Polityka prywatności — Aorum Mail

Ostatnia aktualizacja: 2026-09-29 · Administrator danych: Vansa Sp. z o.o., ul. Jana Smolenia 14, 30-864 Kraków (KRS 0000675425, NIP 6793148076) · Kontakt: support@aorum.app · Strona: aorum.app

W skrócie: Aorum Mail trzyma Twoją pocztę i kontakty na Twoim iPhonie. Nie mamy serwera, który przechowywałby kopię Twojej skrzynki. W wersji 1.0 nasz serwer obsługuje tylko dwie opcjonalne usługi, które włączasz sam/a: natychmiastowe powiadomienia o nowej poczcie Gmail oraz wysyłkę zaplanowanych wiadomości z serwera, także gdy telefon jest wyłączony. Funkcje oparte na iCloud, Dysku Google i OneDrive zapisują dane na Twoich własnych kontach w tych usługach — nie mamy do nich dostępu. Asystent AI, wyszukiwanie według znaczenia i uczący się podział skrzynki działają wyłącznie na iPhonie. Nie sprzedajemy danych i nie prowadzimy śledzenia reklamowego.

1. Administrator danych

Administratorem danych w rozumieniu RODO jest Vansa Sp. z o.o., ul. Jana Smolenia 14, 30-864 Kraków (KRS 0000675425, NIP 6793148076). Kontakt w sprawach ochrony danych: support@aorum.app.

2. Jakie dane przetwarza aplikacja

2.1 Poczta i kontakty — na urządzeniu

Wiadomości, załączniki, szkice, notatki o osobach, zapisane wyszukiwania, ustawienia i indeks wyszukiwania są zapisywane w bazie danych aplikacji na Twoim iPhonie. Wiadomość zaplanowana na później czeka na telefonie i wysyła ją sama aplikacja — chyba że dla danego konta włączysz wysyłkę z serwera (punkt 2.6); wtedy czeka jako szkic w Twojej własnej skrzynce u dostawcy poczty. Aorum Mail nie ma własnego serwera, który trzymałby kopię Twojej skrzynki.

2.2 Konta pocztowe (Gmail, Microsoft, IMAP)

Aby pokazać Twoją pocztę, aplikacja loguje Cię bezpośrednio u dostawcy — Google, Microsoft, Apple albo wskazanego serwera IMAP. Przy Gmailu i Microsoft logujesz się na stronie dostawcy (OAuth), więc aplikacja nie poznaje Twojego hasła — dostaje tylko token dostępu. Przy iCloud i IMAP podajesz dane serwera i hasło (zwykle hasło aplikacji). Tokeny i hasła trzyma pęk kluczy iOS (Keychain), nigdy zwykłe pliki, a aplikacja używa ich do łączenia się z Twoją skrzynką. Opuszczają telefon tylko wtedy, gdy dla danego konta włączysz wysyłkę zaplanowaną z serwera (punkt 2.6) albo serwerowe powiadomienia o poczcie Outlook, Microsoft 365, iCloud i IMAP (punkt 2.14) i zgodzisz się na to w osobnym oknie — wtedy serwer dostaje poświadczenie potrzebne do tej funkcji. Każdy dostawca przetwarza Twoją pocztę zgodnie z własną polityką prywatności.

2.3 Kontakty

Za Twoją zgodą aplikacja może odczytać książkę adresową iPhone'a, a jeśli włączysz synchronizację kontaktów dla konta Gmail (domyślnie wyłączona) — także kontakty tego konta Google, żeby pokazać nadawcę z imieniem i zdjęciem zamiast samego adresu. Zmiana typu numeru telefonu wybrana w aplikacji jest zapisywana z powrotem w Twoich kontaktach Google. Zgodę na książkę adresową cofasz w Ustawieniach systemowych iOS, a synchronizację z Google — w ustawieniach konta w aplikacji; odczytane dane zostają na urządzeniu. Wyjątek to opcjonalne „dopasowanie kontaktów” dla powiadomień Gmail (punkt 2.5) — tylko gdy je włączysz, serwer dostaje jednokierunkowe skróty adresów, nigdy same adresy.

2.4 Asystent AI i Ask — na urządzeniu

Podsumowania, odpowiedzi i szkice wiadomości tworzy model językowy wbudowany w iOS (Apple Foundation Models), uruchamiany na Twoim iPhonie. Ask — pytania zadawane o Twoją pocztę — potrafi też przeszukać tekst rozpoznany na zdjęciach i skanach (OCR, czyli rozpoznawanie tekstu na obrazie, wykonywane przez wbudowaną w iOS usługę Apple Vision), tekst dokumentów DOCX, arkuszy XLSX i prezentacji PPTX oraz szukać według znaczenia, a nie tylko po dosłownych słowach. Do wyszukiwania według znaczenia aplikacja tworzy na iPhonie indeks: zapis sensu fragmentów wiadomości w postaci liczb (tzw. wektorów). Indeks zawiera same liczby, bez treści wiadomości; leży w osobnym pliku aplikacji na urządzeniu, nie trafia do kopii zapasowej iCloud, a rozmowy usunięte ze skrzynki wypadają z niego przy kolejnym przebiegu. Plik znika razem z aplikacją. Gdy Ask potrzebuje starszych wiadomości z konta Microsoft, pobiera je bezpośrednio od Microsoft (Microsoft Graph), tak jak przy zwykłej synchronizacji.

Treść wiadomości, załączniki i adresy nie są wysyłane do żadnego zewnętrznego serwera AI ani na serwer Aorum — przetwarzanie odbywa się w całości na urządzeniu, a same obliczenia AI nie wymagają połączenia z internetem.

2.5 Powiadomienia push o poczcie Gmail (usługa serwerowa)

Natychmiastowe powiadomienia o nowej poczcie Gmail wymagają osobnej, opcjonalnej usługi serwerowej. Gdy z niej korzystasz, do serwera trafiają:

Serwer nie zapisuje treści wiadomości, adresów odbiorców ani pełnego payloadu powiadomienia w bazie danych ani w logach — dane podglądu (nadawca/temat/fragment) istnieją tylko przejściowo w pamięci procesu wysyłającego powiadomienie i w samym powiadomieniu Apple (APNs). Serwer nie czyta Twojej poczty poza tym, co potrzebne do wysłania konkretnego powiadomienia.

Baza danych serwera (Firestore) przechowuje techniczne rekordy rejestracji: adres konta Gmail, token APNs, środowisko (produkcja/sandbox), identyfikator aplikacji, techniczny identyfikator konta, znacznik czasu i termin wygaśnięcia rejestracji oraz Twoje ustawienia polityki powiadomień. Listy nadawców i domen z „dopasowania kontaktów” są przechowywane jako skróty kryptograficzne, nie jako czytelne adresy: po aktualizacji serwera jako HMAC-SHA-256 z kluczem właściwym dla konta, którego nie ma w bazie danych, a do tego czasu jako zwykłe skróty SHA-256. Żeby nie wysłać dwa razy tego samego powiadomienia, serwer zapisuje też techniczne znaczniki postępu synchronizacji Gmaila — numer ostatniej przetworzonej zmiany w skrzynce, powiązany ze skrótem kryptograficznym adresu, a nie z samym adresem.

Usługa działa w Google Cloud (Cloud Run i baza Firestore) w regionie europe-central2 (Warszawa). Powiadomienie dostarcza na Twój iPhone usługa Apple Push Notification service (APNs); token urządzenia i treść powiadomienia trafiają do infrastruktury Apple, także poza Europejskim Obszarem Gospodarczym.

2.6 Wysyłka zaplanowana z serwera (usługa serwerowa)

Ta funkcja jest opcjonalna. Włączasz ją osobno dla każdego konta (ustawienia konta, zakładka Server), po zgodzie w osobnym oknie. Dzięki niej wiadomość zaplanowana na później wychodzi o czasie, nawet gdy telefon jest wyłączony albo bez zasięgu. Bez tej zgody wiadomość z terminem czeka na telefonie i wysyła ją aplikacja.

Gdzie czeka wiadomość. Aplikacja zapisuje ją jako szkic w Twojej własnej skrzynce (Gmail, Outlook albo folder szkiców na serwerze IMAP). Nie kopiujemy jej treści na nasz serwer. W wyznaczonym czasie serwer odczytuje ten szkic u Twojego dostawcy i wysyła go przez dostawcę (Gmail API, Microsoft Graph albo SMTP). Treść może przy tym przejściowo znaleźć się w pamięci procesu wysyłającego — przy iCloud i IMAP zawsze, bo serwer sam przekazuje ją do serwera SMTP — ale serwer nie zapisuje jej w bazie danych ani w logach.

Co zapisuje serwer:

Logi serwera zawierają tylko wybrane pola techniczne — bez adresów e-mail i bez tokenów. Usługa działa w tym samym miejscu co powiadomienia: Google Cloud (Cloud Run i baza Firestore), region europe-central2 (Warszawa); Google Cloud przetwarza te dane w naszym imieniu jako podmiot przetwarzający. Nie przekazujemy ich nikomu innemu.

Jak długo. Poświadczenie — do cofnięcia autoryzacji w ustawieniach konta, usunięcia konta w aplikacji albo użycia „Usuń moje dane z serwera”. Zadanie w toku — do wysłania albo anulowania wiadomości. Po wysłaniu lub anulowaniu zostaje krótki rekord zadania (identyfikatory, termin, wynik; bez treści), który chroni przed wysłaniem tej samej wiadomości dwa razy; nie ma on z góry ustalonego terminu usunięcia — usuniemy go na Twoją prośbę wysłaną na support@aorum.app. Dopóki na serwerze czekają Twoje zaplanowane wiadomości, aplikacja nie pozwoli użyć „Usuń moje dane z serwera” — najpierw je anuluj.

Dokładność. Serwer wysyła wiadomość z dokładnością do około minuty. Jeśli nie wiadomo, czy dostawca przyjął wiadomość, serwer nie wysyła jej drugi raz, a aplikacja pokazuje jej stan.

Podstawa prawna: art. 6 ust. 1 lit. b RODO — usługa, o którą prosisz. Włączenie jest dobrowolne, a wyłączyć funkcję możesz w każdej chwili.

2.7 Ustawienia i stan aplikacji w Twoim iCloud

Opcjonalnie możesz włączyć „Aorum Mail iCloud sync” (Ustawienia → Profile). Wtedy aplikacja zapisuje część swojego stanu, osobno dla każdego profilu, w Twojej prywatnej bazie iCloud (usługa Apple CloudKit), dzięki czemu ten stan jest dostępny na Twoich urządzeniach zalogowanych do tego samego konta Apple.

Podstawa prawna: art. 6 ust. 1 lit. b RODO.

2.8 Wspólne szkice i komentarze (udostępnianie iCloud)

Szkic wiadomości — albo kopię tekstu rozmowy („Discuss with team”) — możesz udostępnić do komentowania wybranym osobom przez systemowy arkusz udostępniania iCloud; zapraszasz je adresem konta Apple, adresem e-mail albo numerem telefonu (tylko zaproszone osoby, bez publicznego linku). Kopia i komentarze są zapisane w prywatnym iCloud właściciela szkicu, czyli osoby, która go udostępniła, i zaszyfrowane tak, że Apple nie widzi tematu, treści, adresów ani komentarzy.

2.9 Potwierdzenia przeczytania

Wysyłając wiadomość, możesz poprosić o potwierdzenie przeczytania. To standardowy mechanizm poczty (MDN, norma RFC 8098): aplikacja dodaje do wiadomości nagłówek z Twoim adresem, a program odbiorcy decyduje — zwykle pytając odbiorcę — czy odeśle potwierdzenie. Nic nie dzieje się bez wiedzy odbiorcy.

Gdy ktoś prosi o potwierdzenie Ciebie, aplikacja nie wysyła go bez Twojej decyzji — pyta albo postępuje zgodnie z ustawieniem, które sam/a wybierzesz. Potwierdzenie to krótki e-mail wysłany z Twojego konta, przez Twojego dostawcę poczty, do osoby, która o nie prosiła. Zawiera identyfikator oryginalnej wiadomości, Twój adres i informację, że wiadomość została wyświetlona; jak każdy e-mail ma datę wysłania.

Status „przeczytane” przy Twojej wysłanej wiadomości pojawia się po nadejściu potwierdzenia i jest zapisany na telefonie. Serwer Aorum w tym nie uczestniczy. Aplikacja nie używa pikseli śledzących (punkt 4).

2.10 Duże załączniki jako link (Dysk Google, OneDrive)

Gdy plik jest za duży dla Twojego dostawcy poczty albo gdy sam/a tak wybierzesz, aplikacja może wysłać go jako link. Plik trafia prosto z iPhone'a na Twój Dysk Google albo Twój OneDrive — nie przez serwer Aorum. Aplikacja tworzy link udostępniania i wstawia go do wiadomości.

Google i Microsoft przechowują te pliki jako dostawcy Twoich własnych usług, na swoich warunkach; nie są naszymi podmiotami przetwarzającymi, a Vansa nie ma dostępu do tych plików. Podstawa prawna: art. 6 ust. 1 lit. b RODO.

2.11 Szyfrowanie i podpis OpenPGP i S/MIME

Wiadomości możesz szyfrować i podpisywać w standardzie OpenPGP (RFC 9580, PGP/MIME według RFC 3156). Szyfrowanie, odszyfrowanie, podpis i sprawdzanie podpisu odbywają się na iPhonie, przy użyciu bibliotek kryptograficznych Apple i standardowych algorytmów. Szyfrowane są tylko wiadomości, które sam/a zaszyfrujesz — pozostała poczta jest przesyłana tak jak zwykle.

2.12 Uczący się podział skrzynki i Gatekeeper

Aplikacja może dzielić skrzynkę na kategorie i uczyć się tego podziału z Twoich działań (przeniesień, oznaczeń, decyzji). Gatekeeper (domyślnie wyłączony, włączasz go sam/a) odkłada nową pocztę od nadawców, do których nigdy nie pisałeś/aś i których nie ma w kontaktach, do osobnego filtra „New senders”, gdzie decydujesz: przyjąć, przenieść czy zablokować. Model, statystyki i decyzje są zapisane w pliku aplikacji na iPhonie (nie synchronizują się przez iCloud); nie trafiają na serwer Aorum ani do zewnętrznego AI.

2.13 Dane z usług Google

Aplikacja korzysta z interfejsów API Google: Gmaila (Twoja poczta, a gdy je włączysz — powiadomienia i wysyłka zaplanowana z serwera), kontaktów Google (gdy włączysz synchronizację kontaktów) i Dysku Google (duże załączniki jako link). Dane z tych interfejsów służą wyłącznie funkcjom opisanym w tej polityce; nie używamy ich do reklam i ich nie sprzedajemy.

Korzystanie przez Aorum Mail z informacji otrzymanych z interfejsów API Google i ich przekazywanie innym aplikacjom jest zgodne z zasadami Google API Services User Data Policy, w tym z wymaganiami ograniczonego użycia (Limited Use).

2.14 Powiadomienia o nowej poczcie Outlook, Microsoft 365, iCloud i IMAP (usługa serwerowa)

Ta funkcja jest opcjonalna. Włączasz ją osobno dla każdego konta Outlook, Microsoft 365, iCloud albo IMAP (ustawienia konta, zakładka Server, przełącznik „Serwerowe powiadomienia o poczcie”), po zgodzie w osobnym oknie. Dzięki niej aplikacja dowiaduje się o nowej poczcie w folderze Odebrane, gdy działa w tle. Bez niej te skrzynki aplikacja sprawdza sama, gdy iOS ją wybudzi.

Jak działa. Przy kontach Microsoft serwer zakłada w Microsoft Graph subskrypcję zmian folderu Odebrane (bez treści wiadomości) i odnawia ją co około trzy dni; Microsoft zgłasza serwerowi tylko, że pojawiła się nowa wiadomość. Przy iCloud i IMAP serwer mniej więcej raz na minutę loguje się do skrzynki i odczytuje wyłącznie dwa liczniki folderu Odebrane (UIDVALIDITY i UIDNEXT). Serwer nigdy nie pobiera treści, tematów, nadawców, adresatów ani załączników. Gdy przyjdzie nowa poczta, wysyła na iPhone'a przez Apple (APNs) cichy sygnał bez żadnej treści — tylko identyfikator monitora i zdarzenia. Aplikacja sama pobiera wtedy pocztę od dostawcy i na telefonie stosuje Twoje ustawienia powiadomień: wyciszonych i zablokowanych nadawców, typy Priorytetowe i Inteligentne oraz Gatekeepera. iOS może opóźnić taki sygnał i nie budzi aplikacji zamkniętej przesunięciem w górę.

Co zapisuje serwer:

Jak długo. Poświadczenia — do wyłączenia przełącznika, odłączenia konta albo użycia „Usuń moje dane z serwera”; wtedy serwer kasuje je od razu. Jeśli sygnały nie mogą już dotrzeć do Twojego iPhone'a (Apple zgłosi nieważny token, np. po usunięciu aplikacji) albo skrzynka jest nieosiągalna przez 72 godziny (np. po zmianie hasła), serwer przestaje ją sprawdzać, a po kolejnych 14 dniach kasuje monitor razem z poświadczeniami, chyba że aplikacja wcześniej go odnowi. Po usunięciu zostaje przez 30 dni tylko skrót tokenu zarządzania (żeby ponowione żądanie usunięcia dostało poprawną odpowiedź) i licznik monitorów danej skrzynki (skrót tożsamości i liczba).

Logi serwera zawierają tylko identyfikator monitora, nazwę dostawcy i kod błędu — bez adresów, loginów, haseł i tokenów. Usługa działa w Google Cloud (Cloud Run i baza Firestore) w regionie europe-central2 (Warszawa); Google Cloud przetwarza te dane w naszym imieniu jako podmiot przetwarzający. Microsoft przy subskrypcji zna adres naszego serwera, na który wysyła zgłoszenia.

Podstawa prawna: Twoja zgoda wyrażona w oknie zgody przy włączaniu funkcji (art. 6 ust. 1 lit. a RODO); cofasz ją, wyłączając przełącznik.

2.15 Czego nie ma w wersji 1.0

W wersji 1.0 nie ma: AI w chmurze ani płatnych subskrypcji i zakupów w aplikacji. Nie przetwarzamy w związku z nimi żadnych danych. Zanim którąś z tych funkcji włączymy, zaktualizujemy tę politykę.

3. Cel i podstawa prawna przetwarzania

Zgodę możesz cofnąć w każdej chwili, wyłączając daną funkcję; nie wpływa to na zgodność z prawem przetwarzania sprzed jej cofnięcia. Z funkcji opartych na umowie możesz zrezygnować w dowolnym momencie, wyłączając je w aplikacji.

4. Czego nie robimy

Nie sprzedajemy ani nie udostępniamy Twoich danych podmiotom trzecim w celach marketingowych. Nie prowadzimy trackingu reklamowego ani profilowania między aplikacjami. Nie zbieramy statystyk użycia aplikacji. Nie czytamy automatycznie treści Twojej poczty do żadnych własnych celów poza dostarczeniem funkcji, o które prosisz (np. podgląd w powiadomieniu). Nie mamy dostępu do Twoich danych w iCloud, na Dysku Google ani w OneDrive.

Aplikacja chroni Cię też przed śledzeniem ukrytym w samej wiadomości: piksele śledzące (niewidoczne obrazki 1×1, którymi nadawcy sprawdzają, czy i kiedy otworzyłeś/aś wiadomość) są usuwane zawsze, a pozostałe zdalne obrazy w treści wiadomości są domyślnie zablokowane, dopóki nie zaufasz danemu nadawcy. Sama aplikacja nigdy nie dodaje pikseli śledzących do wysyłanych wiadomości. Potwierdzenia przeczytania (punkt 2.9) to coś innego: standardowy, widoczny mechanizm poczty, w którym odbiorca widzi prośbę i sam decyduje, czy odpowiedzieć.

5. Jak długo przechowujemy dane

6. Jak usunąć swoje dane

W Ustawieniach aplikacji, w szczegółach konta, możesz odłączyć dowolne konto pocztowe (Disconnect) — usuwa to lokalną kopię jego poczty z telefonu i wysyła do serwera powiadomień żądanie wyrejestrowania tokenu urządzenia dla tego konta (rejestracja jest usuwana z bazy serwera). W tych samych ustawieniach konta, w zakładce Server, możesz cofnąć autoryzację wysyłki z serwera i wyłączyć serwerowe powiadomienia o poczcie — serwer usuwa wtedy zapisane poświadczenie tego konta i jego monitor. Odłączenie konta Outlook, Microsoft 365, iCloud albo IMAP robi to samo przed usunięciem poczty z telefonu.

W Ustawienia → Bezpieczeństwo → Dane na serwerze przycisk „Usuń moje dane z serwera” usuwa wszystko, co serwer przechowuje dla kont z tego iPhone'a: rejestracje urządzenia z ustawieniami powiadomień, autoryzacje serwerowe kont i monitory poczty; potem aplikacja nie rejestruje się ponownie, dopóki sama nie włączysz powiadomień przez serwer. Jeśli na serwerze czekają Twoje zaplanowane wiadomości, najpierw je anuluj — do tego czasu aplikacja odmówi usunięcia danych, żeby nie zgubić wiadomości, które mają wyjść. Usunięcie samej aplikacji z telefonu usuwa tylko dane zapisane na telefonie — danych na serwerze nie, dlatego najpierw użyj tego przycisku.

Stan aplikacji w iCloud usuniesz przyciskiem „Delete iCloud data” (Ustawienia → Profile → iCloud) albo w Ustawieniach iOS (Twoje konto Apple → iCloud → zarządzanie pamięcią). Udostępnianie szkicu możesz zakończyć w każdej chwili, a pliki wysłane jako link usuniesz na Dysku Google albo w OneDrive. Możesz też napisać na adres support@aorum.app z prośbą o informację, jakie dane serwerowe są z Tobą powiązane, oraz o ich usunięcie.

7. Odbiorcy danych

Nie przekazujemy danych innym firmom; serwer nie używa narzędzi analitycznych ani reklamowych.

8. Prawa użytkownika

Zgodnie z RODO masz prawo do: dostępu do swoich danych, ich sprostowania, usunięcia, ograniczenia przetwarzania, przenoszenia danych oraz sprzeciwu wobec przetwarzania. Możesz też cofnąć zgodę na dowolną funkcję w dowolnym momencie w Ustawieniach aplikacji lub iOS. Masz prawo wniesienia skargi do Prezesa Urzędu Ochrony Danych Osobowych (UODO).

9. Zmiany polityki

Możemy aktualizować tę politykę wraz z rozwojem aplikacji. Datę ostatniej zmiany znajdziesz na górze strony. Istotne zmiany zakresu przetwarzania ogłosimy w aplikacji.

10. Kontakt

W sprawach związanych z ochroną danych osobowych pisz na support@aorum.app.

Privacy Policy — Aorum Mail

Last updated: 2026-09-29 · Data controller: Vansa Sp. z o.o., ul. Jana Smolenia 14, 30-864 Kraków (KRS 0000675425, NIP 6793148076) · Contact: support@aorum.app · Site: aorum.app

In short: Aorum Mail keeps your mail and contacts on your iPhone. We have no server that keeps a copy of your mailbox. In version 1.0 our server runs only two optional services that you turn on yourself: instant notifications for new Gmail messages, and sending scheduled messages from the server, even while your phone is off. Features built on iCloud, Google Drive and OneDrive store data in your own accounts with those services — we have no access to them. The AI assistant, meaning-based search and the learning inbox split run only on your iPhone. We do not sell your data and we do not run advertising tracking.

1. Data controller

The data controller within the meaning of GDPR is Vansa Sp. z o.o., ul. Jana Smolenia 14, 30-864 Kraków (KRS 0000675425, NIP 6793148076). Contact for data-protection matters: support@aorum.app.

2. What data the app processes

2.1 Mail and contacts — on the device

Messages, attachments, drafts, notes about people, saved searches, settings and the search index are written to the app's own database on your iPhone. A message scheduled for later waits on the phone and the app itself sends it — unless you turn on sending from the server for that account (section 2.6); then it waits as a draft in your own mailbox with your mail provider. Aorum Mail has no server of its own holding a copy of your mailbox.

2.2 Mail accounts (Gmail, Microsoft, IMAP)

To show your mail, the app signs you in directly with your provider — Google, Microsoft, Apple, or the IMAP server you name. For Gmail and Microsoft you sign in on the provider's own page (OAuth), so the app never sees your password — it only receives an access token. For iCloud and IMAP you supply the server details and a password (usually an app password). Tokens and passwords are kept in the iOS Keychain, never in ordinary files, and the app uses them to connect to your mailbox. They leave the phone only if you turn on scheduled sending from the server (section 2.6) or server mail notifications for Outlook, Microsoft 365, iCloud and IMAP (section 2.14) for an account and agree to it in a separate consent window — the server then receives the credential that feature needs. Each provider handles your mail under its own privacy policy.

2.3 Contacts

With your permission, the app can read the iPhone address book and — if you turn on contact sync for a Gmail account (off by default) — the contacts of that Google account, so a sender arrives with a name and photo rather than a bare address. A phone-number type you change in the app is written back to your Google contacts. Address-book access can be withdrawn in iOS Settings and Google sync in the account settings in the app; the data read stays on the device. The exception is optional "contact matching" for Gmail notifications (section 2.5) — only if you turn it on does the server receive one-way codes of addresses, never the addresses themselves.

2.4 AI assistant and Ask — on the device

Summaries, answers and drafts are produced by the language model built into iOS (Apple Foundation Models), running on your iPhone. Ask — the questions you ask about your mail — can also search text recognised in photos and scans (OCR, meaning reading text from an image, done by Apple's built-in Vision service), the text of DOCX documents, XLSX spreadsheets and PPTX presentations, and search by meaning rather than only by exact words. For meaning-based search the app builds an index on your iPhone: a record of what passages of your messages are about, stored as numbers (so-called vectors). The index holds only numbers, no message text; it lives in a separate app file on the device, is not included in iCloud backup, and conversations deleted from the mailbox drop out of it on the next pass. The file is removed together with the app. When Ask needs older messages from a Microsoft account, it fetches them directly from Microsoft (Microsoft Graph), just like regular sync.

Message content, attachments and addresses are not sent to any external AI server or to the Aorum server — processing happens entirely on the device, and the AI computations themselves do not need an internet connection.

2.5 Push notifications for Gmail (server service)

Instant notifications for new Gmail messages require a separate, optional server service. When you use it, the following reaches the server:

The server does not store message content, recipient addresses, or the full notification payload in its database or logs — preview data (sender/subject/snippet) exists only transiently in the memory of the process sending the notification and in the Apple push notification itself. The server does not read your mail beyond what is needed to send that one notification.

The server database (Firestore) stores technical registration records: the Gmail account address, the APNs token, environment (production/sandbox), app identifier, a technical account identifier, registration timestamps and expiry, and your notification-policy settings. The sender and domain lists from "contact matching" are stored as cryptographic hashes, not as readable addresses: once the server is updated, as HMAC-SHA-256 with a per-account key that is not kept in the database, and until then as plain SHA-256 hashes. To avoid sending the same notification twice, the server also keeps technical Gmail sync markers — the number of the last mailbox change it processed, tied to a cryptographic hash of the address rather than the address itself.

The service runs on Google Cloud (Cloud Run and the Firestore database) in the europe-central2 region (Warsaw). Notifications reach your iPhone through the Apple Push Notification service (APNs); the device token and the notification content pass through Apple's infrastructure, including outside the European Economic Area.

2.6 Scheduled sending from the server (server service)

This feature is optional. You turn it on separately for each account (account settings, Server tab), after agreeing in a separate consent window. With it, a message scheduled for later goes out on time even when your phone is off or has no signal. Without that consent, a scheduled message waits on the phone and the app sends it.

Where the message waits. The app saves it as a draft in your own mailbox (Gmail, Outlook, or the drafts folder on your IMAP server). We do not copy its content to our server. At the scheduled time the server reads that draft from your provider and sends it through the provider (Gmail API, Microsoft Graph or SMTP). The content may pass transiently through the memory of the sending process — always for iCloud and IMAP, because the server itself hands it to the SMTP server — but the server does not store it in its database or logs.

What the server stores:

Server logs contain only selected technical fields — no email addresses and no tokens. The service runs in the same place as notifications: Google Cloud (Cloud Run and the Firestore database), europe-central2 region (Warsaw); Google Cloud processes this data on our behalf as a data processor. We do not pass it to anyone else.

How long. The credential — until you revoke the authorization in the account settings, remove the account in the app, or use "Delete my data from server". A job in progress — until the message is sent or cancelled. Once a message is sent or cancelled, a short job record remains (identifiers, scheduled time, result; no content) that protects against sending the same message twice; it has no fixed deletion date — we will delete it on request sent to support@aorum.app. While scheduled messages are waiting on the server, the app will not let you use "Delete my data from server" — cancel them first.

Accuracy. The server sends a message to within about a minute. If it is uncertain whether the provider accepted a message, the server does not send it a second time, and the app shows its status.

Legal basis: Art. 6(1)(b) GDPR — a service you ask for. Turning it on is voluntary, and you can turn it off at any time.

2.7 Settings and app state in your iCloud

You can optionally turn on "Aorum Mail iCloud sync" (Settings → Profile). The app then stores part of its state, separately for each profile, in your private iCloud database (Apple's CloudKit service), so that this state is available on your devices signed in to the same Apple Account.

Legal basis: Art. 6(1)(b) GDPR.

2.8 Shared drafts and comments (iCloud sharing)

You can share a draft — or a copy of a conversation's text ("Discuss with team") — for comments with people you choose through the system iCloud share sheet; you invite them by Apple Account, email address or phone number (invited people only, no public link). The copy and the comments are stored in the private iCloud of the draft's owner, meaning the person who shared it, and are encrypted so that Apple cannot see the subject, text, addresses or comments.

2.9 Read receipts

When you send a message, you can ask for a read receipt. This is a standard mail mechanism (MDN, standard RFC 8098): the app adds a header with your address to the message, and the recipient's mail program decides — usually by asking the recipient — whether to send a receipt back. Nothing happens without the recipient knowing.

When someone asks you for a receipt, the app does not send one without your decision — it asks you, or follows the setting you choose yourself. A receipt is a short email sent from your account, through your mail provider, to the person who asked for it. It contains the identifier of the original message, your address and a note that the message was displayed; like any email, it carries the date it was sent.

The "read" status on a message you sent appears once a receipt arrives and is stored on the phone. The Aorum server takes no part in this. The app does not use tracking pixels (section 4).

2.10 Large attachments as links (Google Drive, OneDrive)

When a file is too large for your mail provider, or when you choose to, the app can send it as a link. The file goes straight from your iPhone to your Google Drive or your OneDrive — not through the Aorum server. The app creates a sharing link and puts it in the message.

Google and Microsoft store these files as providers of your own services, under their own terms; they are not our data processors, and Vansa has no access to these files. Legal basis: Art. 6(1)(b) GDPR.

2.11 OpenPGP and S/MIME encryption and signing

You can encrypt and sign messages with the OpenPGP standard (RFC 9580, PGP/MIME under RFC 3156). Encryption, decryption, signing and signature checks happen on your iPhone, using Apple's cryptographic libraries and standard algorithms. Only the messages you choose to encrypt are encrypted — the rest of your mail travels as usual.

2.12 Learning inbox split and Gatekeeper

The app can split your inbox into categories and learn that split from what you do (moves, flags, decisions). Gatekeeper (off by default, you turn it on yourself) sets aside new mail from senders you have never written to and who are not in your contacts in a separate "New senders" filter, where you decide: accept, move or block. The model, statistics and decisions are stored in an app file on your iPhone (they are not synced through iCloud); they do not go to the Aorum server or to any external AI.

2.13 Data from Google services

The app uses Google APIs: Gmail (your mail and — when you turn them on — notifications and scheduled sending from the server), Google contacts (when you turn on contact sync) and Google Drive (large attachments as links). Data from these APIs is used only for the features described in this policy; we do not use it for advertising and we do not sell it.

Aorum Mail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2.14 New mail notifications for Outlook, Microsoft 365, iCloud and IMAP (server service)

This feature is optional. You turn it on separately for each Outlook, Microsoft 365, iCloud or IMAP account (account settings, Server tab, the "Server mail notifications" switch), after agreeing in a separate consent window. It lets the app learn about new mail in the Inbox while it runs in the background. Without it, the app checks those mailboxes itself when iOS wakes it up.

How it works. For Microsoft accounts the server creates a Microsoft Graph subscription to changes in the Inbox (without message content) and renews it about every three days; Microsoft only tells the server that a new message has appeared. For iCloud and IMAP the server signs in to the mailbox about once a minute and reads only two Inbox counters (UIDVALIDITY and UIDNEXT). The server never downloads message text, subjects, senders, recipients or attachments. When new mail arrives it sends your iPhone a silent signal through Apple (APNs) with no content — only a monitor and event identifier. The app then fetches the mail from your provider itself and applies your notification settings on the phone: muted and blocked senders, the Priority and Smart types, and Gatekeeper. iOS may delay such a signal and does not wake an app you have swiped away.

What the server stores:

How long. Credentials — until you turn the switch off, disconnect the account or use "Delete my data from server"; the server then deletes them at once. If signals can no longer reach your iPhone (Apple reports an invalid token, e.g. after the app was removed) or the mailbox stays unreachable for 72 hours (e.g. after a password change), the server stops checking it and, 14 days later, deletes the monitor with its credentials unless the app renews it first. After deletion, only a hash of the management token (so that a repeated deletion request gets the right answer) and the per-mailbox monitor counter (identity hash and a number) remain for 30 days.

Server logs contain only the monitor identifier, the provider name and an error code — no addresses, logins, passwords or tokens. The service runs on Google Cloud (Cloud Run and Firestore) in the europe-central2 region (Warsaw); Google Cloud processes this data on our behalf as a processor. For the subscription, Microsoft knows the address of our server to which it sends its reports.

Legal basis: the consent you give in the consent window when you turn the feature on (Art. 6(1)(a) GDPR); you withdraw it by turning the switch off.

2.15 What is not in version 1.0

Version 1.0 does not include cloud AI, or paid subscriptions and in-app purchases. We process no data for them. Before we turn any of these features on, we will update this policy.

3. Purpose and legal basis of processing

You can withdraw consent at any time by turning the feature off; this does not affect the lawfulness of processing before withdrawal. You can stop using contract-based features at any time by turning them off in the app.

4. What we do not do

We do not sell or share your data with third parties for marketing purposes. We do not run advertising tracking or cross-app profiling. We do not collect app usage statistics. We do not automatically read the content of your mail for any purpose of our own beyond delivering the feature you asked for (e.g. a notification preview). We have no access to your data in iCloud, Google Drive or OneDrive.

The app also protects you from tracking hidden inside messages themselves: tracking pixels (invisible 1×1 images senders use to check if and when you opened a message) are always removed, and other remote images in a message's content are blocked by default until you trust that sender. The app itself never adds tracking pixels to the messages you send. Read receipts (section 2.9) are something different: a standard, visible mail mechanism in which the recipient sees the request and decides whether to answer.

5. How long we keep data

6. How to delete your data

In the app's Settings, under an account's details, you can disconnect any mail account — this removes its local mail copy from the phone and sends the push-notification server a request to unregister that account's device token (the registration is removed from the server database). In the same account settings, on the Server tab, you can revoke the authorization for sending from the server and turn off server mail notifications — the server then deletes that account's stored credential and its monitor. Disconnecting an Outlook, Microsoft 365, iCloud or IMAP account does the same before removing its mail from the phone.

In Settings → Security → Server data, "Delete my data from server" deletes everything the server keeps for the accounts on this iPhone: device registrations with notification settings, the accounts' server authorizations and mail monitors; after that the app does not register again until you turn server notifications back on yourself. If scheduled messages are waiting on the server, cancel them first — until then the app refuses to delete the data, so that messages due to go out are not lost. Removing the app itself deletes only what it kept on the phone, not data on the server — use that button first.

You delete the app's state in iCloud with "Delete iCloud data" (Settings → Profile → iCloud) or in iOS Settings (your Apple Account → iCloud → storage management). You can stop sharing a draft at any time, and you delete files sent as links in Google Drive or OneDrive. You can also write to support@aorum.app to ask what server-side data is linked to you, and to have it deleted.

7. Who receives the data

We do not pass data to any other company; the server uses no analytics or advertising tools.

8. Your rights

Under GDPR you have the right to access your data, have it corrected, deleted, have its processing restricted, request data portability, and object to processing. You can also withdraw consent for any feature at any time in the app's or iOS's Settings. You have the right to lodge a complaint with your national data-protection authority.

9. Changes to this policy

We may update this policy as the app evolves. The date of the last change is shown at the top of the page. Material changes to the scope of processing will be announced in the app.

10. Contact

For data-protection matters, write to support@aorum.app.