Blanc Mail · Pre-release policy
Privacy.
Prepared September 22, 2026 · Effective when Blanc Mail launches.
Your Gmail account
Blanc Mail connects directly from your Mac to Google after you authorize it. It first requests access to read your mailbox and send messages you choose to send. Managing drafts, organizing mail, and using Gmail Settings request additional permissions when you first use those features. Google credentials remain in the macOS Keychain. Mail metadata, opened bodies, synchronization state, and recoverable drafts may be stored in your Mac's Application Support folder. Bananify does not receive your mail content or OAuth tokens.
Google Contacts and Calendar
Contact photos are off by default. If you turn on Show contact photos, Mail requests read-only access to your Google Contacts. Contact addresses and photos are cached on your Mac for that account and deleted when you turn the setting off, disconnect or sign out, or switch accounts. Photos come from Google's CDN and are matched to senders on your Mac; Mail does not send sender addresses to an avatar service. A matching photo does not verify who sent a message.
Mail can show an invitation from its attached .ics file without Calendar access. Check availability requests optional access to your primary Calendar's free/busy status and keeps the result in memory. RSVP requests separate Calendar access and sends the invitation identifier and your chosen response directly to Google. Mail does not save Calendar event details with your mail or send Calendar data to Bananify.
Private Push
If you enable Private Push, a Bananify relay delivers refresh signals. Gmail's Pub/Sub event includes your email address and an opaque history checkpoint. The relay derives a keyed hash for device lookup; it does not store the raw address, the checkpoint, or mail content. It stores the keyed hash, installation identifier, APNs token, app version, and registration expiry in Google Cloud Firestore. Apple receives a push containing the registration identifier, checkpoint, and an optional delivery identifier, without mail content. Your Mac fetches actual changes directly from Gmail.
Expired push registrations stop receiving signals immediately. The relay removes their records asynchronously through a six-hour sweep while running and Firestore's time-to-live policy, which typically completes deletion within 24 hours of expiry. Disabling Private Push or signing out removes the registration promptly.
Remote images and attachments
Remote images and eligible web fonts load automatically unless you turn that off in Settings. Loading remote content may reveal your IP address and open time to a sender. For images you attach to outgoing mail, Blanc Mail strips identifying metadata; other file types and forwarded attachments are left intact.
Purchases and licenses
Polar will process new subscription payments and license keys under its privacy policy. The app sends a new license key and the public organization identifier to Polar for validation, without your Gmail account or mail. Existing beta keys continue to be checked by postelmail.com. License state stays in the macOS Keychain.
Instead of pasting a key, you can sign in with the email address you bought with. Mail sends that address and Blanc's public Polar organization identifier to Polar, which emails you a one-time code. Mail exchanges the code with Polar for a short-lived session, uses it once to find your Blanc Mail license key, and does not keep the session. Your address and code go only to Polar, never to a Bananify server.
Updates
Automatic Sparkle checks are off at first. On the app's second launch, Mail asks whether to enable them; until you opt in, it checks the existing postelmail.com appcast only when you choose Check for Updates…. A check exposes your IP address and identifies the app version and updater in its user agent. It sends no account, mail, device, or installation identifier and does not enable Sparkle's optional system profile. Signed updates are verified on your Mac before installation.
Local data and deletion
Removing a Gmail account clears its account-scoped reconstructible cache after pending draft recovery is resolved. Moving Mail to the Trash does not remove its local settings and recovery data; to erase those too, resolve any drafts you need and remove Mail's Application Support data. Bananify has no copy of your mailbox to delete. The app has no advertising or analytics SDK, does not sell user data, and excludes message bodies, subjects, addresses, OAuth tokens, MIME payloads, and attachment contents from diagnostic logging.
Google Limited Use
Blanc Mail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements. Google data is used to provide the features you request and is not used for advertising.
Contact
Privacy questions: support@blancbrowser.com.