Privacy Policy
Last updated: October 5, 2026.
Hermod Mail ("Hermod", "we", "us", "our") is the app and service this policy covers. Contact: support@tryhermod.com.
This policy explains how the Hermod Mail app for iPhone and iPad handles your information, including data it receives from Google APIs.
What Hermod Mail is
Hermod Mail is an email client for iPhone and iPad. It fetches mail from the providers you choose, such as Gmail or Outlook, and shows it in the app. We do not run a server that receives, scans, or stores your messages. Your mail travels directly between your device and your mail provider.
Google user data (Gmail)
When you tap Continue with Google, you sign in on Google’s own page in a secure system browser sheet, so the app never sees your Google password. Once you grant access, Google issues tokens to the app on your device, and the app calls the Gmail API directly from your device.
What Google data the app accesses
- Basic profile: your Google account email address, name, and profile photo URL (from Google sign-in), used to label the account in the app.
- Gmail messages and threads: headers (from, to, cc, subject, date, List-Unsubscribe), message bodies, and attachments. These let you read your inbox, sent mail, drafts, archive, spam, starred, and trash, search your mail, and open conversations.
- Gmail labels: your label list and unread counts. These let the app show folders and badges, and let you create or delete custom folders (Gmail labels).
- Sending: messages you write in the app, including new mail, replies, forwards, and unsubscribe emails you request, are sent through the Gmail API from your account.
How the app uses it
The app uses Google user data only to provide the email features you see in it:
- showing your mailbox, reading and searching messages, and opening attachments;
- sending mail;
- marking messages read or unread, archiving, moving to spam, and moving to trash;
- managing labels and folders;
- grouping mail by sender, subject, or domain in the sender panel, and bulk cleanup you start;
- one-tap unsubscribe when you tap it;
- on-screen security-code detection, new-mail notifications, and on-device mail statistics.
Deleting a message in the app moves it to Gmail’s Trash. The app never permanently deletes Gmail messages.
We do not use Gmail data for advertising, sell it, use it to build profiles for anyone else, or use it to train artificial intelligence or machine learning models. The app does not send mail content to any AI or language-model service.
How it is stored
- Tokens: Google OAuth access and refresh tokens are stored in the iOS Keychain on your device. They are never sent to us.
- Mail cache: message headers, the bodies you open, labels, and the attachments you open are cached in the app’s private storage on your device. This keeps the app fast and lets it work offline.
- Other data on your device: sender photos from your iOS contacts, sender logos (only if you turn on Show sender logos), notification state, and mail statistics (counts only, shown in the Hermod Activity widget).
- We keep no copy of your Gmail data on any server, so we cannot read your mail. If you email us for support and include message content, we use it only to answer you.
How it is shared
We do not receive, sell, or transfer your Gmail data. The app makes these network requests directly from your device:
- Google: sign-in, token refresh, profile, and Gmail API requests go to Google.
- Sender logos (optional, off by default): these lookups happen only if you turn on Settings → Show sender logos. The app then requests a logo for the sender’s domain name (for example
example.com) from DuckDuckGo’s icon service (icons.duckduckgo.com), the sender’s own website, or Google’s favicon service (www.google.com/s2/favicons). It also looks up the sender’s address on Gravatar using an MD5 hash of the address. The subject, body, and your credentials are never sent, and results are cached on your device. While the setting is off (the default), no sender domains, addresses, or hashes are sent to these services. Apart from your own mail provider, no information about your senders leaves your device, except in the two cases described next. - Content inside emails: when you open an HTML email, images and other remote content in it load from the sender’s servers, as they do in most mail apps.
- Unsubscribe: when you tap Unsubscribe, the app sends the sender’s one-click unsubscribe request to the sender’s own web address, or sends an “unsubscribe” email from your account.
- Things you choose to share: attachments you open in other apps and data exports you share go wherever you send them.
The app contains no advertising, analytics, or crash-reporting SDKs from other companies, and it does not use a push-notification server. New-mail alerts are created on your device.
Retention and deletion
- Cached Gmail data and tokens stay on your device until you remove the account, use Delete Account & Data, or delete the app. iOS may also clear cached images and attachments on its own.
- Remove one account: in Settings, swipe left on the account and tap Remove. This deletes that account’s tokens and cached mail from your device.
- Delete everything: Settings → Delete Account & Data deletes all linked accounts, cached mail, and Keychain tokens from your device.
- Deleting data in the app does not delete your mail at Google. Your messages stay in your Gmail account.
How to revoke access
You can revoke the app’s access to your Google account at any time at https://myaccount.google.com/permissions (Google Account → Security → Your connections to third-party apps & services → Hermod → Delete all connections). Once you revoke access, the app can no longer read or send your Gmail. Removing the account in the app deletes the tokens stored on your device. Revoking at Google also cancels the access Google granted.
Limited Use
Hermod Mail’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Information stored on your device
- Account details: email address, display name, provider, profile photo, and last-sync time.
- Credentials: OAuth access and refresh tokens and app passwords are stored in the iOS Keychain on your device. They are never uploaded to us.
- Mail cache: message headers, bodies, and attachments you open may be cached in the app’s private storage so you can read them offline.
- Preferences: settings, send quotas, and optional activity stats, stored in the app’s settings on your device.
- Contacts: if you allow it, the app reads your iOS contacts on your device to suggest recipients and show contact photos. Your contacts are not uploaded.
- Subscriptions: Hermod Pro is sold through the App Store. Apple processes payment, and the app only checks whether a subscription is active.
Information we do not collect
- We do not sell personal data.
- We do not run advertising networks or tracking pixels.
- We do not collect a persistent device advertising identifier.
- We do not collect usage analytics. The app contains no analytics, advertising, or crash-reporting tools from other companies and sends no usage data to us. If you have chosen to share analytics with app developers in iPhone Settings → Privacy & Security → Analytics & Improvements, Apple may share crash reports and aggregated usage statistics with us. If you test the app through TestFlight, feedback and crash reports you choose to send reach us through Apple. If this ever changes, we will update this policy and ask for your consent first.
Sender logos
Sender logo lookups are controlled by an opt-in setting, Show sender logos, which is off by default for every account type. While it is off, the app shows sender initials or photos from your iOS contacts, and no sender domains, email addresses, or address hashes are sent to DuckDuckGo, Google’s favicon service, Gravatar, or sender websites. Apart from your own mail provider, no information about your senders leaves your device, except for remote content in emails you open and unsubscribe requests you tap, as described above. If you turn the setting on, the lookups described under “How it is shared” take place. You can turn it off again at any time. Some early versions of the app looked up logos automatically, so update to the latest version to get this setting.
Other mail providers and Apple
When you connect a non-Google account, you sign in with that provider (Microsoft, Yahoo, AOL, iCloud, or your IMAP/SMTP host). That provider processes your credentials and mail under its own policies. The app uses the resulting tokens or app password only to connect from your device to that provider’s IMAP, SMTP, or Microsoft Graph service. The sender-logo, remote-content, and unsubscribe behavior described above applies to every account.
Purchases are handled by Apple, and Apple’s privacy policy covers App Store payments and subscription management.
Your choices
- Export: Settings → Export Data (Hermod Pro) creates a file (JSON format) of mail cached on your device that you can save or share.
- Delete: Settings → Delete Account & Data removes linked accounts, cached mail, and Keychain tokens from your device. It does not delete your mailbox at Google, Microsoft, or any other provider. You can revoke the app’s access with your provider too (for Google, see above).
- Notifications: new-mail alerts are created on your device, and you can turn them off in the app’s Settings or in iOS Settings.
Children
Hermod Mail is not directed at children under 13, and we do not knowingly collect personal information from children.
Changes
If we change this policy, we will update the date at the top. If we ever change how Google user data is used, we will update this policy and ask for your consent in the app before using the data in the new way.
Contact
Questions about this policy? Email us at support@tryhermod.com.