Draft — pending legal review. No lawyer has reviewed this document yet. It describes how the shipped application actually behaves, but it is not final and should not be relied on as the published policy.
Mailroom is a desktop email client for macOS and Windows. It runs on your computer and talks directly to your own Gmail / Google Workspace or Microsoft 365 / Outlook account.
We do not store your mail. Sorted Solution LLC hosts nothing and receives nothing. There is no Mailroom server, there is no Mailroom account to create, and there is no sign-in of ours — your identity comes from Google or Microsoft. Your mail, calendar and contacts are stored in an encrypted database on your own computer.
When you connect an account, Mailroom asks that provider for permission to do specific things. Each permission exists for a feature you can see in the app.
Mailroom requests exactly these scopes:
| Permission | What it is used for |
|---|---|
openid, email,https://www.googleapis.com/auth/userinfo.email |
To identify which account signed in. |
https://www.googleapis.com/auth/gmail.modify |
To read your mail and attachments so they can be shown in the app; to apply and remove labels; to create and update drafts; and to send the messages you send. |
https://www.googleapis.com/auth/calendar |
To read and write your calendar events, so you can see and edit your calendar in the app. |
https://www.googleapis.com/auth/contacts |
To read and write your contacts, so you can see and edit them in the app. |
https://www.googleapis.com/auth/drive.appdata |
A private, app-only folder in your own Google Drive. See the app-only folder below. |
gmail.modify is a restricted scope in Google's classification. Mailroom
needs it because nothing narrower does the job: gmail.metadata cannot read a message
body, gmail.labels cannot read mail at all, and gmail.send covers only
sending.
Mailroom does not request gmail.compose or
gmail.insert. They were removed: gmail.compose was redundant, and
gmail.insert writes messages into a mailbox, which the product forbids
outright. An automated test fails the build if a restricted scope is added back.
For a Microsoft account, Mailroom requests:
offline_access, openid, profile, email —
to identify which account signed in and to keep that sign-in valid.Mail.ReadWrite and Mail.Send — to read your mail and attachments,
to apply and remove categories, to create and update drafts, and to send.MailboxSettings.Read — to read your mailbox settings.Calendars.ReadWrite — to read and write your calendar events.Files.ReadWrite.AppFolder — the same private, app-only folder idea, in
OneDrive.Mailroom keeps one thing in your own Drive or OneDrive rather than only on your computer: the relationship record — the notes, projects, tags, links and pins you make about your contacts. It lives in a folder that is invisible in Drive's own file browser and that only Mailroom can read. It is in your storage, not ours, so that it survives a rebuilt local database and follows you between machines.
Only three things: labels and categories, drafts, and the messages you send.
Mailroom never deletes a message, never moves one, and never changes a flag you did not initiate. Your mailbox at Google or Microsoft remains the system of record; Mailroom keeps a local copy of it.
On your own computer, in an encrypted SQLite database (SQLCipher):
Mailroom is offline-first: your mail, calendar and contacts are stored locally and the app is fully usable with no network connection. That local database is the only place Mailroom keeps your content, apart from the app-only folder in your own Drive or OneDrive described above.
Nobody. In this release, no message content leaves your computer.
There is one optional feature worth stating precisely. You may paste your own Anthropic API key in order to describe a filing rule in a sentence and have Mailroom turn it into a rule. When you use it, what is sent is the sentence you typed, plus a list of field and command names. No message, no subject and no email address is sent. If you have not configured a key, the feature is simply unavailable and nothing is sent at all.
The application and this website are separate, and what is true of one is not automatically true of the other. Mailroom is a desktop application, not a website: it sets no cookies, and it sends nothing about you anywhere. That does not change.
This website measures its visitors. We use Plausible, a privacy-focused analytics service, so that we can see which pages people read and where they arrived from. It records a page view, the site that referred you, and your approximate country and device type.
It sets no cookies, stores no persistent identifier for you, does not track you across other sites, and does not collect personal data. Because of that, no cookie consent banner is required and none is shown. Nothing it collects is linked to your Mailroom account, to your mailbox, or to you.
If you would rather not be counted at all, any content blocker will stop it, and the site works exactly the same with it blocked.
Mailroom's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Neither of these touches your actual mail. Your messages are still in Gmail or Outlook, where they always were.
Mailroom is not directed at children. It is a tool for using an email account you already have, and we do not knowingly collect anything from children — we do not collect anything from anyone.
If we change this policy, we will update the "Last updated" date at the top of this page. If a change affects what Mailroom accesses or where your data goes, we will say so in the application as well, not only here.
Sorted Solution LLC. Questions about this policy, or about your data, can be sent to [PLACEHOLDER: support email address — to be supplied].
[PLACEHOLDER: company legal postal address — to be supplied, if this policy is to carry one]