Legal
Korvo Mail Privacy Policy
Last updated: August 23, 2026
Korvo Mail is an email client operated by Snab Limited, a company registered in England and Wales (Company No. 16006744), with its registered office at 27 Old Gloucester Street, London WC1N 3AX ("we", "us", "our"). Snab Limited is the data controller for the limited account data described in section 4.
Korvo Mail has no mail server. Your email is synchronised directly between your device and Google, and it is stored on your device. It is not uploaded to Korvo. There is no copy of it for us to read, share, sell, lose in a breach, or train a model on.
This policy covers Korvo Mail specifically. The separate Korvo workspace application is covered by the policy at korvo.xyz/privacy.
1. Google Account Access, and the One Permission We Request
Korvo Mail requests exactly one Google permission: https://www.googleapis.com/auth/gmail.modify. It is presented to you on Google's consent screen as "Read, compose, and send emails from your Gmail account."
This single scope is the minimum that covers what the application does: reading mail, triaging it (archive, star, mark read, trash, spam) and sending replies. Narrower combinations do not work, because Gmail's modify endpoint accepts only this scope or full access.
Korvo Mail never requests https://mail.google.com/, the full-access scope. The consequence is structural rather than a policy we could quietly change: permanent deletion is unreachable. The trash action moves a conversation to Gmail's Trash, where Google retains it for 30 days and you can restore it. Changing this would require a new permission prompt that you would have to accept.
The gmail.modify grant also allows the application to read your Google account's own email address through Gmail's profile endpoint. This is used for the account list and for the reply-from address, and for nothing else. It is why no separate profile or identity scope is requested.
2. What Google Data Is Accessed, and Where It Goes
Under this grant, the application synchronises:
- Message headers — sender, recipients, subject, date
- Message bodies, in plain text and HTML
- Thread structure
- Labels and read or starred state
- Attachment metadata
- Your account's email address
Attachments themselves are referenced, not stored — the file is fetched from Google only when you open it.
This data is requested by the application on your device, directly from Google's servers, using tokens held on your device. It is written to a database in the application's private storage area and indexed there for search. It is not transmitted to Korvo. No Korvo server sits in the path between your device and Gmail.
3. Everything That Leaves Your Device
This list is exhaustive rather than illustrative. Four things ever leave your device:
- oauth2.googleapis.com — token exchange and refresh.
- gmail.googleapis.com — synchronisation and mutations, sent directly from your device.
- Korvo's Supabase project — authentication only. No mail data, ever.
- Remote images referenced in an email — only after you explicitly choose to load them, and only to the sender's own host. Remote images are blocked by default precisely because loading one tells the sender you opened the message.
Korvo Mail contains no analytics, no crash reporting, no telemetry, no advertising SDK and no LLM or AI service calls. We do not know how many messages you have, which accounts you connected, or whether you opened the application today.
4. The Account Data We Do Hold
Korvo Mail uses Supabase Auth for product identity — signing in to the application itself, which is separate from and never crosses into mailbox access. Where a Korvo account exists, we hold:
- An account identifier
- The email address used to sign in
- The authentication provider
- Account creation and last sign-in timestamps
That is all. Guest accounts hold no email address at all.
The separation between the two is the substantive protection, so it is worth stating plainly: the sign-in system never requests any Gmail permission, and the sign-in token is never used to call Gmail. They are different credentials, obtained through different flows, held in different places and used against different endpoints.
Our legal basis is performance of a contract — providing the application — for account data, and your consent, given at the Google permission screen and revocable at any time, for mailbox access.
5. Where Your Data Lives, and How It Is Protected
Mail is stored in the application's private storage in a local database: the application support directory on macOS, the application container on iOS, and app-private storage on Android.
Google account tokens are stored separately, in the operating system's Keychain on macOS and iOS or Keystore on Android, keyed per connected account. Tokens are never written to the database and never written to logs.
The message database is not separately encrypted by the application. It relies on the operating system's own protection — FileVault on macOS, Data Protection on iOS, and app-private storage on Android — and it is excluded from cloud backup.
This is a deliberate decision and we would rather explain it than let you infer a protection that is not there. An additional encryption layer would not defend against the realistic threats here: malware running as your user can read the key as easily as the data, and a stolen locked device is already covered by the operating system. It would, however, cost a measurable amount of search latency against a demanding budget. We will revisit this if the application ever synchronises to a server, which is not planned.
If your device is lost while unlocked and unencrypted, someone holding it can read the mail already synchronised to it, as with any mail client. Use full-disk encryption and a device passcode.
6. Message Content and Remote Content
Message HTML is sanitised locally, inside the application, before it is displayed, and is rendered in an isolated view that cannot reach the rest of the application. Scripts are stripped. Remote images are blocked until you ask for them.
7. What We Never Do With Google User Data
- We do not use it for advertising, and we do not sell it.
- We do not transfer it to data brokers or information resellers.
- We do not use it to train, improve or evaluate any machine-learning or artificial-intelligence model.
- No human at Korvo reads your mail — not for support, not for debugging, not for product research.
The reason is structural rather than a matter of restraint: your mail never reaches our systems, so there is nothing for anyone here to read.
8. Limited Use
Korvo Mail’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. Third Parties
These are the only third parties with any role in Korvo Mail:
- Google LLC — provides Gmail. Your mail is in your Google account and remains subject to Google's own terms and privacy policy. Korvo Mail is a client that reads and modifies it with your permission.
- Supabase — authentication only, acting as processor. No mail data. See Supabase's privacy policy.
- Vercel — hosts this website only. The application does not talk to it. See Vercel's privacy policy.
Korvo Mail uses no other third-party service.
10. International Transfers
Snab Limited is established in the United Kingdom. Authentication data is processed in the European Union. Where personal data is transferred outside the UK or EEA, those transfers rely on adequacy decisions or standard contractual clauses.
Your mail does not enter this picture at all. It moves between your device and Google, and its handling is governed by Google's own arrangements with you or with your Workspace administrator.
11. Retention and Deletion
- Disconnect an account in the application — its messages, threads, labels, attachment references, queued actions and search-index entries are deleted from the device in a single transaction, its Keychain or Keystore item is deleted, and the database is compacted so the space is actually reclaimed rather than merely marked free.
- Uninstall the application — everything stored locally goes with it. Nothing is left on any server, because nothing was ever put there.
- Revoke access at Google — you can withdraw the permission at any time at myaccount.google.com/permissions, without involving us. Synchronisation stops at once. Data already on your device stays there until you disconnect the account or uninstall.
The account records described in section 4 are kept while your account exists, and are deleted within 30 days of a deletion request.
12. Your Rights
Under UK GDPR and GDPR you have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent.
Honestly stated, these rights bite on the limited account data in section 4. For mail content we hold nothing to give you, correct or erase — your rights there run against Google, as the holder of that data, and against your own device.
To exercise any of these, contact support@korvo.xyz. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or to your local supervisory authority.
13. Workspace Accounts
If you connect a Google Workspace account, your organisation's administrator controls whether Korvo Mail may access it at all. gmail.modify is on Google's high-risk scopes list, so an administrator can allow, block or trust the application from the Admin console. Your organisation's own policies apply to your mail regardless of which client you use.
14. Self-Hosted OAuth Clients
If you or your organisation configure Korvo Mail with your own Google Cloud OAuth client, the authorisation relationship is between you and Google directly, using your own client credentials. That does not change how the application stores or transmits data, all of which is described above.
15. Children
Korvo Mail is not directed at children under the age of 16, and we do not knowingly collect their personal data.
16. Changes to This Policy
We may update this policy. When we do, we will update the "last updated" date above, and for material changes affecting Google user data we will notify users in the application before the change takes effect.
17. Contact
For privacy questions or data deletion requests: support@korvo.xyz
Snab Limited · Company No. 16006744
27 Old Gloucester Street, London WC1N 3AX, United Kingdom