Privacy Policy
This policy explains how zora, an email client for macOS (“zora”, “the app”), handles your data, including the data it receives from Google when you sign in with a Google account. zora is developed by Piotr Wittchen (“we”, “us”).
In short: zora runs entirely on your Mac. Your mail, contacts and credentials are stored only on your device and are sent only to your own email provider (for Gmail, to Google) and, only if you turn on the optional AI features, to the AI provider you choose with your own API key, and, only if you turn on the MCP server, to apps such as Claude Code that you connect to it on your Mac. We do not operate any server that receives your email data, we never sell or share it, and we do not use it for advertising, analytics or training AI models. The app contains no analytics, tracking or telemetry. Only this website uses cookieless visitor analytics.
1. Data zora accesses
Google account data
When you add a Gmail account, you sign in with Google in your web browser and grant zora the following permissions (OAuth scopes):
https://mail.google.com/— read, compose, send and manage your Gmail messages. This is the only scope Google accepts for the IMAP and SMTP protocols zora uses to work with your mailbox.openid,emailandprofile— your email address and name, used to identify the account inside the app.
Through these permissions zora accesses your email messages (headers, bodies and attachments), threads, labels and folders, drafts, read/starred state, and the email addresses and names of the people you correspond with.
Other email accounts
For IMAP/SMTP accounts, zora accesses the same kinds of mail data from the mail server you configure, using the email address and password you enter.
What zora does not access
zora does not access your contacts, calendar, Google Drive, location, microphone or camera. To pick a light or dark appearance by time of day, the app estimates sunrise and sunset from your Mac's time zone setting, on the device.
2. How zora uses your data
zora uses your data only to provide the email features you see in the app and use directly:
- showing your mailboxes, labels, threads and messages, and keeping them in sync;
- composing, replying to, forwarding and sending email, and saving drafts;
- archiving, deleting, labeling, starring, moving and marking messages as read, spam or unread when you ask it to;
- suggesting recipients from addresses you have exchanged mail with;
- showing new-mail notifications and the unread count on the Dock icon;
- letting you read cached mail while offline;
- summarizing conversations, suggesting replies and helping you write, only if you turn on the optional AI features (see section 4);
- letting an MCP client you set up, such as Claude Code, read and organize your mail and save drafts, only if you turn on the MCP server (see section 4).
zora does not use your data for advertising, profiling, analytics, or to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models.
The app contains no analytics, tracking or telemetry. The only things we count are downloads, trials and license activations, and only to sell and license zora (see section 4).
3. Where your data is stored
- Mail data is cached in a local database and attachment folder on your Mac, in the app's data and cache directories (
~/Library/Application Support/com.pwittchen.zoraand~/Library/Caches/com.pwittchen.zora). - Credentials — Google OAuth tokens, IMAP/SMTP passwords, any AI provider API keys you add and the MCP server's token — are stored only in your macOS Keychain, never in plain files.
- Settings such as theme and appearance are stored locally on your Mac.
None of this data is uploaded to us or to any server we operate. The app's diagnostic logs stay on your Mac and never contain message contents, subjects, addresses, tokens or passwords.
4. How your data is shared and transferred
We do not sell, rent or share your data, including Google user data, with anyone. zora's network connections are limited to:
- Google (for Gmail accounts): Google's sign-in and token endpoints, and Gmail's IMAP and SMTP servers, to sign you in and to read, send and manage your mail.
- Your mail provider (for IMAP/SMTP accounts): the IMAP and SMTP servers you configure.
- AI providers, only if you turn on AI features. AI features are off by default. If you turn them on in Settings and add your own OpenAI or Anthropic API key, zora sends the conversation you have open (its subject, messages, and the names and addresses of the people in it) to summarize it or suggest replies, and any text you ask it to polish or write a message from, directly from your Mac to the provider you chose. This happens under your own account with that provider and its terms and privacy policy; nothing goes through us. To stop, turn AI features off or remove the key in Settings.
- MCP clients you connect, only if you turn on the MCP server. The MCP server is off by default. If you turn it on in Settings → AI, zora accepts connections only from your own Mac (127.0.0.1), and only from apps that present the secret token you copy from Settings. A client you set up this way, such as Claude Code, can search and read your conversations (their subjects, messages, and the names and addresses of the people in them), mark, star, label, archive or trash them, and save drafts. It can't send mail. What the client reads is then handled by that app and the AI provider it uses, under your own account and their terms and privacy policies. None of it goes through us. To stop, turn the MCP server off. To disconnect clients you set up earlier, make a new token.
- Remote images, only if you choose to load them. Images embedded in emails are blocked by default. If you click Show images, zora downloads them from the sender's servers on your Mac, without your cookies or the original referrer, so senders can't track you through them.
- Licensing, trials and updates. When the app starts a trial, activates a license or checks for updates, it sends only the license key, a random installation ID and the app version. We use these requests, together with download counts, only to handle trials, purchases and licenses. They never contain email data or Google user data.
Purchases are handled by a third-party payment provider under its own privacy policy. We may disclose information only if required by law, and since we do not hold your email data, we have none of it to disclose.
5. Google API Services User Data Policy
zora's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google user data is used only to provide and improve user-facing email features that are visible in the app's interface.
- Google user data is not transferred to others, except as needed to provide those features (such as sending a conversation to the AI provider you chose when you use the optional AI features, or to an MCP client you connected), to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you.
- Google user data is not used or transferred for serving advertisements, including retargeting, personalized or interest-based ads.
- Nobody reads your Google user data. It never leaves your Mac except to go to Google, to the AI provider you chose if you turn on AI features, or to an MCP client you connect if you turn on the MCP server, so we have no access to it.
- Google user data is not used to develop, improve or train generalized AI or machine learning models.
6. Retention and deletion
Your mail data is kept on your Mac for as long as the account is added in zora, so the app can show it and work offline. You are in control of deleting it:
- Remove the account in zora (Settings → Accounts, or Sign out). This deletes the account's tokens or password from the Keychain and its cached mail, attachments and contacts from your Mac.
- Revoke zora's access to your Google account at any time at myaccount.google.com/permissions. zora then can no longer access your Gmail.
- Remove your AI API keys in Settings → AI features. Anything already sent to an AI provider is kept according to that provider's policies.
- Turn off the MCP server in Settings → AI, and remove zora from your MCP client (in Claude Code,
claude mcp remove zora). Anything a client has already read is kept according to that client's and its AI provider's policies. - Uninstall the app. Delete zora from the Applications folder and remove the folders listed in section 3 to delete all remaining local data.
Removing an account from zora does not delete any mail from your Gmail or mail server.
7. Security
zora connects to Google, to mail servers and to AI providers over encrypted connections (TLS). Sign-in with Google uses OAuth 2.0 with PKCE in your own browser, so zora never sees your Google password. Credentials and AI API keys are kept in the macOS Keychain. The optional MCP server listens only on your Mac and refuses any request without its token, which is also kept in the Keychain. All HTML email content is sanitized before it is displayed, with scripts and remote content blocked.
8. This website
This website uses DataFast cookieless analytics to count visitors and see which pages they view and where they come from. It sets no cookies and does not collect your email data. DataFast processes this information under its own privacy policy. Apart from that, the website only remembers your light or dark preference in your browser's local storage.
This analytics runs only on the website. The zora app itself contains no analytics, tracking or telemetry.
9. Children
zora is not directed at children under 13, and we do not knowingly collect personal information from children.
10. Changes to this policy
If we change how zora handles your data, we will update this page and its effective date before the change takes effect. Significant changes will also be announced in the app's release notes.
11. Contact
If you have any questions about this policy or your data, contact Piotr Wittchen at [email protected].