Polityka prywatności — Aorum Mail
W skrócie: Aorum Mail trzyma Twoją pocztę i kontakty na Twoim iPhonie. Nie mamy serwera, który przechowywałby kopię Twojej skrzynki. W wersji 1.0 nasz serwer obsługuje tylko dwie opcjonalne usługi, które włączasz sam/a: natychmiastowe powiadomienia o nowej poczcie Gmail oraz wysyłkę zaplanowanych wiadomości z serwera, także gdy telefon jest wyłączony. Funkcje oparte na iCloud, Dysku Google i OneDrive zapisują dane na Twoich własnych kontach w tych usługach — nie mamy do nich dostępu. Asystent AI, wyszukiwanie według znaczenia i uczący się podział skrzynki działają wyłącznie na iPhonie. Nie sprzedajemy danych i nie prowadzimy śledzenia reklamowego.
1. Administrator danych
Administratorem danych w rozumieniu RODO jest Vansa Sp. z o.o., ul. Jana Smolenia 14, 30-864 Kraków (KRS 0000675425, NIP 6793148076). Kontakt w sprawach ochrony danych: support@aorum.app.
2. Jakie dane przetwarza aplikacja
2.1 Poczta i kontakty — na urządzeniu
Wiadomości, załączniki, szkice, notatki o osobach, zapisane wyszukiwania, ustawienia i indeks wyszukiwania są zapisywane w bazie danych aplikacji na Twoim iPhonie. Wiadomość zaplanowana na później czeka na telefonie i wysyła ją sama aplikacja — chyba że dla danego konta włączysz wysyłkę z serwera (punkt 2.6); wtedy czeka jako szkic w Twojej własnej skrzynce u dostawcy poczty. Aorum Mail nie ma własnego serwera, który trzymałby kopię Twojej skrzynki.
2.2 Konta pocztowe (Gmail, Microsoft, IMAP)
Aby pokazać Twoją pocztę, aplikacja loguje Cię bezpośrednio u dostawcy — Google, Microsoft, Apple albo wskazanego serwera IMAP. Przy Gmailu i Microsoft logujesz się na stronie dostawcy (OAuth), więc aplikacja nie poznaje Twojego hasła — dostaje tylko token dostępu. Przy iCloud i IMAP podajesz dane serwera i hasło (zwykle hasło aplikacji). Tokeny i hasła trzyma pęk kluczy iOS (Keychain), nigdy zwykłe pliki, a aplikacja używa ich do łączenia się z Twoją skrzynką. Opuszczają telefon tylko wtedy, gdy dla danego konta włączysz wysyłkę zaplanowaną z serwera (punkt 2.6) albo serwerowe powiadomienia o poczcie Outlook, Microsoft 365, iCloud i IMAP (punkt 2.14) i zgodzisz się na to w osobnym oknie — wtedy serwer dostaje poświadczenie potrzebne do tej funkcji. Każdy dostawca przetwarza Twoją pocztę zgodnie z własną polityką prywatności.
2.3 Kontakty
Za Twoją zgodą aplikacja może odczytać książkę adresową iPhone'a, a jeśli włączysz synchronizację kontaktów dla konta Gmail (domyślnie wyłączona) — także kontakty tego konta Google, żeby pokazać nadawcę z imieniem i zdjęciem zamiast samego adresu. Zmiana typu numeru telefonu wybrana w aplikacji jest zapisywana z powrotem w Twoich kontaktach Google. Zgodę na książkę adresową cofasz w Ustawieniach systemowych iOS, a synchronizację z Google — w ustawieniach konta w aplikacji; odczytane dane zostają na urządzeniu. Wyjątek to opcjonalne „dopasowanie kontaktów” dla powiadomień Gmail (punkt 2.5) — tylko gdy je włączysz, serwer dostaje jednokierunkowe skróty adresów, nigdy same adresy.
2.4 Asystent AI i Ask — na urządzeniu
Podsumowania, odpowiedzi i szkice wiadomości tworzy model językowy wbudowany w iOS (Apple Foundation Models), uruchamiany na Twoim iPhonie. Ask — pytania zadawane o Twoją pocztę — potrafi też przeszukać tekst rozpoznany na zdjęciach i skanach (OCR, czyli rozpoznawanie tekstu na obrazie, wykonywane przez wbudowaną w iOS usługę Apple Vision), tekst dokumentów DOCX, arkuszy XLSX i prezentacji PPTX oraz szukać według znaczenia, a nie tylko po dosłownych słowach. Do wyszukiwania według znaczenia aplikacja tworzy na iPhonie indeks: zapis sensu fragmentów wiadomości w postaci liczb (tzw. wektorów). Indeks zawiera same liczby, bez treści wiadomości; leży w osobnym pliku aplikacji na urządzeniu, nie trafia do kopii zapasowej iCloud, a rozmowy usunięte ze skrzynki wypadają z niego przy kolejnym przebiegu. Plik znika razem z aplikacją. Gdy Ask potrzebuje starszych wiadomości z konta Microsoft, pobiera je bezpośrednio od Microsoft (Microsoft Graph), tak jak przy zwykłej synchronizacji.
Treść wiadomości, załączniki i adresy nie są wysyłane do żadnego zewnętrznego serwera AI ani na serwer Aorum — przetwarzanie odbywa się w całości na urządzeniu, a same obliczenia AI nie wymagają połączenia z internetem.
2.5 Powiadomienia push o poczcie Gmail (usługa serwerowa)
Natychmiastowe powiadomienia o nowej poczcie Gmail wymagają osobnej, opcjonalnej usługi serwerowej. Gdy z niej korzystasz, do serwera trafiają:
- zweryfikowany adres e-mail Twojego konta Gmail (przez token logowania Google), używany jako identyfikator rejestracji;
- token urządzenia APNs (identyfikator służący Apple do dostarczenia powiadomienia na Twój iPhone);
- techniczny identyfikator konta i profilu w aplikacji oraz migawka Twoich ustawień powiadomień (tryb, dźwięk, poziom podglądu, blokada Face ID, wyciszone i odłożone wątki);
- tylko gdy włączysz w Ustawienia → Aplikacja → Powiadomienia opcję „dopasowanie kontaktów” (osobna zgoda, domyślnie wyłączona): jednokierunkowe skróty adresów z list potrzebnych wybranemu typowi powiadomień — wyciszeni i zablokowani nadawcy (wszystkie typy), ulubieni (Priorytetowe i Inteligentne) oraz wszystkie kontakty (Inteligentne). Nigdy same adresy. Wyłączenie opcji albo wybór „Bez powiadomień” usuwa te listy z serwera przy najbliższym potwierdzeniu ustawień;
- przejściowo, wyłącznie na czas dostarczenia jednego powiadomienia: nadawca, temat, etykiety i krótki fragment wiadomości, odczytane z Twojego konta Gmail, żeby sprawdzić je z Twoimi ustawieniami powiadomień i zbudować podgląd na wybranym przez Ciebie poziomie.
Serwer nie zapisuje treści wiadomości, adresów odbiorców ani pełnego payloadu powiadomienia w bazie danych ani w logach — dane podglądu (nadawca/temat/fragment) istnieją tylko przejściowo w pamięci procesu wysyłającego powiadomienie i w samym powiadomieniu Apple (APNs). Serwer nie czyta Twojej poczty poza tym, co potrzebne do wysłania konkretnego powiadomienia.
Baza danych serwera (Firestore) przechowuje techniczne rekordy rejestracji: adres konta Gmail, token APNs, środowisko (produkcja/sandbox), identyfikator aplikacji, techniczny identyfikator konta, znacznik czasu i termin wygaśnięcia rejestracji oraz Twoje ustawienia polityki powiadomień. Listy nadawców i domen z „dopasowania kontaktów” są przechowywane jako skróty kryptograficzne, nie jako czytelne adresy: po aktualizacji serwera jako HMAC-SHA-256 z kluczem właściwym dla konta, którego nie ma w bazie danych, a do tego czasu jako zwykłe skróty SHA-256. Żeby nie wysłać dwa razy tego samego powiadomienia, serwer zapisuje też techniczne znaczniki postępu synchronizacji Gmaila — numer ostatniej przetworzonej zmiany w skrzynce, powiązany ze skrótem kryptograficznym adresu, a nie z samym adresem.
Usługa działa w Google Cloud (Cloud Run i baza Firestore) w regionie europe-central2 (Warszawa). Powiadomienie dostarcza na Twój iPhone usługa Apple Push Notification service (APNs); token urządzenia i treść powiadomienia trafiają do infrastruktury Apple, także poza Europejskim Obszarem Gospodarczym.
2.6 Wysyłka zaplanowana z serwera (usługa serwerowa)
Ta funkcja jest opcjonalna. Włączasz ją osobno dla każdego konta (ustawienia konta, zakładka Server), po zgodzie w osobnym oknie. Dzięki niej wiadomość zaplanowana na później wychodzi o czasie, nawet gdy telefon jest wyłączony albo bez zasięgu. Bez tej zgody wiadomość z terminem czeka na telefonie i wysyła ją aplikacja.
Gdzie czeka wiadomość. Aplikacja zapisuje ją jako szkic w Twojej własnej skrzynce (Gmail, Outlook albo folder szkiców na serwerze IMAP). Nie kopiujemy jej treści na nasz serwer. W wyznaczonym czasie serwer odczytuje ten szkic u Twojego dostawcy i wysyła go przez dostawcę (Gmail API, Microsoft Graph albo SMTP). Treść może przy tym przejściowo znaleźć się w pamięci procesu wysyłającego — przy iCloud i IMAP zawsze, bo serwer sam przekazuje ją do serwera SMTP — ale serwer nie zapisuje jej w bazie danych ani w logach.
Co zapisuje serwer:
- poświadczenie konta, bez którego nie da się wysłać wiadomości w Twoim imieniu: przy Gmailu — długotrwałą autoryzację Google (tzw. refresh token), którą serwer otrzymuje od Google w zamian za jednorazowy kod przekazany przez aplikację; przy Microsoft — token odświeżania; przy iCloud i IMAP — login i hasło skrzynki (zwykle hasło aplikacji) do serwerów IMAP i SMTP. Poświadczenia są zaszyfrowane (AES-256-GCM), a klucze szyfrujące są przechowywane osobno od bazy, w usłudze Google Secret Manager;
- przy kontach Microsoft, iCloud i IMAP — adres skrzynki, której dotyczy autoryzacja, zapisany zwykłym tekstem jako opis tej autoryzacji;
- zadanie wysyłki: techniczny identyfikator właściciela, identyfikator szkicu w Twojej skrzynce, identyfikator wiadomości (Message-ID), termin, stan i wynik. Zadanie nie zawiera treści, tematu ani adresatów.
Logi serwera zawierają tylko wybrane pola techniczne — bez adresów e-mail i bez tokenów. Usługa działa w tym samym miejscu co powiadomienia: Google Cloud (Cloud Run i baza Firestore), region europe-central2 (Warszawa); Google Cloud przetwarza te dane w naszym imieniu jako podmiot przetwarzający. Nie przekazujemy ich nikomu innemu.
Jak długo. Poświadczenie — do cofnięcia autoryzacji w ustawieniach konta, usunięcia konta w aplikacji albo użycia „Usuń moje dane z serwera”. Zadanie w toku — do wysłania albo anulowania wiadomości. Po wysłaniu lub anulowaniu zostaje krótki rekord zadania (identyfikatory, termin, wynik; bez treści), który chroni przed wysłaniem tej samej wiadomości dwa razy; nie ma on z góry ustalonego terminu usunięcia — usuniemy go na Twoją prośbę wysłaną na support@aorum.app. Dopóki na serwerze czekają Twoje zaplanowane wiadomości, aplikacja nie pozwoli użyć „Usuń moje dane z serwera” — najpierw je anuluj.
Dokładność. Serwer wysyła wiadomość z dokładnością do około minuty. Jeśli nie wiadomo, czy dostawca przyjął wiadomość, serwer nie wysyła jej drugi raz, a aplikacja pokazuje jej stan.
Podstawa prawna: art. 6 ust. 1 lit. b RODO — usługa, o którą prosisz. Włączenie jest dobrowolne, a wyłączyć funkcję możesz w każdej chwili.
2.7 Ustawienia i stan aplikacji w Twoim iCloud
Opcjonalnie możesz włączyć „Aorum Mail iCloud sync” (Ustawienia → Profile). Wtedy aplikacja zapisuje część swojego stanu, osobno dla każdego profilu, w Twojej prywatnej bazie iCloud (usługa Apple CloudKit), dzięki czemu ten stan jest dostępny na Twoich urządzeniach zalogowanych do tego samego konta Apple.
- Co jest synchronizowane: przypięcia, podział skrzynki na kategorie, Later, Set aside, przypomnienia, follow-upy, wyciszenia, ulubione i wyciszone osoby, podpisy i reguły podpisów, szablony, szybkie odpowiedzi i wybrane ustawienia interfejsu. Wątki, osoby i konta są wskazane skrótami kryptograficznymi adresów i identyfikatorów, nie jawnymi adresami.
- Szyfrowanie: zanim dane opuszczą telefon, aplikacja szyfruje je (AES-GCM) kluczem przechowywanym w Twoim pęku kluczy iCloud, a nazwy rekordów zastępuje skrótami. Bez tego klucza treści rekordów nie odczyta ani Apple, ani Vansa.
- Czego nie ma w iCloud: treści poczty, tematów, załączników, kolejki wysyłki, haseł, tokenów, ustawień Face ID i ustawień prywatności urządzenia.
- Kto widzi: prywatna baza iCloud należy do Ciebie; przetwarza ją Apple na warunkach usługi iCloud. Vansa nie ma do niej dostępu, a dane nie przechodzą przez serwer Aorum.
- Jak długo: do czasu, aż je usuniesz. „Disconnect this device” (Ustawienia → Profile → iCloud) zatrzymuje synchronizację na tym urządzeniu i niczego nie usuwa. „Delete iCloud data” w tym samym miejscu usuwa stan profilu z iCloud dla wszystkich Twoich urządzeń (dane na urządzeniach zostają). Dane aplikacji w iCloud możesz też usunąć w Ustawieniach iOS (Twoje konto Apple → iCloud → zarządzanie pamięcią).
Podstawa prawna: art. 6 ust. 1 lit. b RODO.
2.8 Wspólne szkice i komentarze (udostępnianie iCloud)
Szkic wiadomości — albo kopię tekstu rozmowy („Discuss with team”) — możesz udostępnić do komentowania wybranym osobom przez systemowy arkusz udostępniania iCloud; zapraszasz je adresem konta Apple, adresem e-mail albo numerem telefonu (tylko zaproszone osoby, bez publicznego linku). Kopia i komentarze są zapisane w prywatnym iCloud właściciela szkicu, czyli osoby, która go udostępniła, i zaszyfrowane tak, że Apple nie widzi tematu, treści, adresów ani komentarzy.
- Co wychodzi z telefonu: dokładnie to, co pokazuje ekran udostępniania — temat, tekst, nazwy załączników (same pliki zostają na iPhonie) i adresaci tylko wtedy, gdy włączysz „Include recipients” (domyślnie wyłączone). Kopia rozmowy zawiera nagłówki (Od, Data, Do, DW, nazwy załączników) i zwykły tekst wiadomości, bez obrazów i plików — to także dane osób, które do Ciebie pisały, więc udostępniaj ją tylko wtedy, gdy masz do tego prawo.
- Kto widzi: zaproszone osoby (potrzebują Aorum Mail i konta iCloud) widzą udostępnioną kopię i komentarze, mogą komentować, a tekst zmieniać tylko wtedy, gdy na to pozwolisz. Uczestnicy widzą nawzajem swoje imiona lub identyfikatory iCloud. O nowym komentarzu aplikacja powiadamia przez usługę powiadomień Apple; treść baneru tworzy telefon według Twoich ustawień podglądu.
- Serwer Aorum w tym nie uczestniczy, a Vansa nie ma dostępu do tych danych — przetwarza je Apple.
- Jak długo: do zakończenia udostępniania. „Stop sharing” usuwa kopię i wszystkie komentarze u wszystkich uczestników; szkic na Twoim telefonie zostaje. Po wysłaniu wiadomości kopia staje się tylko do odczytu.
2.9 Potwierdzenia przeczytania
Wysyłając wiadomość, możesz poprosić o potwierdzenie przeczytania. To standardowy mechanizm poczty (MDN, norma RFC 8098): aplikacja dodaje do wiadomości nagłówek z Twoim adresem, a program odbiorcy decyduje — zwykle pytając odbiorcę — czy odeśle potwierdzenie. Nic nie dzieje się bez wiedzy odbiorcy.
Gdy ktoś prosi o potwierdzenie Ciebie, aplikacja nie wysyła go bez Twojej decyzji — pyta albo postępuje zgodnie z ustawieniem, które sam/a wybierzesz. Potwierdzenie to krótki e-mail wysłany z Twojego konta, przez Twojego dostawcę poczty, do osoby, która o nie prosiła. Zawiera identyfikator oryginalnej wiadomości, Twój adres i informację, że wiadomość została wyświetlona; jak każdy e-mail ma datę wysłania.
Status „przeczytane” przy Twojej wysłanej wiadomości pojawia się po nadejściu potwierdzenia i jest zapisany na telefonie. Serwer Aorum w tym nie uczestniczy. Aplikacja nie używa pikseli śledzących (punkt 4).
2.10 Duże załączniki jako link (Dysk Google, OneDrive)
Gdy plik jest za duży dla Twojego dostawcy poczty albo gdy sam/a tak wybierzesz, aplikacja może wysłać go jako link. Plik trafia prosto z iPhone'a na Twój Dysk Google albo Twój OneDrive — nie przez serwer Aorum. Aplikacja tworzy link udostępniania i wstawia go do wiadomości.
- Dysk Google: aplikacja prosi o zakres dostępu
drive.file— widzi wyłącznie pliki, które sama utworzyła albo które jawnie z nią otworzysz, a nie resztę Twojego Dysku. Google poprosi Cię o osobną zgodę na ten dostęp. - OneDrive: aplikacja prosi o uprawnienie Microsoft Graph
Files.ReadWrite. Technicznie daje ono dostęp do plików w Twoim OneDrive; aplikacja używa go tylko do utworzenia własnego folderu i wgrania plików, które wybierzesz. - Kto może otworzyć plik: każdy, kto ma link, może pobrać plik — także osoby, którym adresat przekaże wiadomość albo sam link.
- Jak długo: pliki zostają na Dysku Google albo w OneDrive, dopóki ich nie usuniesz; usunięcie pliku unieważnia link. Tokeny dostępu do tych usług trzyma pęk kluczy iOS.
Google i Microsoft przechowują te pliki jako dostawcy Twoich własnych usług, na swoich warunkach; nie są naszymi podmiotami przetwarzającymi, a Vansa nie ma dostępu do tych plików. Podstawa prawna: art. 6 ust. 1 lit. b RODO.
2.11 Szyfrowanie i podpis OpenPGP i S/MIME
Wiadomości możesz szyfrować i podpisywać w standardzie OpenPGP (RFC 9580, PGP/MIME według RFC 3156). Szyfrowanie, odszyfrowanie, podpis i sprawdzanie podpisu odbywają się na iPhonie, przy użyciu bibliotek kryptograficznych Apple i standardowych algorytmów. Szyfrowane są tylko wiadomości, które sam/a zaszyfrujesz — pozostała poczta jest przesyłana tak jak zwykle.
- Klucz prywatny (ten, którym odszyfrowujesz i podpisujesz) powstaje na iPhonie albo go importujesz. Jest przechowywany tylko w pęku kluczy iOS na tym urządzeniu, z oznaczeniem „tylko to urządzenie” — nie synchronizuje się przez pęk kluczy iCloud i nie przechodzi na inne urządzenie. Aplikacja nie wysyła go na serwer Aorum ani nie zapisuje go w iCloud.
- Klucze publiczne innych osób (służą do szyfrowania wiadomości do nich) aplikacja zapisuje w swojej bazie danych.
- Szukanie klucza adresata (WKD, Web Key Directory): aplikacja pyta przez HTTPS serwer WWW domeny adresata — najpierw
openpgpkey.<domena>, potem<domena>/.well-known/openpgpkey. Ten serwer widzi adres IP Twojego telefonu i może ustalić, o który adres pytano (adres jest w zapytaniu zapisany jako skrót, ale łatwo go odtworzyć). - Autocrypt: na kontach Gmail aplikacja zapisuje lokalnie klucze publiczne z nagłówków Autocrypt w otrzymanych wiadomościach (przy Outlooku/Microsoft 365, iCloud i innych kontach IMAP synchronizacja nie pobiera dziś tego nagłówka). Gdy masz własny klucz, każda wysyłana wiadomość niesie w nagłówku Twój klucz publiczny i Twoją preferencję szyfrowania (można to wyłączyć w Ustawieniach) — widzą je adresaci i serwery po drodze (np. listy dyskusyjne). Klucz publiczny pozwala szyfrować wiadomości do Ciebie, ale nie pozwala ich odczytać.
- S/MIME (standard wbudowany w Apple Mail i Outlook, RFC 8551): własny certyfikat importujesz z pliku .p12 lub .pfx, wpisując jego hasło. Klucz prywatny z tego pliku trafia wyłącznie do pęku kluczy iOS na tym urządzeniu, z tym samym oznaczeniem „tylko to urządzenie”; samego pliku ani hasła aplikacja nie zapisuje. Szyfrowanie, odszyfrowanie, podpis i sprawdzanie podpisu odbywają się na iPhonie (RSA, SHA-256, AES-256).
- Certyfikaty S/MIME innych osób: gdy przychodzi poprawnie podpisana wiadomość S/MIME z certyfikatem zaufanego urzędu certyfikacji, aplikacja zapisuje na iPhonie certyfikat nadawcy (zawiera m.in. jego imię i nazwisko lub nazwę, adres e-mail i wystawcę), żeby można było zaszyfrować odpowiedź; certyfikat możesz też zaimportować z pliku albo usunąć w Ustawieniach. Certyfikaty nie trafiają na serwer Aorum ani do iCloud.
- Sprawdzanie zaufania certyfikatu: iOS sprawdza, czy certyfikat nadawcy wystawił zaufany urząd certyfikacji; przy tym system może połączyć się z serwerem tego urzędu (np. po brakujący certyfikat pośredni), który widzi wtedy adres IP Twojego telefonu.
- Czego szyfrowanie nie ukrywa: szyfrowane są treść i załączniki wysłane w samej wiadomości. Temat, nadawca, adresaci i data pozostają widoczne dla dostawców poczty — standard PGP/MIME nie szyfruje tematu. Duży plik wysłany jako link (punkt 2.10) nie jest objęty tym szyfrowaniem, nawet w zaszyfrowanej wiadomości — chroni go wyłącznie ustawienie linku na Twoim Dysku Google albo OneDrive.
2.12 Uczący się podział skrzynki i Gatekeeper
Aplikacja może dzielić skrzynkę na kategorie i uczyć się tego podziału z Twoich działań (przeniesień, oznaczeń, decyzji). Gatekeeper (domyślnie wyłączony, włączasz go sam/a) odkłada nową pocztę od nadawców, do których nigdy nie pisałeś/aś i których nie ma w kontaktach, do osobnego filtra „New senders”, gdzie decydujesz: przyjąć, przenieść czy zablokować. Model, statystyki i decyzje są zapisane w pliku aplikacji na iPhonie (nie synchronizują się przez iCloud); nie trafiają na serwer Aorum ani do zewnętrznego AI.
2.13 Dane z usług Google
Aplikacja korzysta z interfejsów API Google: Gmaila (Twoja poczta, a gdy je włączysz — powiadomienia i wysyłka zaplanowana z serwera), kontaktów Google (gdy włączysz synchronizację kontaktów) i Dysku Google (duże załączniki jako link). Dane z tych interfejsów służą wyłącznie funkcjom opisanym w tej polityce; nie używamy ich do reklam i ich nie sprzedajemy.
Korzystanie przez Aorum Mail z informacji otrzymanych z interfejsów API Google i ich przekazywanie innym aplikacjom jest zgodne z zasadami Google API Services User Data Policy, w tym z wymaganiami ograniczonego użycia (Limited Use).
2.14 Powiadomienia o nowej poczcie Outlook, Microsoft 365, iCloud i IMAP (usługa serwerowa)
Ta funkcja jest opcjonalna. Włączasz ją osobno dla każdego konta Outlook, Microsoft 365, iCloud albo IMAP (ustawienia konta, zakładka Server, przełącznik „Serwerowe powiadomienia o poczcie”), po zgodzie w osobnym oknie. Dzięki niej aplikacja dowiaduje się o nowej poczcie w folderze Odebrane, gdy działa w tle. Bez niej te skrzynki aplikacja sprawdza sama, gdy iOS ją wybudzi.
Jak działa. Przy kontach Microsoft serwer zakłada w Microsoft Graph subskrypcję zmian folderu Odebrane (bez treści wiadomości) i odnawia ją co około trzy dni; Microsoft zgłasza serwerowi tylko, że pojawiła się nowa wiadomość. Przy iCloud i IMAP serwer mniej więcej raz na minutę loguje się do skrzynki i odczytuje wyłącznie dwa liczniki folderu Odebrane (UIDVALIDITY i UIDNEXT). Serwer nigdy nie pobiera treści, tematów, nadawców, adresatów ani załączników. Gdy przyjdzie nowa poczta, wysyła na iPhone'a przez Apple (APNs) cichy sygnał bez żadnej treści — tylko identyfikator monitora i zdarzenia. Aplikacja sama pobiera wtedy pocztę od dostawcy i na telefonie stosuje Twoje ustawienia powiadomień: wyciszonych i zablokowanych nadawców, typy Priorytetowe i Inteligentne oraz Gatekeepera. iOS może opóźnić taki sygnał i nie budzi aplikacji zamkniętej przesunięciem w górę.
Co zapisuje serwer:
- poświadczenie konta: przy Microsoft — token dostępu i token odświeżania (logujesz się na stronie Microsoft, serwer nie zna Twojego hasła) oraz identyfikator rejestracji aplikacji (Client ID); przy iCloud i IMAP — adres serwera IMAP, port, login i hasło skrzynki (przy iCloud hasło do aplikacji wygenerowane w ustawieniach konta Apple, nie hasło do Apple ID). Poświadczenia są zaszyfrowane (AES-256-GCM) razem z tokenem zarządzania monitorem, a klucze szyfrujące są przechowywane osobno od bazy, w Google Secret Manager;
- tożsamość skrzynki zapisaną zwykłym tekstem: przy Microsoft — identyfikator konta Microsoft (bez adresu), przy iCloud i IMAP — nazwę serwera, port i login (zwykle adres e-mail); służy do sprawdzenia, że odnowienie dotyczy tej samej skrzynki;
- token urządzenia APNs Twojego iPhone'a i środowisko (produkcja/sandbox), identyfikator subskrypcji Microsoft albo dwa liczniki folderu Odebrane, stan monitora, znaczniki czasu i kod ostatniego błędu;
- skróty kryptograficzne: tokenu zarządzania, klucza idempotencji i tożsamości skrzynki (limity liczby monitorów); gdy w aplikacji jest konto Gmail — techniczny identyfikator konta Google, żeby „Usuń moje dane z serwera” objęło też ten monitor;
- rekordy zdarzeń (identyfikator zdarzenia i stan, bez treści) do usuwania powtórzeń — wygasają po 7 dniach.
Jak długo. Poświadczenia — do wyłączenia przełącznika, odłączenia konta albo użycia „Usuń moje dane z serwera”; wtedy serwer kasuje je od razu. Jeśli sygnały nie mogą już dotrzeć do Twojego iPhone'a (Apple zgłosi nieważny token, np. po usunięciu aplikacji) albo skrzynka jest nieosiągalna przez 72 godziny (np. po zmianie hasła), serwer przestaje ją sprawdzać, a po kolejnych 14 dniach kasuje monitor razem z poświadczeniami, chyba że aplikacja wcześniej go odnowi. Po usunięciu zostaje przez 30 dni tylko skrót tokenu zarządzania (żeby ponowione żądanie usunięcia dostało poprawną odpowiedź) i licznik monitorów danej skrzynki (skrót tożsamości i liczba).
Logi serwera zawierają tylko identyfikator monitora, nazwę dostawcy i kod błędu — bez adresów, loginów, haseł i tokenów. Usługa działa w Google Cloud (Cloud Run i baza Firestore) w regionie europe-central2 (Warszawa); Google Cloud przetwarza te dane w naszym imieniu jako podmiot przetwarzający. Microsoft przy subskrypcji zna adres naszego serwera, na który wysyła zgłoszenia.
Podstawa prawna: Twoja zgoda wyrażona w oknie zgody przy włączaniu funkcji (art. 6 ust. 1 lit. a RODO); cofasz ją, wyłączając przełącznik.
2.15 Czego nie ma w wersji 1.0
W wersji 1.0 nie ma: AI w chmurze ani płatnych subskrypcji i zakupów w aplikacji. Nie przetwarzamy w związku z nimi żadnych danych. Zanim którąś z tych funkcji włączymy, zaktualizujemy tę politykę.
3. Cel i podstawa prawna przetwarzania
- pokazywanie i wysyłanie Twojej poczty w aplikacji — realizacja usługi, którą wybrałeś/aś, instalując i konfigurując aplikację (art. 6 ust. 1 lit. b RODO);
- funkcje, o które prosisz, włączając je: wysyłka zaplanowana z serwera, synchronizacja przez iCloud, wspólne szkice, duże załączniki jako link, szyfrowanie OpenPGP i S/MIME oraz potwierdzenia przeczytania (art. 6 ust. 1 lit. b RODO);
- natychmiastowe powiadomienia o nowej poczcie Gmail, serwerowe powiadomienia o poczcie Outlook, Microsoft 365, iCloud i IMAP, dostęp do kontaktów i „dopasowanie kontaktów” — na podstawie Twojej zgody wyrażonej przy włączaniu danej funkcji (art. 6 ust. 1 lit. a RODO);
- obsługa zgłoszeń do pomocy technicznej, gdy sam/a się z nami skontaktujesz.
Zgodę możesz cofnąć w każdej chwili, wyłączając daną funkcję; nie wpływa to na zgodność z prawem przetwarzania sprzed jej cofnięcia. Z funkcji opartych na umowie możesz zrezygnować w dowolnym momencie, wyłączając je w aplikacji.
4. Czego nie robimy
Nie sprzedajemy ani nie udostępniamy Twoich danych podmiotom trzecim w celach marketingowych. Nie prowadzimy trackingu reklamowego ani profilowania między aplikacjami. Nie zbieramy statystyk użycia aplikacji. Nie czytamy automatycznie treści Twojej poczty do żadnych własnych celów poza dostarczeniem funkcji, o które prosisz (np. podgląd w powiadomieniu). Nie mamy dostępu do Twoich danych w iCloud, na Dysku Google ani w OneDrive.
Aplikacja chroni Cię też przed śledzeniem ukrytym w samej wiadomości: piksele śledzące (niewidoczne obrazki 1×1, którymi nadawcy sprawdzają, czy i kiedy otworzyłeś/aś wiadomość) są usuwane zawsze, a pozostałe zdalne obrazy w treści wiadomości są domyślnie zablokowane, dopóki nie zaufasz danemu nadawcy. Sama aplikacja nigdy nie dodaje pikseli śledzących do wysyłanych wiadomości. Potwierdzenia przeczytania (punkt 2.9) to coś innego: standardowy, widoczny mechanizm poczty, w którym odbiorca widzi prośbę i sam decyduje, czy odpowiedzieć.
5. Jak długo przechowujemy dane
- Poczta, kontakty, ustawienia, indeks wyszukiwania, klucze publiczne i dane podziału skrzynki na urządzeniu — do czasu usunięcia konta w aplikacji albo usunięcia samej aplikacji (indeks wyszukiwania według znaczenia — do usunięcia aplikacji).
- Rejestracja urządzenia w usłudze powiadomień push (razem z adresem konta i ustawieniami powiadomień) — domyślnie 8 dni (TTL, czyli automatyczne wygaśnięcie), odświeżana automatycznie codziennie, dopóki masz aktywne konto i włączone powiadomienia. Nieaktywny token jest też usuwany automatycznie, gdy Apple odpowie kodem 410 (token nieważny).
- Znaczniki postępu synchronizacji Gmaila — zapisy o pojedynczych zdarzeniach wygasają po 7–30 dniach; znacznik ostatniej przetworzonej zmiany (bez adresu, tylko skrót kryptograficzny) nie wygasa sam, ale usuwa go „Usuń moje dane z serwera” (punkt 6). Jeśli Gmail wyśle jeszcze zdarzenie przed wygaśnięciem subskrypcji (do 7 dni), serwer może zapisać nowy znacznik — usuniemy go na prośbę wysłaną na support@aorum.app.
- Poświadczenia do wysyłki z serwera — do cofnięcia autoryzacji w ustawieniach konta, usunięcia konta w aplikacji albo użycia „Usuń moje dane z serwera”.
- Poświadczenia serwerowych powiadomień o poczcie Outlook, Microsoft 365, iCloud i IMAP — do wyłączenia przełącznika, odłączenia konta albo użycia „Usuń moje dane z serwera”; automatycznie 14 dni po tym, jak serwer przestał docierać do iPhone'a albo do skrzynki (punkt 2.14). Skrót tokenu zarządzania — 30 dni po usunięciu; rekordy zdarzeń — 7 dni.
- Zadania wysyłki w toku — do wysłania albo anulowania wiadomości.
- Rekordy zakończonych i anulowanych zadań (identyfikatory, termin, wynik; bez treści) — bez z góry ustalonego terminu, jako zabezpieczenie przed podwójną wysyłką; usuniemy je na prośbę wysłaną na support@aorum.app.
- Dane w Twoim iCloud (stan aplikacji, wspólne szkice i komentarze) — do czasu, aż je usuniesz; przechowuje je Apple w ramach Twojego konta iCloud.
- Pliki na Dysku Google i w OneDrive — do czasu, aż je usuniesz; przechowują je Google albo Microsoft w ramach Twojego konta.
- Zgłoszenia do pomocy technicznej — przez czas potrzebny do obsługi zgłoszenia.
6. Jak usunąć swoje dane
W Ustawieniach aplikacji, w szczegółach konta, możesz odłączyć dowolne konto pocztowe (Disconnect) — usuwa to lokalną kopię jego poczty z telefonu i wysyła do serwera powiadomień żądanie wyrejestrowania tokenu urządzenia dla tego konta (rejestracja jest usuwana z bazy serwera). W tych samych ustawieniach konta, w zakładce Server, możesz cofnąć autoryzację wysyłki z serwera i wyłączyć serwerowe powiadomienia o poczcie — serwer usuwa wtedy zapisane poświadczenie tego konta i jego monitor. Odłączenie konta Outlook, Microsoft 365, iCloud albo IMAP robi to samo przed usunięciem poczty z telefonu.
W Ustawienia → Bezpieczeństwo → Dane na serwerze przycisk „Usuń moje dane z serwera” usuwa wszystko, co serwer przechowuje dla kont z tego iPhone'a: rejestracje urządzenia z ustawieniami powiadomień, autoryzacje serwerowe kont i monitory poczty; potem aplikacja nie rejestruje się ponownie, dopóki sama nie włączysz powiadomień przez serwer. Jeśli na serwerze czekają Twoje zaplanowane wiadomości, najpierw je anuluj — do tego czasu aplikacja odmówi usunięcia danych, żeby nie zgubić wiadomości, które mają wyjść. Usunięcie samej aplikacji z telefonu usuwa tylko dane zapisane na telefonie — danych na serwerze nie, dlatego najpierw użyj tego przycisku.
Stan aplikacji w iCloud usuniesz przyciskiem „Delete iCloud data” (Ustawienia → Profile → iCloud) albo w Ustawieniach iOS (Twoje konto Apple → iCloud → zarządzanie pamięcią). Udostępnianie szkicu możesz zakończyć w każdej chwili, a pliki wysłane jako link usuniesz na Dysku Google albo w OneDrive. Możesz też napisać na adres support@aorum.app z prośbą o informację, jakie dane serwerowe są z Tobą powiązane, oraz o ich usunięcie.
7. Odbiorcy danych
- Dostawcy poczty (Google, Microsoft, Apple albo Twój serwer IMAP) — Twoja poczta trafia bezpośrednio do nich; to Twoja relacja z dostawcą, nie z nami.
- Google Cloud (region europe-central2, Warszawa) — przetwarza w naszym imieniu, jako dostawca infrastruktury (podmiot przetwarzający), dane usługi powiadomień push (punkt 2.5), wysyłki zaplanowanej z serwera (punkt 2.6) i serwerowych powiadomień o poczcie Outlook, Microsoft 365, iCloud i IMAP (punkt 2.14), w tym klucze szyfrujące w Google Secret Manager.
- Apple — dostarcza powiadomienia na Twój iPhone przez usługę APNs.
- Dostawcy Twoich własnych usług, których nie kontrolujemy: Apple (iCloud i CloudKit — stan aplikacji, wspólne szkice i komentarze), Google (Dysk Google) i Microsoft (OneDrive) — duże załączniki jako link. Przetwarzają dane na podstawie Twojej umowy z nimi; nie są naszymi podmiotami przetwarzającymi.
- Serwery WWW domen adresatów — gdy aplikacja szuka klucza OpenPGP adresata (WKD), serwer jego domeny widzi adres IP Twojego telefonu i adres, o który pytano (punkt 2.11).
- Urzędy certyfikacji — przy sprawdzaniu certyfikatu S/MIME system iOS może zapytać serwer urzędu, który go wystawił; serwer widzi adres IP Twojego telefonu (punkt 2.11).
- Osoby, które sam/a wybierzesz — adresaci Twoich wiadomości, osoby zaproszone do wspólnego szkicu i osoby, które mają link do pliku.
Nie przekazujemy danych innym firmom; serwer nie używa narzędzi analitycznych ani reklamowych.
8. Prawa użytkownika
Zgodnie z RODO masz prawo do: dostępu do swoich danych, ich sprostowania, usunięcia, ograniczenia przetwarzania, przenoszenia danych oraz sprzeciwu wobec przetwarzania. Możesz też cofnąć zgodę na dowolną funkcję w dowolnym momencie w Ustawieniach aplikacji lub iOS. Masz prawo wniesienia skargi do Prezesa Urzędu Ochrony Danych Osobowych (UODO).
9. Zmiany polityki
Możemy aktualizować tę politykę wraz z rozwojem aplikacji. Datę ostatniej zmiany znajdziesz na górze strony. Istotne zmiany zakresu przetwarzania ogłosimy w aplikacji.
10. Kontakt
W sprawach związanych z ochroną danych osobowych pisz na support@aorum.app.
Privacy Policy — Aorum Mail
In short: Aorum Mail keeps your mail and contacts on your iPhone. We have no server that keeps a copy of your mailbox. In version 1.0 our server runs only two optional services that you turn on yourself: instant notifications for new Gmail messages, and sending scheduled messages from the server, even while your phone is off. Features built on iCloud, Google Drive and OneDrive store data in your own accounts with those services — we have no access to them. The AI assistant, meaning-based search and the learning inbox split run only on your iPhone. We do not sell your data and we do not run advertising tracking.
1. Data controller
The data controller within the meaning of GDPR is Vansa Sp. z o.o., ul. Jana Smolenia 14, 30-864 Kraków (KRS 0000675425, NIP 6793148076). Contact for data-protection matters: support@aorum.app.
2. What data the app processes
2.1 Mail and contacts — on the device
Messages, attachments, drafts, notes about people, saved searches, settings and the search index are written to the app's own database on your iPhone. A message scheduled for later waits on the phone and the app itself sends it — unless you turn on sending from the server for that account (section 2.6); then it waits as a draft in your own mailbox with your mail provider. Aorum Mail has no server of its own holding a copy of your mailbox.
2.2 Mail accounts (Gmail, Microsoft, IMAP)
To show your mail, the app signs you in directly with your provider — Google, Microsoft, Apple, or the IMAP server you name. For Gmail and Microsoft you sign in on the provider's own page (OAuth), so the app never sees your password — it only receives an access token. For iCloud and IMAP you supply the server details and a password (usually an app password). Tokens and passwords are kept in the iOS Keychain, never in ordinary files, and the app uses them to connect to your mailbox. They leave the phone only if you turn on scheduled sending from the server (section 2.6) or server mail notifications for Outlook, Microsoft 365, iCloud and IMAP (section 2.14) for an account and agree to it in a separate consent window — the server then receives the credential that feature needs. Each provider handles your mail under its own privacy policy.
2.3 Contacts
With your permission, the app can read the iPhone address book and — if you turn on contact sync for a Gmail account (off by default) — the contacts of that Google account, so a sender arrives with a name and photo rather than a bare address. A phone-number type you change in the app is written back to your Google contacts. Address-book access can be withdrawn in iOS Settings and Google sync in the account settings in the app; the data read stays on the device. The exception is optional "contact matching" for Gmail notifications (section 2.5) — only if you turn it on does the server receive one-way codes of addresses, never the addresses themselves.
2.4 AI assistant and Ask — on the device
Summaries, answers and drafts are produced by the language model built into iOS (Apple Foundation Models), running on your iPhone. Ask — the questions you ask about your mail — can also search text recognised in photos and scans (OCR, meaning reading text from an image, done by Apple's built-in Vision service), the text of DOCX documents, XLSX spreadsheets and PPTX presentations, and search by meaning rather than only by exact words. For meaning-based search the app builds an index on your iPhone: a record of what passages of your messages are about, stored as numbers (so-called vectors). The index holds only numbers, no message text; it lives in a separate app file on the device, is not included in iCloud backup, and conversations deleted from the mailbox drop out of it on the next pass. The file is removed together with the app. When Ask needs older messages from a Microsoft account, it fetches them directly from Microsoft (Microsoft Graph), just like regular sync.
Message content, attachments and addresses are not sent to any external AI server or to the Aorum server — processing happens entirely on the device, and the AI computations themselves do not need an internet connection.
2.5 Push notifications for Gmail (server service)
Instant notifications for new Gmail messages require a separate, optional server service. When you use it, the following reaches the server:
- your Gmail account's verified email address (via a Google sign-in token), used as the registration identifier;
- the device's APNs token (an identifier Apple uses to deliver the notification to your iPhone);
- a technical account/profile identifier within the app, and a snapshot of your notification settings (mode, sound, preview level, Face ID lock, muted and snoozed threads);
- only if you turn on "contact matching" in Settings → Application → Notifications (a separate consent, off by default): one-way codes of the addresses on the lists your notification type needs — muted and blocked senders (every type), favourites (Priority and Smart) and all contacts (Smart). Never the addresses themselves. Turning the option off, or choosing No notifications, removes these lists from the server at the next settings confirmation;
- transiently, only for the duration of delivering a single notification: the sender, subject, labels and a short snippet of the message, read from your Gmail account to check them against your notification settings and build the preview at the level you chose.
The server does not store message content, recipient addresses, or the full notification payload in its database or logs — preview data (sender/subject/snippet) exists only transiently in the memory of the process sending the notification and in the Apple push notification itself. The server does not read your mail beyond what is needed to send that one notification.
The server database (Firestore) stores technical registration records: the Gmail account address, the APNs token, environment (production/sandbox), app identifier, a technical account identifier, registration timestamps and expiry, and your notification-policy settings. The sender and domain lists from "contact matching" are stored as cryptographic hashes, not as readable addresses: once the server is updated, as HMAC-SHA-256 with a per-account key that is not kept in the database, and until then as plain SHA-256 hashes. To avoid sending the same notification twice, the server also keeps technical Gmail sync markers — the number of the last mailbox change it processed, tied to a cryptographic hash of the address rather than the address itself.
The service runs on Google Cloud (Cloud Run and the Firestore database) in the europe-central2 region (Warsaw). Notifications reach your iPhone through the Apple Push Notification service (APNs); the device token and the notification content pass through Apple's infrastructure, including outside the European Economic Area.
2.6 Scheduled sending from the server (server service)
This feature is optional. You turn it on separately for each account (account settings, Server tab), after agreeing in a separate consent window. With it, a message scheduled for later goes out on time even when your phone is off or has no signal. Without that consent, a scheduled message waits on the phone and the app sends it.
Where the message waits. The app saves it as a draft in your own mailbox (Gmail, Outlook, or the drafts folder on your IMAP server). We do not copy its content to our server. At the scheduled time the server reads that draft from your provider and sends it through the provider (Gmail API, Microsoft Graph or SMTP). The content may pass transiently through the memory of the sending process — always for iCloud and IMAP, because the server itself hands it to the SMTP server — but the server does not store it in its database or logs.
What the server stores:
- the account credential without which a message cannot be sent on your behalf: for Gmail — a long-lived Google authorization (a so-called refresh token), which the server receives from Google in exchange for a one-time code passed on by the app; for Microsoft — a refresh token; for iCloud and IMAP — the mailbox login and password (usually an app password) for the IMAP and SMTP servers. Credentials are encrypted (AES-256-GCM), and the encryption keys are kept separately from the database, in Google Secret Manager;
- for Microsoft, iCloud and IMAP accounts — the address of the mailbox the authorization belongs to, stored as plain text as a label for that authorization;
- the send job: a technical owner identifier, the draft's identifier in your mailbox, the message identifier (Message-ID), the scheduled time, the status and the result. The job contains no content, subject or recipients.
Server logs contain only selected technical fields — no email addresses and no tokens. The service runs in the same place as notifications: Google Cloud (Cloud Run and the Firestore database), europe-central2 region (Warsaw); Google Cloud processes this data on our behalf as a data processor. We do not pass it to anyone else.
How long. The credential — until you revoke the authorization in the account settings, remove the account in the app, or use "Delete my data from server". A job in progress — until the message is sent or cancelled. Once a message is sent or cancelled, a short job record remains (identifiers, scheduled time, result; no content) that protects against sending the same message twice; it has no fixed deletion date — we will delete it on request sent to support@aorum.app. While scheduled messages are waiting on the server, the app will not let you use "Delete my data from server" — cancel them first.
Accuracy. The server sends a message to within about a minute. If it is uncertain whether the provider accepted a message, the server does not send it a second time, and the app shows its status.
Legal basis: Art. 6(1)(b) GDPR — a service you ask for. Turning it on is voluntary, and you can turn it off at any time.
2.7 Settings and app state in your iCloud
You can optionally turn on "Aorum Mail iCloud sync" (Settings → Profile). The app then stores part of its state, separately for each profile, in your private iCloud database (Apple's CloudKit service), so that this state is available on your devices signed in to the same Apple Account.
- What is synced: pins, the inbox split into categories, Later, Set aside, reminders, follow-ups, mutes, favourite and muted people, signatures and signature rules, templates, quick replies and selected interface settings. Threads, people and accounts are identified by cryptographic hashes of addresses and identifiers, not by readable addresses.
- Encryption: before the data leaves the phone, the app encrypts it (AES-GCM) with a key kept in your iCloud Keychain and replaces record names with hashes. Without that key neither Apple nor Vansa can read the records' content.
- What is not in iCloud: mail content, subjects, attachments, the send queue, passwords, tokens, Face ID settings and device privacy settings.
- Who can see it: the private iCloud database belongs to you; Apple processes it under the iCloud terms. Vansa has no access to it, and the data does not pass through the Aorum server.
- How long: until you delete it. "Disconnect this device" (Settings → Profile → iCloud) stops syncing on this device and deletes nothing. "Delete iCloud data" in the same place removes the profile's state from iCloud for all your devices (data on the devices stays). You can also delete the app's iCloud data in iOS Settings (your Apple Account → iCloud → storage management).
Legal basis: Art. 6(1)(b) GDPR.
2.8 Shared drafts and comments (iCloud sharing)
You can share a draft — or a copy of a conversation's text ("Discuss with team") — for comments with people you choose through the system iCloud share sheet; you invite them by Apple Account, email address or phone number (invited people only, no public link). The copy and the comments are stored in the private iCloud of the draft's owner, meaning the person who shared it, and are encrypted so that Apple cannot see the subject, text, addresses or comments.
- What leaves the phone: exactly what the sharing screen shows — the subject, the text, attachment names (the files stay on the iPhone) and the recipients only if you turn on "Include recipients" (off by default). A conversation copy contains headers (From, Date, To, Cc, attachment names) and the plain text of the messages, without images or files — that is also data of the people who wrote to you, so share it only when you are entitled to.
- Who can see it: invited people (they need Aorum Mail and an iCloud account) see the shared copy and the comments, can comment, and can change the text only if you allow it. Participants see each other's iCloud names or identifiers. New comments are announced through Apple's notification service; the banner text is built on the phone according to your preview settings.
- The Aorum server takes no part in this, and Vansa has no access to this data — Apple processes it.
- How long: until you stop sharing. "Stop sharing" removes the copy and all comments for every participant; the draft on your phone stays. After the message is sent, the copy becomes read-only.
2.9 Read receipts
When you send a message, you can ask for a read receipt. This is a standard mail mechanism (MDN, standard RFC 8098): the app adds a header with your address to the message, and the recipient's mail program decides — usually by asking the recipient — whether to send a receipt back. Nothing happens without the recipient knowing.
When someone asks you for a receipt, the app does not send one without your decision — it asks you, or follows the setting you choose yourself. A receipt is a short email sent from your account, through your mail provider, to the person who asked for it. It contains the identifier of the original message, your address and a note that the message was displayed; like any email, it carries the date it was sent.
The "read" status on a message you sent appears once a receipt arrives and is stored on the phone. The Aorum server takes no part in this. The app does not use tracking pixels (section 4).
2.10 Large attachments as links (Google Drive, OneDrive)
When a file is too large for your mail provider, or when you choose to, the app can send it as a link. The file goes straight from your iPhone to your Google Drive or your OneDrive — not through the Aorum server. The app creates a sharing link and puts it in the message.
- Google Drive: the app asks for the
drive.fileaccess scope — it sees only files it created itself or that you explicitly open with it, not the rest of your Drive. Google asks you for separate consent to this access. - OneDrive: the app asks for the Microsoft Graph
Files.ReadWritepermission. Technically it gives access to the files in your OneDrive; the app uses it only to create its own folder and upload the files you choose. - Who can open the file: anyone who has the link can download the file — including people the recipient forwards the message or the link to.
- How long: files stay in Google Drive or OneDrive until you delete them; deleting a file makes the link stop working. Access tokens for these services are kept in the iOS Keychain.
Google and Microsoft store these files as providers of your own services, under their own terms; they are not our data processors, and Vansa has no access to these files. Legal basis: Art. 6(1)(b) GDPR.
2.11 OpenPGP and S/MIME encryption and signing
You can encrypt and sign messages with the OpenPGP standard (RFC 9580, PGP/MIME under RFC 3156). Encryption, decryption, signing and signature checks happen on your iPhone, using Apple's cryptographic libraries and standard algorithms. Only the messages you choose to encrypt are encrypted — the rest of your mail travels as usual.
- Your private key (the one you decrypt and sign with) is created on your iPhone or imported by you. It is kept only in the iOS Keychain on this device, marked "this device only" — it does not sync through iCloud Keychain and does not move to another device. The app does not send it to the Aorum server and does not store it in iCloud.
- Other people's public keys (used to encrypt messages to them) are stored in the app's database.
- Looking up a recipient's key (WKD, Web Key Directory): the app asks the web server of the recipient's domain over HTTPS — first
openpgpkey.<domain>, then<domain>/.well-known/openpgpkey. That server sees your phone's IP address and can tell which address was looked up (the address is written as a hash in the request, but it is easy to work back). - Autocrypt: on Gmail accounts, the app stores public keys from the Autocrypt headers of messages you receive, locally (Outlook/Microsoft 365, iCloud and other IMAP accounts do not fetch this header during sync today). When you have your own key, every message you send carries your public key and your encryption preference in a header — you can turn this off in Settings — visible to recipients and to servers along the way (for example mailing lists). A public key lets others encrypt messages to you, but does not let anyone read them.
- S/MIME (the standard built into Apple Mail and Outlook, RFC 8551): you import your own certificate from a .p12 or .pfx file and type its password. The private key from that file goes only into the iOS Keychain on this device, with the same "this device only" marking; the app does not store the file or the password. Encryption, decryption, signing and signature checks happen on your iPhone (RSA, SHA-256, AES-256).
- Other people's S/MIME certificates: when a correctly signed S/MIME message with a certificate from a trusted certificate authority arrives, the app saves the sender's certificate on your iPhone (it contains, among other things, their name, email address and issuer) so you can encrypt your reply; you can also import a certificate from a file or remove it in Settings. Certificates do not go to the Aorum server or to iCloud.
- Checking whether a certificate is trusted: iOS checks that the sender's certificate was issued by a trusted certificate authority; while doing so, the system may contact that authority's server (for example for a missing intermediate certificate), which then sees your phone's IP address.
- What encryption does not hide: the body and attachments you send inside the message are encrypted. The subject, sender, recipients and date stay visible to mail providers — the PGP/MIME standard does not encrypt the subject. A large file sent as a link (section 2.10) is not covered by this encryption, even in an encrypted message — only your Google Drive or OneDrive link setting protects it.
2.12 Learning inbox split and Gatekeeper
The app can split your inbox into categories and learn that split from what you do (moves, flags, decisions). Gatekeeper (off by default, you turn it on yourself) sets aside new mail from senders you have never written to and who are not in your contacts in a separate "New senders" filter, where you decide: accept, move or block. The model, statistics and decisions are stored in an app file on your iPhone (they are not synced through iCloud); they do not go to the Aorum server or to any external AI.
2.13 Data from Google services
The app uses Google APIs: Gmail (your mail and — when you turn them on — notifications and scheduled sending from the server), Google contacts (when you turn on contact sync) and Google Drive (large attachments as links). Data from these APIs is used only for the features described in this policy; we do not use it for advertising and we do not sell it.
Aorum Mail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2.14 New mail notifications for Outlook, Microsoft 365, iCloud and IMAP (server service)
This feature is optional. You turn it on separately for each Outlook, Microsoft 365, iCloud or IMAP account (account settings, Server tab, the "Server mail notifications" switch), after agreeing in a separate consent window. It lets the app learn about new mail in the Inbox while it runs in the background. Without it, the app checks those mailboxes itself when iOS wakes it up.
How it works. For Microsoft accounts the server creates a Microsoft Graph subscription to changes in the Inbox (without message content) and renews it about every three days; Microsoft only tells the server that a new message has appeared. For iCloud and IMAP the server signs in to the mailbox about once a minute and reads only two Inbox counters (UIDVALIDITY and UIDNEXT). The server never downloads message text, subjects, senders, recipients or attachments. When new mail arrives it sends your iPhone a silent signal through Apple (APNs) with no content — only a monitor and event identifier. The app then fetches the mail from your provider itself and applies your notification settings on the phone: muted and blocked senders, the Priority and Smart types, and Gatekeeper. iOS may delay such a signal and does not wake an app you have swiped away.
What the server stores:
- the account credential: for Microsoft — an access token and a refresh token (you sign in on Microsoft's page, the server never learns your password) and the app registration identifier (Client ID); for iCloud and IMAP — the IMAP server address, port, login and mailbox password (for iCloud, an app-specific password generated in your Apple Account settings, not your Apple ID password). Credentials are encrypted (AES-256-GCM) together with the monitor's management token, and the encryption keys are kept separately from the database, in Google Secret Manager;
- the mailbox identity in plain text: for Microsoft — the Microsoft account identifier (no address); for iCloud and IMAP — the server name, port and login (usually the email address); it is used to check that a renewal concerns the same mailbox;
- your iPhone's APNs device token and environment (production/sandbox), the Microsoft subscription identifier or the two Inbox counters, the monitor state, timestamps and the last error code;
- cryptographic hashes of the management token, the idempotency key and the mailbox identity (limits on the number of monitors); if the app has a Gmail account — a technical Google account identifier, so that "Delete my data from server" also covers this monitor;
- event records (event identifier and state, no content) used to avoid duplicates — they expire after 7 days.
How long. Credentials — until you turn the switch off, disconnect the account or use "Delete my data from server"; the server then deletes them at once. If signals can no longer reach your iPhone (Apple reports an invalid token, e.g. after the app was removed) or the mailbox stays unreachable for 72 hours (e.g. after a password change), the server stops checking it and, 14 days later, deletes the monitor with its credentials unless the app renews it first. After deletion, only a hash of the management token (so that a repeated deletion request gets the right answer) and the per-mailbox monitor counter (identity hash and a number) remain for 30 days.
Server logs contain only the monitor identifier, the provider name and an error code — no addresses, logins, passwords or tokens. The service runs on Google Cloud (Cloud Run and Firestore) in the europe-central2 region (Warsaw); Google Cloud processes this data on our behalf as a processor. For the subscription, Microsoft knows the address of our server to which it sends its reports.
Legal basis: the consent you give in the consent window when you turn the feature on (Art. 6(1)(a) GDPR); you withdraw it by turning the switch off.
2.15 What is not in version 1.0
Version 1.0 does not include cloud AI, or paid subscriptions and in-app purchases. We process no data for them. Before we turn any of these features on, we will update this policy.
3. Purpose and legal basis of processing
- showing and sending your mail in the app — delivering the service you chose by installing and configuring the app (Art. 6(1)(b) GDPR);
- features you ask for by turning them on: scheduled sending from the server, iCloud sync, shared drafts, large attachments as links, OpenPGP and S/MIME encryption and read receipts (Art. 6(1)(b) GDPR);
- instant notifications for new Gmail messages, server mail notifications for Outlook, Microsoft 365, iCloud and IMAP, contacts access and "contact matching" — based on the consent you give when you turn that feature on (Art. 6(1)(a) GDPR);
- handling support requests when you contact us directly.
You can withdraw consent at any time by turning the feature off; this does not affect the lawfulness of processing before withdrawal. You can stop using contract-based features at any time by turning them off in the app.
4. What we do not do
We do not sell or share your data with third parties for marketing purposes. We do not run advertising tracking or cross-app profiling. We do not collect app usage statistics. We do not automatically read the content of your mail for any purpose of our own beyond delivering the feature you asked for (e.g. a notification preview). We have no access to your data in iCloud, Google Drive or OneDrive.
The app also protects you from tracking hidden inside messages themselves: tracking pixels (invisible 1×1 images senders use to check if and when you opened a message) are always removed, and other remote images in a message's content are blocked by default until you trust that sender. The app itself never adds tracking pixels to the messages you send. Read receipts (section 2.9) are something different: a standard, visible mail mechanism in which the recipient sees the request and decides whether to answer.
5. How long we keep data
- Mail, contacts, settings, the search index, public keys and inbox-split data on the device — until you remove the account in the app or remove the app itself (the meaning-based search index — until you remove the app).
- Device registration for push notifications (together with the account address and notification settings) — 8 days by default (TTL, meaning automatic expiry), refreshed automatically every day while you have an active account and notifications turned on. An inactive token is also removed automatically once Apple responds with a 410 (invalid token).
- Gmail sync markers — records of individual events expire after 7–30 days; the marker of the last processed change (no address, only a cryptographic hash) does not expire on its own, but "Delete my data from server" removes it (section 6). If Gmail still sends an event before its subscription runs out (up to 7 days), the server may write a new marker — we will delete it on request sent to support@aorum.app.
- Credentials for sending from the server — until you revoke the authorization in the account settings, remove the account in the app, or use "Delete my data from server".
- Credentials for server mail notifications for Outlook, Microsoft 365, iCloud and IMAP — until you turn the switch off, disconnect the account or use "Delete my data from server"; automatically 14 days after the server could no longer reach the iPhone or the mailbox (section 2.14). The management-token hash — 30 days after deletion; event records — 7 days.
- Send jobs in progress — until the message is sent or cancelled.
- Records of completed and cancelled jobs (identifiers, scheduled time, result; no content) — with no fixed deletion date, as a safeguard against sending twice; we will delete them on request sent to support@aorum.app.
- Data in your iCloud (app state, shared drafts and comments) — until you delete it; Apple stores it as part of your iCloud account.
- Files in Google Drive and OneDrive — until you delete them; Google or Microsoft stores them as part of your account.
- Support requests — for as long as needed to handle the request.
6. How to delete your data
In the app's Settings, under an account's details, you can disconnect any mail account — this removes its local mail copy from the phone and sends the push-notification server a request to unregister that account's device token (the registration is removed from the server database). In the same account settings, on the Server tab, you can revoke the authorization for sending from the server and turn off server mail notifications — the server then deletes that account's stored credential and its monitor. Disconnecting an Outlook, Microsoft 365, iCloud or IMAP account does the same before removing its mail from the phone.
In Settings → Security → Server data, "Delete my data from server" deletes everything the server keeps for the accounts on this iPhone: device registrations with notification settings, the accounts' server authorizations and mail monitors; after that the app does not register again until you turn server notifications back on yourself. If scheduled messages are waiting on the server, cancel them first — until then the app refuses to delete the data, so that messages due to go out are not lost. Removing the app itself deletes only what it kept on the phone, not data on the server — use that button first.
You delete the app's state in iCloud with "Delete iCloud data" (Settings → Profile → iCloud) or in iOS Settings (your Apple Account → iCloud → storage management). You can stop sharing a draft at any time, and you delete files sent as links in Google Drive or OneDrive. You can also write to support@aorum.app to ask what server-side data is linked to you, and to have it deleted.
7. Who receives the data
- Mail providers (Google, Microsoft, Apple, or your own IMAP server) — your mail goes directly to them; that is your relationship with the provider, not with us.
- Google Cloud (europe-central2 region, Warsaw) — processes, on our behalf and as the infrastructure provider (data processor), the data of the push-notification service (section 2.5), of scheduled sending from the server (section 2.6) and of server mail notifications for Outlook, Microsoft 365, iCloud and IMAP (section 2.14), including the encryption keys in Google Secret Manager.
- Apple — delivers notifications to your iPhone through APNs.
- Providers of your own services, which we do not control: Apple (iCloud and CloudKit — app state, shared drafts and comments), Google (Google Drive) and Microsoft (OneDrive) — large attachments as links. They process data under your own agreement with them; they are not our data processors.
- Web servers of recipients' domains — when the app looks up a recipient's OpenPGP key (WKD), the server of their domain sees your phone's IP address and the address that was looked up (section 2.11).
- Certificate authorities — when checking an S/MIME certificate, iOS may ask the server of the authority that issued it; that server sees your phone's IP address (section 2.11).
- People you choose yourself — the recipients of your messages, people invited to a shared draft, and anyone who has the link to a file.
We do not pass data to any other company; the server uses no analytics or advertising tools.
8. Your rights
Under GDPR you have the right to access your data, have it corrected, deleted, have its processing restricted, request data portability, and object to processing. You can also withdraw consent for any feature at any time in the app's or iOS's Settings. You have the right to lodge a complaint with your national data-protection authority.
9. Changes to this policy
We may update this policy as the app evolves. The date of the last change is shown at the top of the page. Material changes to the scope of processing will be announced in the app.
10. Contact
For data-protection matters, write to support@aorum.app.