Privacy

Privacy policy

The Mail & Calendar apps are local-first: your mail stays between your device and your own provider. This page explains the little that can ever reach us — all of it opt-in.

Version 1.4 · Effective: 2026-07-22

Allodia Mail & Calendar is a mail and calendar app that runs on your device and connects to the mail provider you choose. This policy explains, in plain language, what that means for your data: what stays on your device (almost everything), what the app sends and to whom (by default, nothing to us), and the one thing you can choose to share with us (usage statistics — off unless you switch it on).

The short version

  • Your mail never touches Allodia. The app syncs directly between your device and your own mail provider. We are not in that path, we have no servers in that path, and we cannot read your mail, your events, or your credentials.
  • By default, the app sends us nothing. No telemetry, no crash reports, no identifiers — not even the fact that you installed it.
  • One optional exception, and you decide. At first start the app asks whether you want to share usage statistics. The switch is off; the app shows you the exact data before you decide; saying no costs you nothing and is remembered. You can withdraw in one click at any time.
  • We never sell data, never show ads, never profile you, and never use third-party analytics or tracking services. Anything we do receive stays on servers we ourselves operate in the EU.
  • Your rights are the GDPR's, and most of them you can exercise directly in the app — the data is already in your hands.

1. Who we are

Allodia ("Allodia", "we"), registered with the Dutch Chamber of Commerce (KvK) under no. 56789823, Kamerlingh Onnesweg 2, 3316GL Dordrecht, the Netherlands.

For anything in this policy: info@allodia.eu.

We are the "controller" only for the little that actually reaches us: optional usage statistics (§5), messages you send us (§6), and the website (§8). For everything the app processes on your device, we are neither controller nor processor — we never receive it (§2).

2. The default: everything stays on your device

The app stores your mail, calendar events, attachments, account settings, and a local diagnostic log on your device. None of it is uploaded to Allodia. There is no Allodia account, no cloud copy, no backend of ours holding your content.

The only network connections the app makes by default are between your device and the mail and calendar providers you connect — over open standards (IMAP, SMTP, JMAP, CalDAV) or a provider's own API (e.g. Microsoft 365, or Google for Gmail + Google Calendar). Your provider processes your mail under its terms and privacy policy, exactly as it would with any other mail app; connecting it here changes nothing about that relationship — and does not add us to it.

Signing in to a provider that uses OAuth (e.g. Microsoft 365, Google, or a JMAP server such as Fastmail) happens in your system browser, directly between you and the provider. Allodia operates no sign-in server, never sees your password, and the resulting tokens are stored only in your device's secure keystore.

For a JMAP account the app can offer this sign-in even for a provider we have never integrated, by reading what your server itself publishes: it asks your server where its sign-in service is and what permissions exist, then registers itself with that server as an app on your device. Three things bound it. Those requests go only to your own mail server — never to Allodia, and never to any third party. Only your domain is involved, never your full email address, until you reach your provider's own sign-in page. And the app asks for the narrowest permissions that let it do its job — your mail and your calendars, and permission to stay signed in — never your contacts or anything else your server may offer. If your server does not publish this, nothing is sent and you simply sign in with a password or an API token as before.

Privacy protections that are built in, on every platform:

  • Remote images in messages are blocked by default. Tracking pixels are remote images; a message cannot report that you opened it. You can load images per message, and the choice resets on the next message (§4).
  • Message HTML is sanitized and scripts never run. A message cannot execute code, navigate the app, phone home, or read anything on your device.
  • The diagnostic log never contains content. It records counts, durations, and technical events — never message content, subjects, addresses, or credentials — is capped at a few megabytes, and stays on your device unless you yourself choose to send it to us (§6).
  • New-mail notifications are generated on your device. No notification service of ours sees your mail. Whether a preview (sender, subject) appears on your lock screen follows your OS notification settings.
  • Credentials live in the platform keystore (Keychain, Windows Credential Manager, Android Keystore) — never in the app's database. The message store is protected by your device's encryption at rest.

Finding your settings when you add an account. So you don't have to type server names, the app can work them out from your email address when you ask it to. It looks in the standard places for your provider's published settings: the mail, JMAP, and calendar autodiscovery addresses on your own email domain and your provider's domain, a normal DNS lookup for your provider's mail host, and the Thunderbird project's public autoconfig database (autoconfig.thunderbird.net, run by MZLA/Mozilla) — a shared directory of provider settings. Two rules bound all of it: only your domain is ever sent, never your full email address; and everything is attempted over HTTPS — a settings source reached any other way is shown to you as untrusted and is never used to connect until you approve it. No password is involved (this happens before you sign in), Allodia receives none of it, and "Set up manually" skips the lookup entirely.

Today the app has no AI features, no Allodia account, and no cloud services of ours. If we add a feature that changes how data is handled, we will update this policy first, and anything that would send new data will ask you before it sends.

3. Data you are not required to provide

None of it. There is no legal or contractual requirement to provide us any personal data, and the app is fully functional if you never send us anything and leave every optional switch off.

4. Things that happen only when you act

Some actions in a mail app necessarily send data somewhere — but to parties you choose, at the moment you choose, never via Allodia:

  • Connecting an account sends your credentials to that provider and syncs your mail with it.
  • Loading remote images in a message fetches them from the servers that host them (often the sender's), which see your IP address — that is why the app blocks them by default and asks per message.
  • Tapping a link or opening an attachment hands it to your system browser or the app your OS associates with the file. Only ordinary web and mail links (http, https, mailto) are ever handed off; attachments are never rendered inside the app.
  • Sending mail or invitations delivers them to your recipients through your provider.

These are your dispatches, not ours: Allodia receives nothing from any of them.

5. Optional usage statistics (off by default)

The one thing the app can send us — only if you opt in.

At first start, before any account is set up, the app asks whether you want to share usage statistics. The switch is off. Nothing is stored or sent unless you switch it on and confirm. Declining is remembered — we don't ask again. The consent screen has a "see exactly what we send" panel showing the literal data, byte for byte; the description below summarizes that panel, but the panel is authoritative.

What is sent if you opt in:

Data Value Deliberately not
Install id A random identifier, created only at the moment you opt in Not derived from your device, account, or any hardware id
Platform + OS e.g. android, OS major version only (15) Never a build number
Device class e.g. iphone, mac-laptop, android-tablet Never a device model
App version + language e.g. 1.4.0, nl Language only, never a full locale/region
Account shape How many accounts (bucketed: 0, 1, 2, 3–5, 6+) and which protocol kinds Never which providers, hosts, or addresses
Events App opened; account setup started/completed/failed and sync completed/failed (per protocol kind); a feature was used (from a fixed list); which settings are switched on Never anything you typed or configured as text

What is never sent — by construction, not just by policy: message content, subjects, senders, recipients, email addresses, folder names, message counts, search queries, calendar titles or event details, attachment names, server hostnames, device model strings. Every field above is a label from a fixed list or a bucket; there is no field in the payload that could carry your content, and our server rejects anything outside that fixed list.

Where it goes and how long it stays: only to servers Allodia itself operates in the EU (Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany). No third-party analytics company is involved, ever. Your IP address is technically visible when your device connects, as with any internet connection, but it is not stored and not linked to the usage data. Usage events are kept for at most 24 months, after which they are deleted or reduced to aggregate statistics that no longer relate to any install id.

What it is: pseudonymous usage data. The install id doesn't contain your name, address, or anything about you — but it is stable while you stay opted in (that is what lets us see whether setup succeeds and whether people keep using the app), so we treat it as personal data under the GDPR rather than calling it anonymous.

What it is for: product decisions, nothing else — which platforms and languages need attention, whether account setup and sync succeed, which features are actually used, whether an update made things worse.

Withdrawing: Settings → Privacy, one switch, any time. The app deletes the install id and consent record from your device and instructs our server to erase everything held under that id (GDPR Art. 17). Withdrawal is exactly as easy as opting in was.

If we ever want to send more, the app treats your earlier consent as not covering it and asks you again, showing the new data before anything changes. A payload can never grow under a consent that was given for less.

Legal basis: your consent (GDPR Art. 6(1)(a); storage and reading on your device per the national implementations of ePrivacy Art. 5(3)).

6. When you contact us

If you email us (e.g. info@allodia.eu), we process what you send — your address, your message, and anything you attach (for support, that may include the app's diagnostic log, which by design contains no message content, §2) — solely to answer you and resolve the issue.

Our mailboxes are hosted by Soverin (Netherlands), our EU email provider. Support correspondence is kept for 24 months after the last message, then deleted.

Legal basis: our legitimate interest in answering the people who write to us (Art. 6(1)(f)), or steps prior to a contract where you're asking about purchasing (Art. 6(1)(b)).

7. App stores and updates

You install and update the app through Apple's App Store, Google Play, or the Microsoft Store. The stores process your purchase and device data as independent controllers under their own privacy policies — not on our behalf. What we receive from them are aggregated dashboards (installs, active devices, OS versions, device models, crash statistics) that don't identify you to us; whether your device contributes to those is governed by your OS-level sharing settings. The app itself contains no crash reporter and performs no update checks of its own.

8. The allodia.eu website

Our website uses only cookies and local storage necessary for it to function (language preference, security, session handling) — no analytics or marketing cookies. If that ever changes, we will ask first. If you use the contact form, we process your name, email address, optional company name, and message to reply to you, as in §6. The site is hosted in the Netherlands and Germany.

9. What we never do

  • We never sell or rent personal data, and never share it for advertising.
  • We never use third-party analytics, tracking, or advertising SDKs in the app.
  • We never make automated decisions about you or profile you (GDPR Art. 22).
  • We never train AI models on your mail — we have no access to your mail at all.
  • We never transfer the personal data we hold outside the EU/EEA. (Where your own provider is located is your choice and a direct relationship between you and them.)

10. Retention — at a glance

Data Kept Where
Your mail, events, settings, diagnostic log On your device, under your control — delete the app's data or the app and it's gone Your device
Usage statistics (opt-in) Until you withdraw, at most 24 months Allodia-operated servers, EU
Support correspondence 24 months after the last message Soverin, NL
Website contact-form messages As support correspondence Soverin, NL
Invoices/records, if you buy from us As long as Dutch tax law requires (7 years) Allodia administration, EU

11. Your rights

Under the GDPR you can ask us for access to, correction, deletion, or a copy (portability) of your personal data, ask us to restrict processing, object to processing based on legitimate interest, and withdraw any consent at any time (which doesn't affect what was lawful before).

In practice, the fastest route is usually the app itself: your mail and settings are already in your hands, and the usage-statistics switch (Settings → Privacy) is the withdrawal-and-erasure mechanism for the one dataset we hold about the app. One honest limitation: an install id doesn't tell us who you are, so we can't look yours up from your name or email — the in-app switch, which proves control of the device the id belongs to, is the reliable way to have that data erased.

For everything else: info@allodia.eu. We respond within a month (Art. 12(3)). You can also complain to a data protection authority — ours is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), but you may use the authority of your own EU/EEA country.

12. Security

Credentials are stored only in your device's secure keystore and are never written to the app's database or its logs. Connections to your provider use the encrypted protocols it offers (TLS). Inbound HTML is sanitized in a hardened renderer where scripts never run and remote content is blocked by default. The little we operate server-side runs on EU infrastructure with access limited to those who need it, protected by multi-factor authentication and encryption at rest.

13. Changes to this policy

If we change what data is handled, we update this policy before the change ships, bump the version and date at the top, and — where the change would widen what the app sends — the app asks for your consent again rather than assuming it. The current version is always at https://allodia.eu/privacy/mail-calendar.

14. Contact

Allodia · KvK 56789823 · Kamerlingh Onnesweg 2, 3316GL Dordrecht, the Netherlands · info@allodia.eu