Privacy Policy
Last updated: 10 September 2026
GigaMail is software you install and run on your own computer. It has no servers, no accounts and no backend. We do not receive, store or see your mail, your calendar or your files.
Who this policy is from
GigaMail is published by Adecubed. It is open-source software licensed under the AGPL-3.0; the source is at github.com/adecubed/gigamail. Questions about this policy: founder@adecubed.com.
What GigaMail accesses
Only what you connect, and only while it runs on your machine.
- Email — through Microsoft Graph or your IMAP and SMTP servers, using credentials you supply.
- Google Calendar — events on your primary calendar, read and written through the calendar.events scope, if you connect a Google account.
- Google Drive — through the drive.file scope, which grants access only to files GigaMail itself created. GigaMail cannot see the rest of your Drive, and does not ask to.
- Your email address and basic profile — to show which account is connected.
Where the data goes
Nowhere we control. Your mail, events and file contents move between your computer and your own providers. They are held on your machine, in the application data directory of your user account.
Access tokens are kept in memory only. Refresh tokens and mailbox passwords are encrypted at rest; on Windows the encryption key is itself protected by the operating system and bound to your user account, so copying the files to another machine does not make them readable.
The AI agent you choose
GigaMail exists to give an AI agent access to your mailbox. That agent is not part of GigaMail: it is a separate program you choose and configure, such as Claude Code or Codex CLI. When it drafts a reply, summarises a thread, reads an attachment or proposes a meeting time, the relevant content — including Google Calendar events and the text of Drive files GigaMail created — is sent to that agent and therefore to its provider, under that provider's own terms and privacy policy. This is the one path by which your data leaves your machine, and it happens because you asked for it.
GigaMail does not choose the agent for you and sends nothing to any provider of its own.
Google user data: limited use
GigaMail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely:
- Google user data is used only to provide the features you invoke.
- It is never sold, and never used for advertising or profiling.
- No human at Adecubed reads it. We have no way to: it never reaches us.
- It is transferred only to the AI agent you configured, to perform the action you asked for.
Actions that change something need your approval
Sending or replying to mail, deleting messages or folders, moving a message, creating or deleting a calendar event, uploading a file to Drive or moving one to the trash: none of these happen because the agent decided to. Each one stops and waits for a human approval given separately, behind your device's own authentication. The agent cannot grant that approval and cannot bypass it.
Retention and deletion
Everything GigaMail stores lives in a directory on your computer. Disconnecting an account deletes its stored credentials and revokes the token with the provider. Uninstalling GigaMail and deleting that directory removes everything. There is nothing held elsewhere for us to delete on your behalf.
You can also revoke GigaMail's access to your Google account at any time from your Google Account permissions page, independently of the application.
Children
GigaMail is a tool for professional email and is not directed at children under 13.
Changes to this policy
Changes are published on this page with a new date at the top. The history of the file is public in the repository, so you can see exactly what changed and when.