Privacy Policy for 4Mail
Last updated: October 2026
1. Who is responsible
4Mail by robspace ("4Mail", "the App") is developed and published by Robert Poetzsch under the robspace brand.
Robert Poetzsch
Brückenstr. 8A
65719 Hofheim am Taunus
Germany
Email: support@robspace.de
This policy explains which data 4Mail processes, where it is kept and who can see it. It applies to 4Mail on iPhone, iPad and Mac.
2. Summary
- 4Mail is an email client for your Gmail account and, if you like, further IMAP accounts. The App fetches and sends your mail directly with Google or your mail provider. There is no robspace server that your mail passes through or is stored on.
- We (robspace) never see your mail, contacts, appointments or sign-in credentials. We have no technical way to.
- 4Mail contains no analytics, no advertising, no tracking, no crash-reporting SDKs and no third-party SDKs. It is built with Apple's frameworks; for IMAP it also uses Apple's open-source networking libraries (SwiftNIO), which only connect to your mail provider.
- Everything the App stores stays on your device. When you sign out, 4Mail deletes the mail data from the device and revokes its access at Google.
- Optionally (default: off), 4Mail syncs your settings and ToDos between your devices through your private iCloud. Mail content, subjects and sign-in credentials never go to iCloud (section 12).
- AI summaries are created on the device with Apple Intelligence. Your mail does not leave the device for this.
3. Google user data
This section explains how 4Mail accesses, uses, stores and shares data from your Google Account.
3.1 Access
You sign in to 4Mail with your Google Account. Sign-in happens on Google's own sign-in page; you enter your Google password only there, 4Mail never sees it. Google then asks whether you allow 4Mail access.
4Mail requests exactly one permission: https://www.googleapis.com/auth/gmail.modify ("Read, compose, and send emails from your Gmail account"). This permission does not allow permanent deletion of mail; deleted mail goes to the Gmail trash. 4Mail does not request any other Google service (no Calendar, Drive, Contacts or profile scopes).
3.2 What 4Mail retrieves from Google
- Messages and conversations: headers (sender, recipients, subject, date, technical headers such as
Delivered-ToandList-Unsubscribe), message body, snippet, and attachments when you open a message or an attachment. - Metadata: thread and message IDs, labels on a message, read state, change history (
historyId) for syncing. - Labels: names and counts (unread/total) of your Gmail labels.
- Sender identities: your "Send mail as" addresses with display name, reply-to address and signature (Gmail setting
sendAs). - Mailbox profile: your Gmail address and current sync position (
users.getProfile). - Search results: when you search, 4Mail sends your search terms to Gmail and receives the matching conversations.
3.3 How 4Mail uses this data
Only for the features you see and operate in the App:
- Showing, reading and searching your mail, sorted into boxes (by label or by the address it was sent to).
- Marking mail read/unread, archiving, moving to a box, applying labels, moving to trash or restoring from it. 4Mail sends these changes to Gmail.
- Writing, replying to and forwarding mail, including from one of your "Send mail as" addresses. Mail is sent through Gmail.
- ToDos: when you turn a mail into a ToDo, 4Mail creates the label "4Mail/ToDo" in your Gmail account (once) and applies it to that mail. Due date and note stay on the device.
- Counting on the device: unread mail per box, unanswered personal mail, newsletter bundles for the Briefing tab.
- AI summaries on the device (section 5).
- Local notifications about new mail (section 8).
- Unsubscribing from newsletters when you confirm it (section 9).
- Appointment suggestions from dates in mail, which you confirm in the calendar editor (section 7).
4Mail does not use Google user data for advertising, for profiling, to train or improve AI or machine-learning models, or for any purpose other than the features listed above.
3.4 Where the data is stored
Only on your device, in the App's database (SwiftData) and a search index (SQLite) inside the App's own storage. On iPhone and iPad the folder is encrypted by iOS Data Protection (available after first unlock); on the Mac it is protected by the App sandbox and, if turned on, FileVault. The folder is excluded from device backups (iCloud Backup, Finder backup, Time Machine). Details are in section 4.
If you turn on iCloud sync, 4Mail also keeps settings, ToDos and identifiers (for example thread IDs of mail ToDos and Gmail label IDs) in your private iCloud database, but no mail content. Section 12 lists exactly what.
Google's sign-in key (refresh token) is kept in the device keychain with the "this device only" setting: it is not synced via iCloud Keychain and not included in device backups. The short-lived access token is held in memory only.
The connection to Google is encrypted (HTTPS) and uses no network cache.
3.5 Sharing
4Mail does not share Google user data with anyone: not with robspace, not with advertising networks, data brokers or any other third party. Data is never sold.
Data leaves the device only in these cases, each triggered by you:
- to Google, when 4Mail sends your changes, outgoing mail or search requests to Gmail;
- to your private iCloud database at Apple, if you turn on iCloud sync: only the settings, ToDos and identifiers listed in section 12, no mail content. Only you have access through your Apple Account; robspace cannot see this database;
- to the newsletter sender, when you confirm an unsubscribe (section 9);
- to Apple Calendar on your device, when you save an appointment suggestion in the calendar editor (section 7). What then happens to the event depends on the calendar account you pick there;
- to apps or places you choose in the share sheet when you open, share or save an attachment.
3.6 No human reads your data
Nobody at robspace reads your mail or other Google data. We have no access to it. If you forward a mail to us for support yourself, we see only what you send.
3.7 Limited Use
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Sources: Google Workspace API User Data and Developer Policy, Google API Services User Data Policy.
3.8 Revoking access and deleting data
- In the App: Settings → Sign out. 4Mail revokes its access at Google and deletes the mail data from the device (section 6). If you are offline, 4Mail remembers the revocation and completes it once the device is online again.
- At Google: at any time at https://myaccount.google.com/permissions → 4Mail by robspace → remove access. 4Mail can then no longer access your mailbox; delete the data on the device by signing out or deleting the App.
- Deleting the App: On iPhone and iPad, iOS deletes all of the App's data on the device, including settings. On the Mac, the data stays in the App's container (
~/Library/Containers/RobEarth.-Mail) until you remove it. The system does not always remove the keychain entry, so sign out in the App or revoke access at Google before deleting. - iCloud: delete data in your iCloud in 4Mail under Settings → iCloud → "Delete data from iCloud…" (section 12).
4. What 4Mail stores on the device
| What | Where | Device backup |
|---|---|---|
| Cache of your mail: conversations, headers, snippets, opened message bodies, label assignments, AI summaries | App database Cache | excluded |
| What you created: account entry, boxes (name, colour, symbol, order, default sender, notification setting), colours/initials of your identities, ToDos (due date, note, title), actions not yet sent | App database User | excluded |
| Search index (subject, sender, recipients, snippet, attachment names, labels, ToDo state; no message bodies) | Search.sqlite in the same folder | excluded |
| List of your labels, last generated Briefing | App cache folder | excluded |
| Opened attachments | temporary folder; deleted after closing and at the next launch | excluded |
| Google sign-in key, IMAP passwords | keychain, this device only | not included |
| IMAP accounts: account list, index file and search index per account (section 13) | in the same mail folder | excluded |
| Own ToDos without a mail, if you choose to keep them when signing out | OwnTodos.json in App storage | included |
| Account markers, see below | AccountSettings.plist in the same folder | excluded |
| iCloud sync state (only if turned on) | in the same folder | excluded |
| General settings without reference to mail (UserDefaults), see below | App settings | included |
Account markers (in the mail folder, excluded from device backups): sender addresses you marked as important; senders for which you chose "no reply needed" (with a count); own addresses you excluded from the Briefing; dismissed "reply due" hints (thread ID and date of the last message); dismissed appointment suggestions and the link "appointment created from this mail" (thread ID to event ID); identifiers of messages already notified (so no notification comes twice); your recent search terms.
General settings (UserDefaults): your choices for Briefing times and content, AI on/off, notifications, calendar suggestions, default ToDo due time and view, layout, what to show after archiving, the App version last shown in "What's New", whether iCloud sync is on and for which areas, plus the list of newsletters you unsubscribed from via 4Mail and the name the Briefing greets you with (both deleted when you sign out). No sender addresses or mail content are stored here.
5. Summaries with Apple Intelligence
If Apple Intelligence is available on your device and turned on in 4Mail (Settings → Briefing & AI), 4Mail lets the on-device language model (Apple Foundation Models) summarise individual messages and assess whether a reply is expected and whether a reply deadline is mentioned. In doing so:
- Only the on-device model is used, not Apple's Private Cloud Compute or any other server. The message text does not leave the device.
- 4Mail does not send mail content to Apple as feedback and does not train any model.
- Numbers in the Briefing (open replies, ToDos, appointments, newsletters) are counted by 4Mail itself, without AI.
- Results are kept in the cache (section 4) and deleted with the message or when you sign out.
- AI can be wrong. Every line in the Briefing links to its source.
You can turn the AI features off at any time; the Briefing then keeps counting without AI.
6. Signing out: what is deleted and what stays
When you sign out (Settings → Sign out), 4Mail revokes its access at Google, deletes the sign-in key from the keychain and deletes from the device: both App databases with all mail data and mail ToDos, the search index, the Briefing, the label list, opened attachments, the list of unsubscribed newsletters, recent search terms, network and web caches, all account markers (section 4), the iCloud sync state, the greeting setting and this device's iCloud switches, and resets the app icon badge.
Only the general settings without reference to mail (section 4) are kept. Own ToDos without a mail are kept only if you choose so when signing out.
Signing out does not delete data in your iCloud, so your other devices keep it. To remove it, use Settings → iCloud → "Delete data from iCloud…" before signing out (section 12).
7. Calendar
For the Agenda (appointments next to mail and ToDos), 4Mail asks for access to your calendars. If you grant it, 4Mail reads your appointments on the device only; they are not transferred anywhere. 4Mail does not change existing appointments.
If 4Mail recognises a date in a mail, it can suggest an appointment. It is saved only if you confirm it: on iPhone and iPad in Apple's calendar editor, on the Mac in a 4Mail event form. There you also pick the calendar. If that calendar belongs to an online service (for example iCloud or Google Calendar), the system syncs the event there under that service's rules.
You can withdraw calendar access at any time in iOS Settings.
8. Notifications and background refresh
4Mail checks for new mail in the background when iOS or macOS allows it. There is no robspace push server (if iCloud sync is on, Apple's iCloud tells the device with a silent notification that settings or ToDos have changed): notifications about new mail, the morning/evening Briefing and the "please sign in again" notice are created locally on the device with Apple's notification system.
For each box you choose whether notifications appear and whether they show a preview (sender, subject, recipient address). With preview, these details may be visible on the lock screen, depending on your iOS settings. Without preview, the notification only says "New mail in …".
Pre-computing AI summaries in the background only runs while the device is charging.
9. Unsubscribing from newsletters
If a newsletter offers an unsubscribe option (List-Unsubscribe header), 4Mail shows a button for it. Unsubscribing happens only after you confirm in a dialog that names the destination:
- One-click unsubscribe (RFC 8058): 4Mail sends a single request to the address the sender provided. It contains only
List-Unsubscribe=One-Click, no cookies and no data from your account. As with any web request, the sender's server sees your IP address. 4Mail offers this only if the mail carries a DKIM signature matching the sender, and refuses destinations on a local network. - Unsubscribe by email: 4Mail opens a pre-filled message to the given address in its own editor. You check it and send it yourself through your Gmail account.
- Unsubscribe on a web page: 4Mail opens the page in a browser (on iPhone and iPad in a Safari view inside the App); whatever you enter there goes to the operator of that page.
The sender's own privacy policy applies to processing on their side.
10. Images and links in mail
Images and other content a mail would load from the internet (for example tracking pixels) are blocked by default. Scripts in mail never run. If you tap "Load images" on a mail, 4Mail loads that mail's images from the sender's servers; they then see your IP address and the time.
4Mail opens links in mail only after asking you and showing the destination, and then in your browser. The privacy policy of that website applies there.
In Settings, 4Mail also links to the community page on github.com ("Community & Feedback"), this website and, for iCloud Mail, Apple's pages on app-specific passwords (account.apple.com, support.apple.com). A tap opens the page in your browser; the App itself sends nothing.
11. Demo without an account
In demo mode ("Take a look first – demo without account"), 4Mail shows invented sample mail. There is no connection to Google, and demo data is held in memory only.
12. iCloud sync (optional)
iCloud sync is off by default. You turn it on under Settings → iCloud and choose there which areas are synced. 4Mail then keeps the data listed below in the private CloudKit database of your Apple Account, so your other devices with the same Apple Account and the same Gmail account can pick it up. There is no robspace server involved; robspace has no access to your private iCloud database.
What may be in your iCloud (depending on the areas you choose):
- Boxes: kind, Gmail label ID, your own name, order, size, colour, symbol, default sender, notification and ToDo settings; saved searches with your search text (people in them only as a checksum, without names).
- Addresses: nickname, initials and colour of your own addresses.
- ToDos: own ToDos in full (title, note, due date, state). For ToDos from mail only the mail's thread ID, due date, your note, state and a title you typed yourself, never the subject.
- Briefing and settings: times, content, AI on/off, greeting name, ToDo defaults; important senders, "no reply needed" and excluded own addresses; dismissed reply hints (thread ID and date of the last message).
Email addresses (yours and senders') and the account itself appear in iCloud only as a checksum (HMAC-SHA256 with a random key kept only in your private iCloud database). The address cannot be computed back from the checksum.
What never goes to iCloud: sign-in credentials and tokens, message bodies, subjects, snippets, attachments, sender names, addresses in plain text, AI summaries, Briefings, the search index and the Gmail sync position.
Encryption: 4Mail stores the content of every record in CloudKit fields that are encrypted on the device (encryptedValues). If you turned on Advanced Data Protection for your Apple Account, only you hold the keys; without it, Apple holds the keys and the data is encrypted in transit and on Apple's servers. CloudKit does not separately encrypt the technical names of records and zones (for example a Gmail label ID, a thread ID or a checksum). Apple's privacy policy applies to iCloud.
Turning off and deleting: under Settings → iCloud you can turn sync off and keep or delete the data in iCloud. "Delete data from iCloud…" removes either this account's data or everything of 4Mail from your iCloud. The data on your devices stays; other devices keep their own copy. Signing out does not delete iCloud data (section 6).
13. Other mail providers (IMAP)
Besides Gmail you can add accounts of other providers that offer IMAP and SMTP (for example iCloud Mail, GMX, web.de, T-Online, Posteo, mailbox.org). Outlook.com/Hotmail and Proton Mail are not supported. Section 3 (Google user data) applies only to Gmail accounts; this section applies to IMAP accounts.
- Connection: 4Mail connects directly to your provider's servers, always encrypted (TLS 1.2 or later, or mandatory STARTTLS). If a server offers no encryption or it fails, 4Mail stops; there is no fallback to unencrypted connections and no "accept the certificate anyway". No robspace server is involved.
- Password: Your password (for iCloud Mail an app-specific password) is kept only in this device's keychain with the "this device only" setting: never in iCloud Keychain, never in device backups, never in iCloud sync. You enter it yourself on each further device.
- Setup (autoconfiguration): To find the server addresses, 4Mail first uses a built-in table of known providers. If your provider is not listed, 4Mail requests the configuration file from your domain's provider (
https://autoconfig.<domain>/…andhttps://<domain>/.well-known/autoconfig/…) and then the domain's DNS SRV records. Only the domain of your address (the part after "@") and, as with any request, your IP address go to the domain's server or your DNS server; no credentials, no cookies. 4Mail does not query any central provider database on the internet. You can also enter the servers yourself. - What 4Mail retrieves and stores: folders, headers, message bodies and attachments as with Gmail (sections 3.2–3.4 and 4 apply accordingly): in the App's cache, a search index and an index file per account, all in the device's mail folder, encrypted and excluded from device backups. The account list (address, display name, servers, user name, chosen archive folder, no password) is kept there too.
- What 4Mail changes on the server: read/unread and flagged (IMAP flags), moving to folders, archive and trash, and for ToDos the IMAP keyword
$ToDoon the message. Mail is sent through your provider's SMTP server; 4Mail puts a copy in your Sent folder if the provider does not do so itself. When you search, 4Mail may send the search to your provider's server. - Removing an IMAP account (Settings → Accounts → "Remove account"): 4Mail deletes the password from the keychain and all of this account's data from the device (cache, search index, index file, entry in the account list). The mail on the server stays unchanged.
- iCloud sync: Section 12 applies to IMAP accounts accordingly, with a separate area per account (named after the checksum of the address). Instead of a Gmail label ID, boxes carry the name of the IMAP folder; server settings and passwords are never synced.
Your mail provider's privacy policy applies to processing on their side.
14. No analytics, no advertising, no third parties
4Mail contains no analytics, tracking, advertising or crash-reporting SDKs. Apart from Apple's frameworks, the App contains only Apple's open-source libraries SwiftNIO (swift-nio, swift-nio-ssl, swift-nio-transport-services, swift-nio-imap) plus swift-collections, swift-atomics and swift-system for IMAP and SMTP; they send no data to third parties. 4Mail does not track you across other companies' apps or websites and does not use the advertising identifier.
Independently of 4Mail, Apple provides app developers with crash reports and usage statistics if you agreed in the system settings to "Share with App Developers" (iPhone/iPad: Settings → Privacy & Security → Analytics & Improvements; Mac: System Settings → Privacy & Security → Analytics & Improvements). You control this there.
15. Legal bases and your rights
robspace does not collect personal data through 4Mail on its own systems. Processing in the App takes place on your device, under your control and at your instruction (Art. 6(1)(b) GDPR: providing the features you use). Google's privacy policy applies to your Google Account, your mail provider's to IMAP accounts, Apple's to the App Store.
If you write to support@robspace.de, we process your message to answer it (Art. 6(1)(b) or (f) GDPR) and delete it once it is resolved and no retention obligation applies.
You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and the right to lodge a complaint with a data protection supervisory authority, for example the Hessian Commissioner for Data Protection and Freedom of Information. Because we receive no data from the App, you can exercise most of these rights directly in the App (sign out, delete).
16. Children
4Mail is not directed at children. The age limits of your Google Account apply to sign-in.
17. Changes
If we change this policy, we update this page and the date above. If 4Mail is ever to access or use Google data in a way not described here, the App will ask for your consent first.
18. Contact
Privacy questions: support@robspace.de