← Back to Maildara
CLEAR BY DESIGN

Your inbox.
Your information.

Privacy should be easy to understand. Here is what Maildara handles, where it goes, and what you control.

Privacy policyEffective September 8, 2026

Your mail cache lives on your device. Optional AI sends selected email content to OpenAI. This website does not read your inbox.

1. Who we are

Maildara is a desktop email assistant operated by Bonline. This notice covers the Maildara desktop application and the websites maildara.com and license.bonlineco.com. It explains the current early-access service, including optional AI features.

For privacy questions or requests, contact info@bonlineco.com with “Maildara privacy” in the subject. Please do not send passwords, access tokens, or an entire mailbox with your request.

2. Information the app handles

When you connect a mailbox, Maildara accesses the account email address and available display name; message identifiers, senders, recipients, subjects, dates, message text, and attachment metadata; and calendar invitation data found in messages. It uses these to display your inbox, find possible meetings, create reminders, and help you prepare replies.

The app stores its cached messages, local drafts and sent-message records, meeting details, reminder preferences, provider configuration, and connection tokens on your device. A custom IMAP/SMTP connection also requires the server addresses, ports, usernames, and passwords you enter. Google and Microsoft sign-in use provider authorization pages; Maildara does not ask for their account passwords.

Ordinary attachment files are not automatically downloaded for viewing. Calendar invitation attachments may be processed to identify meeting details. Theme and language preferences are also saved locally.

3. Mail and calendar permissions

Depending on the app version, Google permissions cover reading Gmail messages (gmail.readonly) or reading and changing mail (gmail.modify), composing and sending mail (gmail.compose), and reading or changing calendar events (calendar.events). Microsoft connections use delegated profile, mail-reading or mail-changing (Mail.ReadWrite), mail-sending, and calendar permissions, with offline access for continued synchronization. Mail-change permission enables moving a selected inbox message to Trash after your confirmation. Older connections may need to reconnect to grant this permission.

Sending a message requires your review and confirmation in Maildara. Creating or updating an event in your provider’s calendar requires your action. The app may check for scheduling overlaps before creating an event. Proposed meetings are not automatically accepted, and personal calendar copies do not automatically invite attendees.

Google and Microsoft decide which permissions an account may grant. Connection availability during early access depends on provider setup, verification, and any organization administrator restrictions.

4. Optional AI and OpenAI

Starting with Maildara 0.4.2, AI features use Bonline’s OpenAI API backend within your account allowance. No personal ChatGPT account is required. When you request a summary, meeting or action-item analysis, a scam check, or a reply draft, selected message text and relevant context are sent from your device through Bonline’s backend to OpenAI. A reply request can include up to eight cached messages from that conversation, along with your instructions. Analysis can include the sender address and display name, reply-to address, subject, message date, and your time zone. Suggested tasks, follow-ups, and scam-risk assessments are stored locally. Scam checks review available email text; they do not authenticate the sender, visit links, or scan attachments, and cannot guarantee safety.

Automatic analysis is off by default. If you enable it, Maildara can send up to ten newly imported messages per synchronization to OpenAI. You can turn it off in Settings and save your preferences. Mailbox passwords and connection tokens are not included in AI prompts. Bonline processes this content transiently and does not store it in the AI ledger. It stores the customer and device identifiers, request ID, operation, timestamps, token counts and charged/reserved credit to enforce allowances and investigate billing. API keys remain encrypted on the server. Requests set store=false; provider-side retention still follows OpenAI’s applicable terms.

OpenAI processes this information under its applicable terms, account settings, and privacy policy. Those controls affect provider-side retention and model-improvement use; an ephemeral application session does not mean that OpenAI retains nothing. Bonline must use an API project configuration that excludes mailbox content from model training. Review your organization’s rules before sharing workplace messages.

Bonline does not use your mailbox content to train general-purpose AI models. AI output may be inaccurate; review recipients, wording, dates, and commitments before acting on it.

Voice dictation is optional and the microphone starts only when you choose it. Local Whisper transcription remains the default: its first-time setup downloads a model from Hugging Face, which receives normal connection information such as your IP address. Whisper transcribes recordings on your computer. In Maildara 0.3.16 and later, you can choose Gemini transcription included with your active subscription at no extra charge. The app sends the recording and language/dialect hints over HTTPS to Bonline’s server at license.bonlineco.com, which checks your device activation and current license before forwarding the audio to Google Gemini. The Google API key stays on Bonline’s server; customers do not supply a key. The transcription request does not include your inbox or draft text. Bonline’s application processes audio and transcripts transiently and does not store them. It keeps short-lived request counters and concurrent-request identifiers to prevent abuse, alongside ordinary hosting access logs. Offline license access does not authorize cloud transcription after server-side suspension, revocation or expiry. Version 0.3.15 used a customer-supplied key and sent audio directly to Google; later versions remove that locally saved key. Google processes Gemini requests under its applicable Gemini API terms and privacy policy. Google-side retention and data use depend on the service and account; cancelling a request cannot recall audio already transmitted. Whisper does not upload recordings to Bonline or OpenAI. Maildara does not switch local dictation to Gemini automatically. Local temporary audio and transcription files are removed after transcription or cancellation; crash leftovers are removed on the next launch. The Whisper model remains on your device for reuse. When you request AI drafting, your typed or reviewed dictated instructions, draft text, and relevant reply conversation are sent to OpenAI through Bonline’s API backend. You review the result before using or sending it.

5. Sharing and Google Limited Use

Maildara uses mailbox data for the features you choose. Data is exchanged with your mail provider to synchronize messages, deliver approved mail, or manage calendar events. OpenAI receives the selected content described above when you use AI. Your operating system may display meeting information in notifications, including on a lock screen if your settings allow it.

Bonline does not sell mailbox data, use it for advertising, or give staff routine access to your local inbox. If you voluntarily send a message or screenshot to support, our support team will see the information you include. Providers and hosting operators process information needed to deliver their services; legal disclosures may be required by applicable law.

Maildara handles Google API data in accordance with the Google API Services User Data Policy and its Limited Use requirements. Google-derived data is limited to the disclosed, user-facing features. It is not used for advertising, credit decisions, surveillance, or general-purpose model training. This policy does not mean Google has verified or endorsed Maildara.

6. Storage, security, and retention

The desktop app keeps its mail cache, drafts, reminder data, settings, and mailbox credentials in a local encrypted vault using operating-system storage facilities. Custom mail connections default to TLS or STARTTLS with certificate validation. If you explicitly choose an unencrypted connection for a legacy server, the mailbox password and email traffic travel without TLS protection. SmarterMail API connections use HTTPS. Local vault encryption does not encrypt an unencrypted network connection. Remote tracking images and remote email HTML are not loaded in the message viewer.

OpenAI API credentials are encrypted on Bonline’s backend and are never supplied to the desktop app. Your operating-system account, disk protection, device backups, and OpenAI controls remain important.

Cached mailbox data remains on the device until you disconnect the account or remove the application’s data. Uninstalling the program alone may leave that data behind. The current app does not automatically expire cached messages on a fixed schedule. Support correspondence is retained as needed to handle the request and relevant business or legal obligations. Hosting logs are retained according to the hosting service’s operational and security requirements; contact us for information about a specific request. Provider-side messages and AI data follow those providers’ retention rules.

No security measure eliminates every risk. Bonline cannot remotely erase data from your device, your backups, or another provider’s systems.

7. Your choices and deletion requests

You can disconnect a mailbox in Maildara to remove that account’s local mail cache, drafts, and reminders. This does not delete mail or events at Google, Microsoft, or your mail server. Revoke provider authorization in your Google account connections or Microsoft account settings if you also want to invalidate continued provider access.

You can stop using AI, disable automatic analysis, change notification settings, and remove Maildara’s local application data and backups. Use OpenAI’s account controls for data held by OpenAI. Bonline does not hold a server-side copy of your desktop inbox for us to retrieve or erase.

Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to processing of your personal information. Send requests concerning information held by Bonline to our privacy contact. We may need enough information to verify your identity and identify the relevant records. Some records may need to be retained where law permits or requires it.

8. This website and contacting Bonline

This marketing website does not connect to your mailbox, accept payments, or include advertising pixels or analytics scripts. Its fonts and illustrations are hosted on this domain. It stores a light/dark appearance preference in your browser’s local storage; clear site data to remove it. The language is selected through the page URL.

Our hosting service receives ordinary request information such as IP address, requested URL, time, response status, and browser information for delivery, security, and troubleshooting. Infrastructure providers may use essential security mechanisms. Clicking an email link opens your email application; Bonline receives your email address and whatever you choose to send. There is no hidden mailing-list subscription.

External services have their own privacy policies. Providers may process information in countries different from yours. Maildara is intended for adults managing their own or authorized work email and is not directed to children.

9. Changes to this notice

We will update this page when the service’s data practices change and revise the effective date. Material changes to mailbox-data use will be disclosed before the new use begins, with renewed consent where required. The license dashboard and payment processing are described below.

10. License dashboard and payments

The administrator dashboard and customer purchase pages are hosted at license.bonlineco.com. It stores administrator email addresses, password hashes and roles; customer email addresses linked to licenses; license and subscription records; activation-key hashes and encrypted keys; and administrative activity. Customers receive a license key after verified Stripe payment, or directly from an administrator, and activate the desktop app without registering a dashboard account. The purchase session links the confirmation page to the browser used for checkout; email alone cannot reveal a key. Administrator login and customer checkout use an essential, host-only session cookie and a 30-day HttpOnly purchase-continuity cookie. Language is stored in the session; appearance preferences may be stored in your browser.

Desktop activation sends the license key initially and then a device activation identifier and secret to Bonline over HTTPS. The service records a random device identifier, device label, operating-system platform, app version, and activation/validation times to enforce device limits and check access. The activation endpoint does not receive mailbox passwords or message content. The separate AI endpoint receives selected message content only for requested AI processing.

Stripe processes payments arranged by Bonline. Verified successful payment automatically issues or renews the license. The customer copies or downloads the key on the payment confirmation page and enters it in Maildara. Administrators can suspend or revoke access. Bonline sends the account email and product/order references to Stripe, and retains customer, price, invoice-related subscription status, and payment-event references needed to manage access. Card entry happens on Stripe; Maildara does not store full card numbers. See Stripe’s privacy policy.

License/account records remain while needed to provide access, resolve billing/support requests, prevent abuse, and meet applicable accounting obligations. There is no automatic account-data purge in the current release; contact Bonline to request account closure or deletion. Some transaction or audit records may need to be retained. Removing a device stops future license validation for that activation; an already issued offline access token can remain valid for up to 72 hours, within the license expiry.