Effective date: June 22, 2026 ·
App version: 1.0 and later ·
Developer: hackitz
The short version
- JustMail does not collect, store, or transmit any of your data to us or any third party.
- Your email credentials are stored only on your device.
- All email processing happens entirely on your device.
- The app connects only to servers you choose — your mail server, plus any optional services you turn on (sign-in, cloud storage, translation).
- No analytics, no advertising, no tracking of any kind.
1. Information we collect
We collect nothing. JustMail does not collect, transmit, or store any personal
information on our servers. There are no servers operated by hackitz that receive any data from the app.
The following information is processed and stored locally on your device only:
- Email account credentials — your email address, username, and password (or, for
accounts you sign in to with OAuth, an access token) are stored in your device's local app storage to
allow the app to connect to your mail server. They are never sent anywhere except directly to the mail
server or sign-in provider you specify.
- Email content — messages fetched from your mail server are cached locally on your
device to provide offline access. This content never leaves your device except when synced back to your
mail server.
- App settings and preferences — configuration choices (theme, notification settings,
etc.) are stored locally in your device's app storage.
- Contacts — if you import or auto-save contacts, they are stored locally in the
app's private storage and are never uploaded anywhere.
2. How your data is used
All data processed by JustMail is used solely to provide the core functionality of the app —
sending and receiving email on your behalf using the account details you provide. Specifically:
- Your credentials are used to authenticate with your mail server (IMAP/SMTP).
- Email content is fetched from and sent to your mail server based on your actions.
- No data is used for advertising, profiling, analytics, or any purpose other than email functionality.
3. Network connections and third-party services
JustMail does not integrate with any analytics platforms, advertising networks, or data brokers. It makes
network connections only to servers you choose, and only to provide features you use. These are:
- Your IMAP server — to fetch, sync, and manage your email messages.
- Your SMTP server — to send email on your behalf.
- Sign-in providers (OAuth) — if you add an Outlook or Microsoft 365 account, the app
signs in via Microsoft's OAuth service to obtain an access token for your mailbox. The token is stored
only on your device.
- Cloud storage you connect (optional) — if you enable cloud storage for large
attachments, the app uploads attachments you send (and saves attachments you choose) to a provider you
connect: Nextcloud, Google Drive, or Microsoft OneDrive. Files go only to your own account on
that service, using credentials or tokens stored on your device. hackitz never receives these files.
- Google (on-device translation, optional) — if you use the message-translation
feature, the app downloads offline language packs from Google's ML Kit service. Translation runs entirely
on your device; your message text is not sent to Google or anyone else.
- Unsubscribe links (optional) — only when you tap "Unsubscribe" on a mailing-list
message, the app contacts the unsubscribe address provided by that sender in the message headers.
- OpenKeychain (optional) — if you enable OpenPGP, JustMail communicates with the
separate OpenKeychain app installed on your device to decrypt or verify messages. Your private keys remain
in OpenKeychain and are never accessed by or transmitted through hackitz.
All of these connections are configured and initiated by you. hackitz has no visibility into, access to, or
control over them or the data exchanged.
Google API Services — Limited Use
JustMail's use and transfer of information received from Google APIs adheres to the
Google
API Services User Data Policy, including the Limited Use requirements.
The Google Drive integration uses only the drive.file scope, which grants access solely to
files that JustMail itself creates. This access is used exclusively to upload large email attachments you
send and to save attachments you choose to your Drive. JustMail does not transfer this data to others
except as needed to provide that feature, does not use it for advertising, and does not sell it. No
human reads this data, and it is not used to train generalized AI/ML models.
4. Data sharing and disclosure
We do not share your data with any third party, because we never receive your data in the first place.
There is no central server, no cloud storage operated by us, and no telemetry.
The only parties who can access your email data are:
- You, on your own device.
- Your email provider, through the standard IMAP/SMTP protocols you configured.
- Any optional service you explicitly connect (sign-in provider or cloud storage), acting on your own account.
5. Data storage and security
All app data (credentials, cached messages, settings) is stored in your device's private app storage,
which is only accessible to JustMail and protected by Android's application sandbox. Other apps on
your device cannot access this data. OAuth and cloud-storage tokens are kept in encrypted storage backed
by the Android Keystore.
Network connections to your mail server use the settings you configure in the app. We strongly recommend
enabling SSL/TLS on both your incoming (IMAP) and outgoing (SMTP) connections, which is the default
setting in JustMail.
We do not operate any servers and therefore cannot experience a server-side data breach affecting
your information.
6. Backups
JustMail's optional backup feature exports your app settings and account configuration (without passwords)
to a file stored in a location you choose on your device or a cloud storage provider you have connected
(such as Google Drive or OneDrive). This export is entirely under your control. hackitz does not have
access to these backup files.
Android system backups (if enabled in your device settings) may include app settings data as managed by
Android's own backup system, which is subject to Google's privacy policy.
7. Permissions
JustMail requests the following Android permissions:
- INTERNET — required to connect to your mail server.
- ACCESS_NETWORK_STATE — used to detect whether Wi-Fi or mobile data is active,
to apply your sync preferences.
- POST_NOTIFICATIONS — used to display new-mail notifications.
- RECEIVE_BOOT_COMPLETED — used to restart background mail monitoring after a
device reboot, if you have enabled that feature.
- USE_BIOMETRIC — used for the optional app lock feature (biometric or device
credential authentication).
- READ_CONTACTS — used only if you choose to import contacts from your device's
contacts app. This is optional and only accessed when you explicitly request it.
- FOREGROUND_SERVICE / FOREGROUND_SERVICE_DATA_SYNC — used by the optional
persistent background service that checks for new mail.
None of the data accessed through these permissions is transmitted to hackitz or any third party.
8. Children's privacy
JustMail is not directed at children under 13 years of age and we do not knowingly collect personal
information from children. The app functions solely as an email client for general-audience use.
9. Changes to this policy
If we update this privacy policy, the new version will be published at this URL and the "Effective date"
at the top of this page will be updated. Significant changes will also be noted in the app's release notes.
Because JustMail does not collect personal data, any updates to this policy are unlikely to affect how
your information is handled.
10. Contact
If you have any questions about this privacy policy or about JustMail's data practices, please open an
issue on the app's GitHub page
or contact us at the address listed in the Google Play Store listing.