Privacy Policy
Effective date: August 31, 2026
1. Who we are
Alteox s.à r.l. ("Alteox", "we", "us", or "our"), a company registered in Luxembourg, develops and publishes Bréifkëscht Mail (the "App") and operates the website https://breifkescht.app (the "Site"). This Privacy Policy explains what data the App and the Site handle, why, how long it is kept, and how you can delete it.
For any privacy question, or to exercise the rights described in section 12, contact us at hello@alteox.com.
2. Summary: Bréifkëscht is a local email client
Bréifkëscht is a standalone email client that runs entirely on your own device. It connects directly to the mail servers of the accounts you add, using the standard IMAP, SMTP, JMAP, CalDAV and CardDAV protocols.
We do not operate any server that stores, relays, proxies, or processes your email. Alteox has no user accounts, no cloud sync service, and no mailbox backup service. Your messages travel between your device and your mail provider, and nowhere else. We cannot read your email, because it never reaches us.
The only Alteox-operated service the App ever contacts is our self-hosted crash-reporting endpoint, which is disabled by default and described in section 8.
3. Google user data the App accesses
If you choose to add a Gmail or Google Workspace account, the App uses Google's OAuth 2.0 sign-in so that you never have to give the App your Google password. You are shown Google's own consent screen, and you grant the following scopes:
- https://mail.google.com/ — required to authenticate to Gmail's IMAP and SMTP servers using the XOAUTH2 mechanism. This is the only scope Google offers that authorises IMAP and SMTP access; narrower Gmail API scopes do not work with these protocols. The App uses it solely to fetch and display your messages and folders, to send messages you write, and to carry out actions you take yourself (marking read or unread, flagging, moving between folders, and deleting).
- openid and email — used only to learn the email address of the account you signed in with, so the App can label the account correctly. We do not build a profile from this.
Message content retrieved from Google (headers, message bodies, folder structure, and attachment metadata) is stored only in the App's encrypted local database on your device, and is used only to display and manage your mailbox inside the App. Attachment file contents are downloaded on demand and are not retained in the database.
We do not request access to your Google Contacts, Google Calendar, Google Drive, or any other Google service.
4. How we use your data, and what we never do with it
Data obtained through Google APIs, and email data generally, is used for one purpose only: to provide the mail-client features you are actively using on your own device. We do not use it for any secondary purpose.
Specifically, we do not:
- sell or rent your data to anyone, ever;
- transfer your data to third parties, except as strictly necessary to deliver the features described in section 9;
- use your data for advertising, ad targeting, ad personalisation, or ad measurement;
- use your data for credit assessment, lending, insurance, or employment decisions;
- read, review, or allow any human to access your email, other than the automated processing that happens on your own device;
- use your data to develop, improve, or train artificial-intelligence or machine-learning models (see section 5);
- aggregate, profile, or monetise your email content in any form.
Bréifkëscht's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Artificial intelligence and machine learning
Bréifkëscht contains no artificial-intelligence or machine-learning features. It does not summarise, classify, autocomplete, or otherwise analyse your email using AI or ML, and no email content is ever sent to any AI or ML service.
We do not use Google Workspace APIs data to develop, improve, or train generalised or non-personalised artificial-intelligence or machine-learning models. We do not permit any third party to do so with data obtained through the App.
Features such as thread grouping, priority detection, and unsubscribe links are implemented as deterministic rules that read standard email headers on your device. No content leaves your device for any of them.
6. Where your data is stored, and how it is protected
All mail data the App keeps is stored locally on your device, inside an encrypted SQLite database. Encryption is always on and cannot be disabled. The database encryption key is generated on your device using a cryptographically secure random source and is held in your operating system's secure credential store.
Your credentials are stored in the same operating-system secure store, never in the App's database and never in plain text:
- Apple Keychain on macOS and iOS;
- Android Keystore-backed encrypted storage on Android;
- Data Protection API (DPAPI) on Windows;
- libsecret on Linux.
For Google accounts, this means the OAuth refresh and access tokens are held in your device's secure store. They are never transmitted to Alteox, because there is no Alteox server to transmit them to.
Two caveats we want to be explicit about. First, when you open an attachment, the App must write a decrypted copy of that file to a private folder on your device so that another application can open it; you can delete these copies at any time under Settings → Opened attachments → Clear, and you can cap or disable this storage entirely. Second, if you use an operating-system backup service such as Time Machine, iCloud Backup, or Android Backup, a copy of the encrypted database may be included in those backups under the terms of whichever service you use.
Connections to mail servers and to Google use TLS. Remote images in messages are blocked by default, so simply opening a message does not disclose your IP address to a sender.
7. Data retention
Because Bréifkëscht stores data only on your device, retention is under your control, and Alteox retains nothing.
- Messages, folders, contacts, and calendar entries synced from your accounts remain in the App's local encrypted database for as long as the account is present in the App. The App mirrors your mail server: when a message is deleted on the server, the local copy is removed on the next sync.
- OAuth tokens remain in your device's secure store until you remove the account, or until they are revoked or expire.
- Decrypted copies of attachments you have opened are kept within a size limit you choose in Settings, oldest removed first, and can be cleared at any time. Setting the limit to zero means no copies are kept beyond your current session.
- Cached sender images, if you have enabled that optional feature, are kept until you turn the feature off, which deletes the cache.
- Crash reports, if you have enabled crash reporting, are retained on our self-hosted crash-reporting server only for as long as needed to diagnose and fix the underlying problem, and are then deleted. They contain no email content and no credentials.
Removing an account from the App, or uninstalling the App, ends retention as described in section 8.
8. Deleting your data and revoking access
You can delete everything at any time, without contacting us.
Removing a single account. In the App, go to Settings → Accounts and remove the account. The App then, in order: asks Google to revoke the App's access token by calling Google's official token-revocation endpoint (https://oauth2.googleapis.com/revoke); deletes that account's password, refresh token, and access token from your device's secure store; and deletes the account together with all of its messages, message bodies, attachment metadata, folders, search-index entries, drafts, queued outgoing messages, contacts, address books, and calendar entries from the local database. If credential deletion fails for any reason, the account is deliberately kept so that you can retry, rather than leaving orphaned credentials behind.
Deleting the remaining local files. Decrypted copies of attachments you previously opened are removed under Settings → Opened attachments → Clear. Cached sender images are removed by switching the sender-pictures setting off.
Deleting everything. Uninstalling the App removes its local database and its files. Depending on your operating system, entries in the secure credential store may need to be removed separately by your OS; on all platforms, removing your accounts inside the App before uninstalling deletes them.
Revoking access independently of the App. You can revoke Bréifkëscht's access to your Google Account at any time, whether or not you still have the App installed, at https://myaccount.google.com/permissions. Revoking access stops all further synchronisation immediately.
Because we hold no copy of your mail, there is nothing for us to delete on our side. If you have enabled crash reporting and want the associated diagnostic reports deleted, email hello@alteox.com and we will delete them.
9. Third parties
The App contains no advertising SDKs, no analytics SDKs, and no tracking or attribution SDKs. We share no App data or Google user data with advertisers, data brokers, or analytics vendors. (Website visitor analytics on breifkescht.app is a separate matter, described in section 10; it receives no App data.) The complete list of parties that can receive any data as a result of using the App is as follows.
- Your own mail and calendar providers, including Google when you add a Gmail account. This is inherent to using an email client: the App connects to them on your behalf.
- Our self-hosted crash-reporting service (Sentry, operated by Alteox on our own infrastructure at sentry.alteox.app). Crash reporting is off by default. When you switch it on in Settings → Privacy, the App may send diagnostic reports containing the error type, a scrubbed error message, a stack trace, and your app version, operating-system version, and device model. Before any report is sent, the App automatically removes email addresses, access and refresh tokens, passwords, and authentication credentials from it. Email subjects, message bodies, attachments, and contact lists are never included, and we do not attach your IP address or identity to reports. You can switch crash reporting off again at any time, with immediate effect.
- DNS-over-HTTPS resolvers (Cloudflare at cloudflare-dns.com and Google at dns.google) and the Mozilla ISPDB (autoconfig.thunderbird.net). When you add an account, the App may need to look up which mail servers your email domain uses. Only the domain part of your address is sent, never the full address, and this only happens for domains not already in the App's built-in list of known providers.
- unavatar.io, only if you enable the optional "sender pictures" feature, which is off by default. When enabled, the domain of a correspondent's address is sent in order to retrieve a logo.
- The operator of an unsubscribe link, only when you personally choose to unsubscribe from a mailing list.
- Hosts referenced inside a message's HTML, only if you enable remote images, which are blocked by default.
We do not transfer Google user data to any third party for any purpose other than those listed above.
10. The website (separate from the App)
The Site is a marketing website. It is entirely separate from the App, and the two share no data.
The Site uses Google Analytics and Google Tag Manager to measure website traffic — for example which pages visitors open, approximate location derived from IP address, and browser and device type. This measurement covers visitors browsing the website only.
To be unambiguous: no email content, no mailbox data, and no data obtained from Google APIs through the App is ever sent to Google Analytics, to Google Tag Manager, or to any other analytics or advertising service. The App contains no analytics or advertising components at all. Website visitor statistics and your mailbox are completely separate, and we do not combine them.
The Site sets cookies for analytics as described above, and, if you vote on a feature suggestion, a cookie containing a random identifier so that the same suggestion is not counted twice. You can block or delete these cookies in your browser, and you can opt out of Google Analytics entirely using Google's opt-out browser add-on. Blocking them does not affect the App.
If you submit a feature suggestion through the Site, the text you submit is sent to us by email so that we can read it. Your IP address is used transiently, in memory only, for rate limiting, and is not stored.
11. Children
The App is not directed at children under 16, and we do not knowingly collect data from them. Because the App holds data only on the user's own device and we operate no accounts, we have no means of identifying a user's age.
12. Your rights
Alteox is established in Luxembourg, and the General Data Protection Regulation (GDPR) applies to our processing. Under the GDPR you have the rights of access, rectification, erasure, restriction, objection, and data portability, and the right to lodge a complaint with a supervisory authority — in Luxembourg, the Commission nationale pour la protection des données (CNPD).
In practice, for email data these rights are satisfied directly and immediately by you, because that data lives on your device and we hold no copy of it: you have full access to it in the App, and you can erase it as described in section 8. The only personal data we may hold is a crash report you have chosen to send us, and any email correspondence you initiate with us.
To make a request regarding data we hold, contact hello@alteox.com. We will respond within 30 days.
Our lawful basis for processing crash reports is your consent, which you give by enabling the setting and can withdraw at any time by disabling it.
13. Changes to this policy
We may update this policy. When we do, we will change the effective date at the top of this page. If a change materially reduces the protections described here, we will give notice in the App before it takes effect. We will not apply a materially different handling of previously collected data without your consent.
14. Contact
Alteox s.à r.l., Luxembourg. Privacy and data-protection enquiries: hello@alteox.com. Product support: sven.breckler@alteox.com.
