QuickMail Privacy Policy

Effective date: September 24, 2026. Replaces the version dated August 27, 2026.

Short version: QuickMail is a Windows desktop application with no servers of its own. Your mail, contacts, and calendar travel between your computer and the accounts you already have. Nothing you read, write, or receive is sent to the developer, and QuickMail collects no analytics or telemetry. The only information that ever reaches the developer is a bug report you choose to send — and you see its full text before it goes.

What QuickMail is

QuickMail is a free, open-source Windows desktop email client, built to be used with a keyboard and with screen readers. It runs entirely on your computer. There are no QuickMail servers that hold your mail, there is no account to create with the developer, and there is no cloud sync. QuickMail's source code is public at github.com/kellylford/QuickMail, so every claim on this page can be checked against the code that makes it.

What QuickMail stores, and where

Everything QuickMail keeps is stored on your computer, in your profile directory — normally %APPDATA%\QuickMail. Nothing in that folder is uploaded anywhere by QuickMail.

Files QuickMail writes to your profile directory
FileWhat it holds
mail.dbThe local SQLite cache of messages you have synced — headers and message bodies, so mail can be read and searched without waiting on the network.
accounts.jsonYour account settings: email addresses, server names, ports, security settings, signatures, and display preferences. Never passwords.
contacts.json, groups.jsonContacts you typed in yourself, contact groups, and the read-only copies of contacts synced from accounts you opted in.
Calendar dataEvents copied from calendars you have connected, so the calendar works offline.
config.iniYour settings: theme, fonts, announcement preferences, keyboard customizations, saved views, and message-list field choices.
rules.json, templates, flagsMail rules, message templates, and the named flags you create. Mail rules run inside QuickMail only; your provider never sees them.
quickmail.log, connection.logDiagnostic logs. Both are off by default — see Logs, diagnostics, and screenshots.
debug-screenshots\Window screenshots, written only while the debug capture option is switched on. See Logs, diagnostics, and screenshots.

Passwords, app passwords, and sign-in tokens

QuickMail never writes a password or a token to accounts.json or to any other file in your profile directory. Passwords and app-specific passwords are stored in Windows Credential Manager — the encrypted credential store built into Windows — under your Windows account.

Accounts that sign in with Microsoft or Google use OAuth 2.0 instead of a password. You sign in on the provider's own page; QuickMail never sees your provider password. The provider issues QuickMail a refresh token, which is also stored in Windows Credential Manager on your device and is used to request the short-lived access tokens that each connection needs. Removing the account in QuickMail deletes the stored token.

Your mail, contacts, and calendar

QuickMail connects directly to the mail, contact, and calendar services of the accounts you add — over IMAP, POP3, and SMTP, over Microsoft Graph, or over CalDAV and CardDAV, depending on the account. There is no intermediary. Message content is processed on your computer and cached in mail.db.

Remote content in messages is blocked by default. The reading pane renders HTML mail under a strict Content Security Policy that permits no remote images, scripts, frames, forms, media, or network connections of any kind. On its own, a message cannot load a tracking pixel, phone home, or report that you opened it. Pictures sent inside a message are shown: QuickMail reads them from the message's own parts and hands them to the reading pane itself, from an address that never leaves your computer. The only server involved is your own mail provider, from which the message was read; the sender is never contacted. A setting turns this off.

Pictures on the web, only when you ask. A message can link to pictures on another server. QuickMail does not fetch them unless you choose Load Pictures for that message, or turn on Load pictures from the web automatically in Settings (off by default). When it does, QuickMail itself requests each picture from the server the message names, and that server learns your IP address, the time, and the picture's address — which may identify the message. QuickMail sends no cookies and no referrer, keeps no cookies it is given, contacts public internet addresses only, keeps the file only if it is a picture, never fetches pictures declared 2 pixels or smaller (the usual size of a tracking pixel), and keeps what it fetched in memory only while it runs. The reading pane still contacts nothing itself. Links you activate deliberately open in your default browser.

Google user data — specific disclosures

Signing in with Google is off by default and applies only to accounts that already had a Google authorization; new Gmail accounts normally connect with an app password over IMAP and SMTP. Where Google sign-in is used, QuickMail requests these Google OAuth scopes:

ScopeWhen requestedWhy
https://mail.google.com/ Whenever a Gmail account signs in with Google Full Gmail access (read, compose, send, organize, delete) — required to function as an email client
openid, email Whenever a Gmail account signs in with Google Confirms which address you signed in as, so the account is set up for the right mailbox
https://www.googleapis.com/auth/calendar Interactive sign-in, for calendar features Read your Google Calendar and create, edit, and delete events you act on in QuickMail
https://www.googleapis.com/auth/contacts.readonly
https://www.googleapis.com/auth/contacts.other.readonly
Only when you opt that account into contact sync Read your saved contacts and previously used recipients, so addresses autocomplete and appear in the address book

QuickMail uses this access only to:

QuickMail does not:

QuickMail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking Google access

To revoke QuickMail's access to your Google account at any time, visit Google Account Permissions and remove QuickMail. Removing the account in QuickMail immediately deletes the stored refresh token from Windows Credential Manager on your computer.

Microsoft user data — specific disclosures

Outlook.com, Hotmail, Live, and Microsoft 365 work or school accounts sign in through the Microsoft identity platform. Depending on how the account connects, QuickMail requests:

PermissionWhen requestedWhy
IMAP.AccessAsUser.All, SMTP.Send (Outlook) Accounts connecting over IMAP and SMTP with a Microsoft sign-in Read and send mail over the standard protocols
Mail.ReadWrite, Mail.Send, User.Read (Graph) Any account connecting over Graph, personal or work/school Read, organize, and send mail; confirm which mailbox you signed in as
MailboxSettings.ReadWrite (Graph) Work or school accounts Read and write the server-side mail rules QuickMail shows you
Mail.ReadWrite.Shared, Mail.Send.Shared (Graph) Only when you add a shared mailbox Read and send from a shared mailbox your organization has given you access to
Contacts.Read, People.Read (Graph) Only when you opt that account into contact sync Read your saved contacts and prior correspondents, read-only
Calendars.ReadWrite (Graph) Only when you connect that account's calendar Read your calendars and create, edit, and delete events you act on in QuickMail

As with Google, this access is used only to operate the email, contacts, and calendar features you see. Microsoft data is not shared with anyone, is not used for advertising or profiling, is not used to train machine learning models, and is not stored anywhere but your computer. To revoke access, visit your Microsoft account settings (work and school accounts: your organization's administrator can also revoke consent), or remove the account in QuickMail, which deletes the stored token.

iCloud accounts

iCloud mail connects over IMAP and SMTP, and iCloud contacts and calendars over CardDAV and CalDAV, using an app-specific password that you generate at Apple and that QuickMail stores in Windows Credential Manager. QuickMail talks to Apple's servers directly; nothing passes through the developer.

What leaves your computer, and to whom

These are every network destination QuickMail contacts, and what is sent to each.

DestinationWhenWhat is sent
Your own mail, contact, and calendar servers Whenever QuickMail syncs, sends, or you act on an item Your credentials or token, and the mail, contact, and calendar data of that account
Microsoft (login.microsoftonline.com) and Google (accounts.google.com) sign-in pages When you sign in or a token is refreshed Whatever you type on the provider's own sign-in page, and token refresh requests. QuickMail never sees your provider password.
Mozilla's public autoconfig database (autoconfig.thunderbird.net) Adding an account whose provider QuickMail does not recognize The domain of your address only — never the address itself
Your domain's own Autodiscover service Same lookup, if the previous step found nothing Your full email address, sent to your own mail provider's server
Cloudflare's public DNS resolver (cloudflare-dns.com) Same lookup, if the previous steps found nothing The domain of your address, in a DNS-over-HTTPS query for its MX and autodiscover records
GitHub (api.github.com, github.com) Each time QuickMail starts, to check for a newer release; and to download an update A request for the public release list, identified only by the QuickMail version in the user agent. No account, mail, or usage data.
QuickMail's bug-report relay (a Cloudflare Worker) Only when you choose Send in Report a Bug The report you wrote and previewed — see Bug reports
The servers a message's pictures are on Only when you choose Load Pictures for a message, or have turned on Load pictures from the web automatically (off by default) A plain request for each picture's address, from your IP address, with no cookies and no referrer. Only public internet addresses are contacted.
Your default browser When you activate a link, open the user guide, or open a release page Whatever the browser sends for the address you opened. Once a link is handed to the browser it is outside QuickMail.

The three lookup steps that go to Mozilla, your domain's Autodiscover service, and Cloudflare's DNS resolver can all be switched off: set AutoDiscoverOnline = off in config.ini. QuickMail's built-in provider list keeps working offline either way. The update check can be reduced to notification-only in Settings → Advanced → Updates.

Bug reports

Report a Bug in the Help menu is the one feature that sends anything to the developer, and it sends nothing unless you fill it in and choose to send it. The report window shows a Preview of the complete text as you type, so you see exactly what will be sent before it leaves your computer.

A report contains:

A report never contains:

A sent report becomes a public GitHub issue on the QuickMail repository, filed by a bot account, and is readable by anyone. Do not type anything into a report you would not publish. The report travels through a small relay service (a Cloudflare Worker run for this purpose), which holds the credential that files the issue and rate-limits requests by IP address; it stores no report content of its own. If the relay is unavailable, QuickMail falls back to copying the report to your clipboard and opening a pre-filled GitHub issue page, which you submit yourself.

The Help menu also offers Copy report and open GitHub, which files under your own GitHub account, and you can email support@theideaplace.net instead. Both attach your identity by design, so a reply is possible; the in-app Send path does not.

Logs, diagnostics, and screenshots

All of QuickMail's diagnostic outputs stay on your computer. None of them is uploaded, and none is attached to a bug report.

Delete QuickMail logs in Settings → Advanced deletes all three immediately: the application log, the connection log, and every saved screenshot.

Analytics and telemetry

QuickMail collects no analytics, usage statistics, crash reporting, or telemetry of any kind. There is no identifier assigned to you or to your installation, and nothing reports that QuickMail has been launched or used. The update check asks GitHub for a public list of releases; that is the whole of QuickMail's routine contact with anything the developer runs.

Data retention and deletion

The developer holds no data about you, so there is nothing to request or erase — except a bug report you chose to send, which is a public GitHub issue you can ask to have deleted by emailing the address at the bottom of this page.

Everything else is on your computer and under your control. To remove all of it, delete the %APPDATA%\QuickMail folder, and remove QuickMail's saved credentials from Windows Credential Manager. Uninstalling QuickMail does not delete either automatically. To cut a provider's connection at the provider's end, revoke access as described in the Google and Microsoft sections above.

Children's privacy

QuickMail is not directed at children under 13 and does not knowingly collect information from children.

Changes to this policy

If this policy changes materially, the updated policy will be published at this URL with a new effective date. Every revision is visible in the file's history in the QuickMail GitHub repository.

Contact

For privacy questions or concerns, contact: kelly@theideaplace.net