🔒 App Store Privacy Policy

Privacy Policy

This policy describes how CF Mail handles information across standard IMAP/SMTP accounts, self-hosted CloudMail accounts, local diagnostics, notifications, contacts, and this website.

Run your own CloudMail Server

The server is open source. Deploy it privately, use your own domain, and connect it to CF Mail.

GitHub

1. Overview

CF Mail is an iOS mail client that supports standard IMAP/SMTP accounts and self-hosted CloudMail Server accounts. This Privacy Policy explains how CF Mail handles information when you use the iOS app and the official CF Mail website.

Key principle: CF Mail is designed as a client. Standard email data is exchanged with the email provider you configure. CloudMail data is exchanged with the CloudMail Server you configure. The current iOS app does not include advertising SDKs or behavioral analytics SDKs.

2. Information handled by the app

CategoryHow it is usedWhere it goes / is stored
Account identifiers and credentialsAuthenticate to your email provider or CloudMail Server.Credentials and tokens are stored using iOS Keychain where applicable and transmitted only as needed to the configured service.
Email content and metadataDisplay, search, compose, send, receive, and manage mail.Transferred between your device and the email provider or CloudMail Server you choose. CF Mail may cache message lists, downloaded attachments, and search data locally for performance and offline use.
ContactsOptional recipient suggestions while composing.System Contacts access is optional. Contact data is used on device for recipient selection. Recent mail contacts may also be learned and stored locally.
Notification informationNotify you about new mail.Standard IMAP/SMTP accounts use local notifications. CloudMail accounts may register an APNs device token with the CloudMail Server you configured so that server can send remote notifications through Apple Push Notification service.
DiagnosticsTroubleshoot app, network, API, IMAP/SMTP, sync, and lifecycle issues.Redacted diagnostics stay on device by default. They are not uploaded automatically. A diagnostic package leaves the device only when you explicitly export or share it.
Website request dataDeliver and protect this static website.The website itself intentionally uses no advertising pixels or behavioral analytics. The hosting/network provider may process standard request metadata such as IP address, user agent, and timestamps for delivery, reliability, and security.

3. Standard IMAP/SMTP accounts

When you add a Gmail, iCloud, Outlook, Yahoo, Fastmail, QQ, NetEase, Zoho, AOL, GMX, Yandex, Mail.ru, or other IMAP/SMTP-compatible account, CF Mail communicates with that provider to perform the mail actions you request. Those providers process information under their own privacy policies and account terms.

For supported providers using OAuth, authorization and token exchange occur with the applicable identity/email provider. CF Mail does not embed a provider client secret in the iOS application.

4. Self-hosted CloudMail

CloudMail accounts connect to the CloudMail Server address you configure. The operator of that server determines its server-side retention, access controls, logs, and administrative practices. If you operate your own CloudMail instance, you control those server-side practices. If another person or organization operates it, contact that operator for server-side privacy or deletion requests.

CloudMail remote push may require the app to send its APNs device token to the configured CloudMail Server. The token is used to address notifications for this app/device through Apple Push Notification service.

5. Local storage and security

  • Credentials and authentication tokens use iOS Keychain where applicable.
  • Downloaded attachments, mailbox lists, search indexes, drafts, preferences, and related working data may be stored locally so the app can function efficiently.
  • The app can use Face ID, Touch ID, or the device passcode to protect access to mail and account settings.
  • Local app data is subject to iOS platform security controls and the security of your device.

6. Diagnostics and logs

CF Mail keeps bounded diagnostic information locally to help troubleshoot problems. The current project is designed to retain up to seven days / seven rotating diagnostic files, approximately 2 MB each. Diagnostic files use iOS Data Protection and are excluded from iCloud backup.

Before export, authorization data, email addresses, message subjects, bodies, and attachment contents are redacted or excluded according to the app's diagnostic design. Diagnostic packages are not uploaded automatically.

7. Remote images in email

Remote images can cause a third-party image server to learn network information such as your IP address and when an image was requested. CF Mail therefore provides mail privacy controls that let you block remote images, ask before loading them, or always load them. Your choice affects what the external image host can observe.

8. Sharing and third parties

CF Mail does not sell personal information and the current iOS project does not integrate advertising networks or behavioral analytics SDKs. Information may nevertheless be processed by services necessary to the functionality you choose, including:

  • your email provider or identity provider;
  • the CloudMail Server you configure;
  • Apple services such as APNs and platform security/authentication features;
  • a service you explicitly choose from the iOS share sheet when exporting diagnostics or other content.

Each external service is governed by its own terms and privacy practices.

9. Retention and deletion

You can clear regenerable local cache data and local diagnostic logs from the app. Removing an account removes the app's local connection state for that account. “Reset All Data” clears local accounts, credentials, configured CloudMail Server information, drafts, cache, preferences, and diagnostic data, returning CF Mail to its first-install state.

A local reset does not delete mail or other information stored by an email provider or CloudMail Server. To delete server-side information, use the controls offered by that provider/server or contact its operator.

10. Your choices

  • Choose whether to grant Contacts access in iOS Settings.
  • Enable or disable app lock with Face ID / Touch ID / device passcode where available.
  • Choose the remote-image policy for mail.
  • Control notifications in CF Mail and iOS Settings.
  • Clear local cache and diagnostics, remove accounts, or reset all local app data.
  • For server-side access, correction, or deletion requests, use the controls of the relevant email provider or CloudMail Server operator.

11. This website

This website is intentionally implemented as static HTML. It does not intentionally set advertising cookies, load third-party advertising pixels, or run behavioral analytics scripts. Network and hosting infrastructure may create security and access logs needed to serve the site.

12. Children

CF Mail is a general-purpose email client and is not designed specifically for children. Users should comply with the age and account requirements of their email provider and any applicable CloudMail Server.

13. Changes to this policy

We may update this policy when CF Mail features or data practices change. The effective date at the top of this page will be updated when material changes are published.

14. Contact

For privacy or support questions about CF Mail, email support@readori.com or visit cfmail.readori.com. For information controlled by an external email provider or a self-hosted CloudMail Server, contact that provider or server operator directly.