Mail Menubar

YOUR DATA

Privacy policy

Mail Menubar 1.17.1. Last updated: September 14, 2026.

About the app

Mail Menubar is an independent macOS Gmail client. For support or privacy questions, contact alexic.ralph@gmail.com. The app is not affiliated with Google or Apple. Google's restricted-scope verification is still in progress; the app must not be represented as approved for Advanced Protection accounts.

Google account access and permissions

Connecting an account initially requests only Gmail metadata access. The authenticated Gmail profile identifies the mailbox; the app does not request separate Google identity or profile permissions. Metadata access shows recent inbox message identifiers, labels, sender, subject, timestamps and unread counts. It initially retrieves up to 30 inbox headers per connected account; scrolling loads older messages as needed. All/Unread filtering uses the downloaded list.

Reading message bodies and changing messages require a separate Enable reading permission upgrade. The app requests gmail.modify to display message content, mark individual messages read or unread, and move messages to Gmail Trash. Google's permission also allows composing and sending, but Mail Menubar does not implement those functions. The app does not request the broader full-mail scope, implement immediate permanent deletion, or download attachments. Headers-only connections remain usable without the reading upgrade.

Reading and images

With reading enabled, Mail Menubar prepares message bodies for the downloaded inbox list when it checks mail. This lets recently received messages open faster. Preparing a body does not mark it as read. Original view displays filtered email HTML and styling, or plain source when no HTML is available. Text view displays a simplified, readable representation. The default view can be changed in settings.

Remote image downloading is off for new installations, and images are never prefetched as messages arrive. Users may load images for an opened message or explicitly enable loading by default. Image downloads contact the image host directly, which can learn the device's public IP address, request time and information encoded in the image URL. A tracking image may therefore reveal that its content was requested. Mail Menubar does not provide an image privacy proxy.

Image requests do not include Gmail authorization tokens, cookies or referrer headers. Email scripts, forms, frames, external fonts/stylesheets and automatic navigation are blocked. Clicking permitted links opens the system browser. Turning off image loading stops further downloads; already displayed or locally cached images can remain visible.

Local storage and retention

Connected-account credentials, including refresh tokens and OAuth configuration, are stored in the macOS Keychain. A signed helper handles credential operations locally and exits after each operation. Access tokens and displayed inbox headers are kept in memory.

Downloaded message bodies, their display representations and explicitly downloaded images are stored in an account-separated cache on the Mac. Cache folders and files are restricted to the current macOS user and excluded from backups. SQLCipher encrypts the entire cache database and its journal pages using AES-256. A separate random 256-bit key is stored in macOS Keychain. Cache metadata, bodies and cached images are encrypted together. Temporary database storage stays in memory; when the key is unavailable, new downloads are cached only in memory, never in plaintext files.

Cached downloads expire for reuse 30 days after download. Opening an item does not extend that deadline. Data may be removed sooner to stay within storage limits. Expired files are cleaned up during app activity and at the next launch if the app has been closed; the app cannot erase files while it is not running. A message already visible on screen can remain visible until it is closed. Disconnecting a mailbox clears its cached data and saved credential.

Window dimensions, text size, reader/image preferences and optional mailbox display names are saved locally. The app has no developer-operated cloud email archive or synchronization service for these preferences.

Connections and updates

Gmail authorization and API requests go directly between the Mac and Google over encrypted connections. The app checks each mailbox on startup and wake, then again 60 seconds after the previous check finishes. Manual refresh is also available. These are periodic checks, not push notifications. They run while the app is open and the Mac is awake and online, independently of Apple Mail.

The app does not access Apple Mail's database, automate Apple Mail or require Full Disk Access. Quitting, sleeping or disconnecting stops the relevant mailbox work. Expired authorization requires reconnection.

Sharing and use of Google data

Mail Menubar does not send Gmail credentials, headers or bodies to a developer-operated server. It includes no advertising or analytics SDK and does not sell email data, use it for advertising or use it to train AI models. Optional image loading and explicitly opened links contact their destination sites as described above.

Mail Menubar's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting and deleting data

Disconnect a mailbox in the app to remove its saved credential and local cached downloads and stop its connection. Other connected mailbox connections remain active. If account-specific cache deletion cannot be completed because local cache access is unavailable, the entire disposable cache is cleared. Disconnecting does not itself revoke Google's server-side authorization; authorization can also be removed through Google Account connections.

Mark read/unread changes the selected message's UNREAD label in Gmail. Move to Trash changes the source Gmail mailbox; Gmail's own Trash retention and recovery rules apply. Disconnecting or uninstalling the app does not undo those mailbox actions.

Website and support

The informational website does not connect to Gmail. It has no app-authored analytics, tracking scripts, sign-in forms or database. Hosting providers may process normal connection data and security cookies to deliver and protect the site.

If you contact support, your email and contact information are used to respond. Avoid including passwords, tokens or private message content. Requests concerning support correspondence can be sent to alexic.ralph@gmail.com, subject to any required retention.

Security and availability

The app uses encrypted Google connections, browser-based OAuth with PKCE, macOS Keychain credential storage and local cache access restrictions. The current build uses a local signing certificate; it is not Apple Developer ID signed, notarized or independently security-audited. Local cache encryption is not end-to-end email encryption and cannot protect mail while a compromised Mac is using it. These controls do not guarantee absolute security. Keep Google Advanced Protection enabled where it is already in use.