Product-interaction records support AI quotas and reliability, not advertising.

Installation-level anonymous and account-associated pseudonymous data are distinct

When usage statistics are enabled, Orvia sends only a random installation identifier, platform and distribution channel, version and build, coarse plan or entitlement, and connection counts grouped by mail-provider kind. It does not send mailbox addresses or domains, provider account identifiers, message or contact data, attachments, OAuth credentials, transaction or license identifiers, device serial numbers, or raw errors. The installation identifier does not identify a person on its own. After authentication through Orvia Account, an App Store subscription, or a Classic entitlement, the server associates the snapshot with an opaque account or entitlement identity, so that data is pseudonymous rather than strictly anonymous. Turning statistics off immediately stops new snapshots and requests deletion; temporary failures retain a deletion task for retry, and snapshots are retained for no more than 90 days.

Crash and reliability records contain no mailbox content

Release builds may send privacy-minimized operational and crash diagnostics associated with a random installation identifier. These records may include platform and distribution channel, app version and build, operation stage and outcome, coarse duration and item-count buckets, an allowlisted error category, and scrubbed exception frames needed for symbolication. Before transmission, Orvia removes exception messages, full paths, URLs, credentials, mailbox addresses or domains, provider account identifiers, message or contact data, attachments, transaction or license identifiers, device serial numbers, and fields outside the diagnostic allowlist. Diagnostics are used only to detect, investigate, and verify reliability problems—not for advertising or cross-app tracking. Remote diagnostics can be disabled without disabling local reliability records or core mail features.

Each service receives only what its function requires

Your mail provider handles mail sync and sending. Apple and RevenueCat handle App Store purchases and entitlements. Waffo Pancake handles Classic checkout. A transactional email provider delivers codes or notices you request. Only when you enable eligible cloud AI or Classic Personal AI does the selected model provider receive task-limited text that has passed Orvia's privacy gateway. Orvia includes no advertising network, data broker, or cross-app tracking SDK. Each third party processes the data needed to provide its service under its own terms.

What the website collects

When you register for launch notifications, we collect only the email address you submit. It is used for launch notices and important product updates. You can email hello@orviamail.com to request deletion.

What Gmail data Orvia Mail accesses

After you connect Gmail, Orvia Mail may access your account email address, mailbox labels or folders, message headers, snippets, message bodies, attachments you choose to open, read/unread state, starred state, and message metadata needed to provide email client features. Gmail is currently in limited testing for users with a verified paid monthly or annual Plus entitlement or an active Classic license; free accounts and free trials cannot start a new Gmail connection. The ordinary mailbox allowance and Google or account requirements still apply.

How Gmail data is used

Orvia Mail uses raw and derived Gmail data, including local search indexes and triage state, only for user-facing mail client features: showing your inbox, rendering and sending messages, syncing read/unread and starred state, local search, and mail organization. Orvia Mail does not create, transfer, or sell aggregated or anonymized Gmail datasets.

Where Gmail data goes

Orvia Mail communicates directly with the Google Gmail API over HTTPS/TLS. Gmail OAuth tokens are never sent to Orvia servers or AI providers, and sending and receiving mail is not proxied through Orvia Mail-owned relay servers. Gmail message content stays on your Mac unless you separately enable cloud AI globally and for that Gmail mailbox. When both permissions are on, the optional cloud AI flow described below sends only the task-limited, redacted text needed for the feature you invoke through Orvia AI Proxy; the redacted result is then cached for idempotent retries as described below.

Remote images are blocked by default

Remote images and other sender-hosted resources are blocked by default. If the user explicitly loads them, the remote host may receive the resource URL, request time, and network or device information such as the user's IP address and user agent. Orvia does not control that host's retention practices.

Local storage and credential security

Message bodies, attachments, account settings, drafts, outbox queue, search indexes, and triage preferences are stored in app-specific local storage available to the current macOS user. OAuth tokens and Classic provider keys are stored in macOS Keychain. Orvia does not place OAuth tokens, provider keys, or full Gmail message content in operational logs, analytics, or proxy records.

PDF preview and export stay on your Mac

Scenario-based PDF preview and export renders a selected mail or conversation locally using the reading mode you choose, such as Safe Reader or the original message. Orvia does not upload the mail content or generated PDF. If you save or share it, the destination you choose in macOS controls where the file is stored and who can access it.

How long Gmail data is retained

Gmail content and derived local indexes are retained on the Mac until the user removes the Gmail account from Orvia Mail or deletes the app data. OAuth credentials are retained until the account is removed or the user revokes access in Google. Orvia servers do not retain full Gmail message bodies. The redacted AI task-result cache and reusable layout templates that prevent duplicate charges and keep client retries idempotent have no fixed deletion date; a verified deletion request removes them, together with the subscription's usage records, within 30 days. Verified server-side deletion requests are completed within 30 days after identity verification, except for limited records that must be retained for legal or security obligations.

No model training

Orvia Mail does not sell Gmail data or use it for advertising, credit, or lending decisions. Raw or derived Gmail data is not used or transferred to develop, improve, or train general-purpose AI/ML models. Gmail cloud AI is off by default and runs only after you enable it globally and for that Gmail mailbox; when enabled, task-limited redacted text is processed under the terms of the model provider configured for your AI Data Region.

Cloud features are off by default

Orvia-managed cloud AI is off by default. For every mailbox, including Gmail after you explicitly enable it for that mailbox, Orvia sends the minimum text needed for a requested task only after the user enables both the global and mailbox-level cloud permissions and the privacy gateway approves the request. Classic Personal AI is a separate direct-to-provider path described above.

Where cloud AI is processed

Cloud AI requests are routed by the AI Data Region you confirm in Orvia Mail: China Mainland, European Union, International, or United States, applied to every mailbox including Gmail. The provider configured for that region is currently Alibaba Cloud Model Studio (Qwen), and requests never fall back across regions. The region setting is not changed by travel or a VPN; you can move it in Settings, which briefly pauses new AI requests while the binding changes.

Every cloud request is screened and redacted first

Before eligible text can leave the Mac, it must pass Orvia's privacy gateway. High-risk mail and content that cannot be processed safely are blocked. Allowed requests are stripped of unrelated material, and recoverable sensitive fields are replaced with random placeholders. The placeholder map stays in the current Mac session; the model provider sees only task-limited redacted text. If the response fails placeholder-integrity or safety checks, Orvia rejects it.

See how privacy redaction worksA complete walkthrough with an interactive example.

Quota and entitlement records contain no full message body

To verify subscriptions, enforce quotas, prevent duplicate charges, and keep the service reliable, Orvia may retain a purchase transaction identifier, requested feature, credit cost, status, latency, limited account or license-activation records, and a redacted model-result cache for idempotent retries. These records do not contain mailbox passwords, OAuth tokens, or the full original message body, and they are not used to build advertising profiles. The cache has no fixed deletion date and is removed on a verified deletion request as described under retention.

Google Limited Use compliance

The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

When a person may access data

Orvia personnel do not read Gmail content unless the user gives explicit, documented permission for support involving specific content, or access is necessary to investigate security abuse or comply with law.

How to turn off and delete data

You can turn off cloud AI, disable Classic Personal AI, or remove its provider key or account connection in Orvia Mail Settings; delete local account data in Settings -> Accounts. Deleting a Gmail account in Orvia attempts to revoke its refresh token at Google; if the device is offline or revocation fails, you can remove Orvia access at https://myaccount.google.com/permissions. Turning statistics off stops new snapshots and requests deletion. Full deletion steps are available at data-deletion.

Privacy requests

To query or delete your launch notification email, request deletion of server-side subscription, quota, support, or AI proxy records, or ask a privacy question, contact hello@orviamail.com. When a request concerns an App Store subscription, include the Apple subscription transaction identifier so the records can be located.

Website usage statistics

This website uses Umami Cloud to count page views and download-button clicks. We send the canonical page path, page language, referrer origin, approximate traffic source and selected edition/platform, without URL query strings, email content, addresses or account identifiers. A short-lived record in session storage preserves the landing page within the tab; no tracking cookie is set. The service receives normal connection information to process requests. We respect Do Not Track and Global Privacy Control. Download clicks are a proxy metric, not installations or purchases. See Umami’s privacy policy.