Privacy Policy
Orvia Mail does not sell mailbox data, build advertising profiles, or use your mail to train an Orvia model. This policy separates Classic from the App Store edition and explains what stays on your Mac, what may leave, and how to turn it off. Last updated 2026-08-01.
Your inbox is not Orvia's dataset
Orvia does not sync your mailbox into a server-side archive for analytics, advertising, data brokerage, or training an Orvia model. Mail stays on your Mac by default and communicates directly with the provider you choose. Only a feature you deliberately use—such as purchasing, license activation, account recovery, or optional cloud processing—handles the minimum data needed to perform that feature. Limited processing and redacted-result caching for optional cloud AI are described below.
Classic is a separate lifetime edition with no cloud AI
Orvia Mail Classic is the independently distributed, one-time-purchase edition. It does not include cloud AI. Message bodies, attachments, indexes, and local-rule results stay on the Mac; mail connects directly to your provider and is not relayed through Orvia or sent to Orvia AI Proxy or an AI model provider. Classic uses limited network services only for purchasing, license activation, and software updates: Waffo Pancake handles checkout, activation sends the license key and a random installation ID, and Sparkle checks for updates.
Why the App Store says “Data Linked to You”
The label belongs to the App Store edition and combines every optional data path; it does not describe the separately distributed Classic edition. Purchase history supports Apple / RevenueCat entitlement checks. Email address and user ID support optional account and entitlement recovery. “Emails or Text Messages” is Apple's combined category—Orvia does not access SMS—and refers to redacted email text only after a user enables eligible non-Gmail cloud AI. Product-interaction records support AI quotas and reliability, not advertising.
Installation-level anonymous and account-associated pseudonymous data are distinct
When usage statistics are enabled, Orvia sends only a random installation identifier, platform and distribution channel, version and build, coarse plan or entitlement, and connection counts grouped by mail-provider kind. It does not send mailbox addresses or domains, provider account identifiers, message or contact data, attachments, OAuth credentials, transaction or license identifiers, device serial numbers, or raw errors. The installation identifier does not identify a person on its own. After authentication through Orvia Account, an App Store subscription, or a Classic entitlement, the server associates the snapshot with an opaque account or entitlement identity, so that data is pseudonymous rather than strictly anonymous. Turning statistics off immediately stops new snapshots and requests deletion; temporary failures retain a deletion task for retry, and snapshots are retained for no more than 90 days.
Crash and reliability records contain no mailbox content
Release builds may send privacy-minimized operational and crash diagnostics associated with a random installation identifier. These records may include platform and distribution channel, app version and build, operation stage and outcome, coarse duration and item-count buckets, an allowlisted error category, and scrubbed exception frames needed for symbolication. Before transmission, Orvia removes exception messages, full paths, URLs, credentials, mailbox addresses or domains, provider account identifiers, message or contact data, attachments, transaction or license identifiers, device serial numbers, and fields outside the diagnostic allowlist. Diagnostics are used only to detect, investigate, and verify reliability problems—not for advertising or cross-app tracking. Remote diagnostics can be disabled without disabling local reliability records or core mail features.
Each service receives only what its function requires
Your mail provider handles mail sync and sending. Apple and RevenueCat handle App Store purchases and entitlements. Waffo Pancake handles Classic checkout. A transactional email provider delivers codes or notices you request. Only when you enable eligible cloud AI does the configured model provider receive task-limited text that has passed Orvia's privacy gateway. Orvia includes no advertising network, data broker, or cross-app tracking SDK. Each third party processes the data needed to provide its service under its own terms.
What the website collects
When you register for launch notifications, we collect only the email address you submit. It is used for launch notices and important product updates. You can email orvia@aedc.cc to request deletion.
What Gmail data Orvia Mail accesses
After you connect Gmail, Orvia Mail may access your account email address, mailbox labels or folders, message headers, snippets, message bodies, attachments you choose to open, read/unread state, starred state, and message metadata needed to provide email client features. Gmail is currently limited to eligible invited testers.
How Gmail data is used
Orvia Mail uses raw and derived Gmail data, including local search indexes and triage state, only for user-facing mail client features: showing your inbox, rendering and sending messages, syncing read/unread and starred state, local search, and mail organization. Orvia Mail does not create, transfer, or sell aggregated or anonymized Gmail datasets.
Where Gmail data goes
Orvia Mail communicates directly with the Google Gmail API over HTTPS/TLS. Except for user-triggered sender-hosted resources described below, during limited testing Orvia Mail does not transmit Gmail message content, derived data, or OAuth tokens to Orvia servers, AI providers, advertising platforms, data brokers, or other third parties. Sending and receiving mail is not proxied through Orvia Mail-owned relay servers.
Remote images are blocked by default
Remote images and other sender-hosted resources are blocked by default. If the user explicitly loads them, the remote host may receive the resource URL, request time, and network or device information such as the user's IP address and user agent. Orvia does not control that host's retention practices.
Local storage and credential security
Message bodies, attachments, account settings, drafts, outbox queue, search indexes, and triage preferences are stored in app-specific local storage available to the current macOS user. OAuth tokens are stored in macOS Keychain. Orvia does not place OAuth tokens or full Gmail message content in operational logs, analytics, or proxy records.
How long Gmail data is retained
Gmail content and derived local indexes are retained on the Mac until the user removes the Gmail account from Orvia Mail or deletes the app data. OAuth credentials are retained until the account is removed or the user revokes access in Google. During limited testing, Orvia servers do not retain Gmail message content. Verified server-side deletion requests are completed within 30 days after identity verification, except for limited records that must be retained for legal or security obligations.
No model training
Orvia Mail does not sell Gmail data or use it for advertising, credit, or lending decisions. Raw or derived Gmail data is not used or transferred to develop, improve, or train general-purpose AI/ML models. During limited testing, cloud AI is disabled for Gmail mailboxes and Gmail data is not transferred to third-party AI/ML services.
Cloud features are off by default
Cloud AI is off by default. For supported non-Gmail mailboxes, Orvia sends the minimum text needed for a requested task only after the user enables both the global and mailbox-level cloud permissions and the privacy gateway approves the request. This optional path includes no Gmail data during Gmail limited testing.
Every cloud request is screened and redacted first
Before eligible text can leave the Mac, it must pass Orvia's privacy gateway. High-risk mail and content that cannot be processed safely are blocked. Allowed requests are stripped of unrelated material, and recoverable sensitive fields are replaced with random placeholders. The placeholder map stays in the current Mac session; the model provider sees only task-limited redacted text. If the response fails placeholder-integrity or safety checks, Orvia rejects it.
See how privacy redaction worksA complete walkthrough with an interactive example.
Quota and entitlement records contain no full message body
To verify subscriptions, enforce quotas, prevent duplicate charges, and keep the service reliable, Orvia may retain a purchase transaction identifier, requested feature, credit cost, status, latency, limited account or license-activation records, and a redacted model-result cache for idempotent retries. These records do not contain mailbox passwords, OAuth tokens, or the full original message body, and they are not used to build advertising profiles.
Google Limited Use compliance
The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
When a person may access data
Orvia personnel do not read Gmail content unless the user gives explicit, documented permission for support involving specific content, or access is necessary to investigate security abuse or comply with law.
How to turn off and delete data
You can turn off cloud AI and pseudonymous usage statistics in Orvia Mail Settings, delete local account data in Settings -> Accounts, and revoke Orvia Mail Google access from your Google Account permissions page. Turning statistics off stops new snapshots and requests deletion. Full deletion steps are available at data-deletion.html.
Privacy requests
To query or delete your launch notification email, request deletion of server-side subscription/quota/support records, or ask a privacy question, contact orvia@aedc.cc.
Orvia Mail home · FAQ · Privacy Policy · Changelog