Effective date: 29 August 2026
Last updated: 29 August 2026
This Privacy Policy explains how Postbird (“Postbird,” “the app,” “we,” “us,” or “our”), operated by Otron Pty Ltd, accesses, uses, stores, and shares information when you use the Postbird Linux application.
Contact: postbird@otron.com
Website: https://otron.com/postbird
1. What Postbird is
Postbird is a desktop email client that lets a user access and manage their own Gmail accounts. Postbird runs on the user’s Linux computer and communicates directly with Google’s Gmail API. We do not operate a Postbird server that receives or stores users’ Gmail mailbox data.
2. Google account information Postbird accesses
After you choose to connect a Google account and approve Google’s OAuth consent screen, Postbird may access:
- your Google account email address and basic account identity;
- Gmail messages, conversations, headers, bodies, snippets, and attachments;
- Gmail folders, system labels, and user-created labels;
- message state such as read/unread, starred, archived, draft, sent, spam, and trash status; and
- messages, drafts, replies, and attachments that you choose to create or send.
Postbird requests the Google gmail.modify permission because its visible email-client features require it to read mail and perform actions requested by the user, including sending, drafting, labeling, archiving, marking read or unread, starring, and moving mail to Trash. It also requests basic Google account identity information so connected accounts can be identified in the account selector.
3. How Google user data is used
Postbird uses Google user data only to provide or improve user-facing email features within Postbird, including:
- displaying your mailbox, messages, conversations, and labels;
- searching and refreshing mail;
- maintaining a local inbox cache for faster startup and limited offline viewing;
- carrying out mailbox actions that you initiate;
- composing, saving, replying to, and sending messages; and
- supporting multiple connected Google accounts.
Postbird does not use Google user data for advertising, profiling, credit decisions, data brokerage, surveillance, or training general-purpose artificial-intelligence or machine-learning models. We do not sell Google user data.
Postbird’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Where information is stored
Postbird stores information locally on the computer where it is installed:
- Google OAuth access and refresh tokens are stored through the Linux system keyring;
- connected-account names and email addresses, the imported Google Desktop OAuth client file, and interface preferences are stored in the user’s Postbird configuration directory;
- cached message content and metadata are stored in a local SQLite database; and
- attachments selected for sending remain at their existing local file locations until they are sent to Google at the user’s request.
The local mail cache is not separately encrypted by Postbird. Its protection depends on the security of the user’s device, operating-system account, filesystem, disk encryption, and backups. Users should enable full-disk encryption and a secure login where appropriate.
Postbird does not include developer-operated analytics, telemetry, advertising, or crash-reporting services.
5. When information leaves your device
Postbird sends information to Google only as required to authenticate, retrieve Gmail data, refresh mailbox state, and perform actions requested by the user. Google processes that information under its own terms and privacy policies.
Information may also leave the device in these situations:
- when you send a message or attachment, its contents are transmitted to Google and the recipients you specify;
- HTML email may contain externally hosted images or other remote resources. Loading those resources can disclose your IP address, device/network information, and resource-specific identifiers to the email sender or hosting provider;
- clicking a link opens it through your system browser and shares information according to the destination site’s policies; and
- your operating system’s browser, keyring, networking, and desktop services process information necessary to provide those functions.
We do not transfer Gmail data to advertising platforms, data brokers, information resellers, or unrelated third parties.
6. Human access to Google user data
Because Postbird has no developer-operated mailbox server, we do not ordinarily receive or have human access to your Google user data. A person may see information only if you deliberately provide it in a support request, if access is necessary for security or abuse investigation and permitted by law, or where legally required. Do not include private message content or credentials in support requests unless specifically necessary.
7. Retention and deletion
Google user data is retained locally for as long as it remains in Postbird’s configuration, system keyring, local mail cache, filesystem, or device backups.
Removing an account inside Postbird removes that account from Postbird and deletes its stored OAuth token from the system keyring. The current version does not automatically remove that account’s records from the shared local mail cache or delete the imported OAuth client configuration.
To remove Postbird data completely:
- remove each connected account in Postbird;
- revoke Postbird’s access from your Google Account’s third-party connections or permissions page;
- close Postbird;
- delete Postbird’s configuration directory, normally
~/.config/postbird/; - delete Postbird’s local data directory, normally
~/.local/share/postbird/; and - remove any Postbird credentials that remain in the Linux system keyring and delete relevant device backups if desired.
These paths can differ if the system uses custom XDG configuration or data directories. Deleting local Postbird data does not delete messages from Gmail. Mailbox changes that you already requested through Postbird, such as sending or trashing a message, remain part of the Google account unless changed in Gmail.
You may contact postbird@otron.com for privacy assistance. Because we do not hold a server-side copy of your mailbox, we may be unable to delete data stored only on your own device; the steps above provide direct control over that data.
8. Security
We use safeguards appropriate to a local desktop application, including Google’s browser-based OAuth flow, a loopback redirect bound to the local computer, PKCE during authorization, system-keyring token storage, restricted local configuration-file permissions, and HTTPS communication with Google APIs.
No system is completely secure. Users are responsible for maintaining the security of their computer, operating-system account, keyring, backups, and Google account. Please report suspected security issues to postbird@otron.com.
9. Children
Postbird is a general-purpose email client and is not directed to children under 13 or the minimum age required by applicable local law. We do not knowingly operate a service that collects children’s Gmail data on our servers.
10. International processing
Postbird itself stores Gmail data locally. Google, message recipients, remote-content providers, browser destinations, and operating-system service providers may process data in other countries under their respective terms and privacy policies.
11. Changes to this policy
We may update this Privacy Policy when Postbird’s functionality, data practices, or legal obligations change. The updated version will be posted at https://otron.com/postbird/privacy-policy with a revised “Last updated” date. Material changes will be communicated through the website or application where reasonably practical.
12. Contact
Otron Pty Ltd
postbird@otron.com
https://otron.com/postbird
