AIMA ("the app", "we", "us") is a mobile email client developed by Daniel Voipan that lets you
read, organize, and send email from your own email accounts (Gmail and other providers, connected
over standard IMAP/SMTP). This policy explains what data the app handles, how it is used
and stored, and the choices you have. By using AIMA you agree to this policy.
1. Information we handle
Account connection data
Email accounts: the email address, server settings, and the password you provide.
For Gmail and similar providers this is an app-specific password that you generate yourself; AIMA
connects only over standard IMAP/SMTP and does not use the Gmail API or Google sign-in.
Email content and metadata
Message headers (sender, recipients, subject, date), short previews/snippets, and read/starred state.
Message bodies, fetched so you can read your mail. Bodies are cached temporarily (see Retention) and
otherwise re-fetched on demand.
Attachment metadata only (file name, type, size). Attachment file contents are not stored
on our server — they are streamed from your mail provider to your device when you download them.
Spam-detection data
To detect spam, an AI model analyses the sender, subject and body of incoming messages to
compute a spam likelihood. This runs on our own backend; message content is not
sent to any third-party AI service.
If you mark a message as spam / not spam, that feedback is stored to improve detection
for your account. Spam handling can be set per account (badge, auto-move, or off) or disabled.
Device and notification data
A device identifier and a push-notification token, used to deliver new-mail notifications.
An anonymous app account is created on first launch (a generated identifier plus a randomly generated
secret, stored hashed) so your data stays isolated to your install. No name, email, or password is required
to use the app itself.
2. How we use the information
To provide the core email-client features: showing your inbox, reading messages, marking read/starred,
archiving/trashing, searching, listing attachments, and sending mail you compose.
To deliver push notifications for new mail.
To keep your accounts in sync.
To flag likely spam and predatory mail (you control this per account) and to improve detection from your feedback.
We do not use your data for advertising, and we do not sell it.
3. Storage and security
Data is transmitted over encrypted connections (HTTPS/TLS).
Email content — subjects, previews and message bodies — is encrypted at rest using
AES‑256‑GCM. It is decrypted only transiently on our server when needed to display
a message, run the on-request "Verify" checks, or generate a new-mail notification.
Your IMAP/SMTP account passwords are also encrypted at rest using AES‑256‑GCM.
Our backend runs on a private server (hosted with OVHcloud) with restricted access.
Spam detection runs on our own backend using a local model — your email is not sent to any external AI provider for classification.
Note: encryption at rest protects your stored data (e.g. against a database or backup being
accessed). Because AIMA connects to your mailbox on your behalf, our server can technically
access message content while it is being processed — we do not read it except to provide the
features described above, where necessary for security, or to comply with the law.
4. Data retention
Message bodies are retained for at most 30 days, after which they are deleted from our
server and re-fetched from your mail provider on demand when you open a message.
Message headers, previews, read/starred state, and attachment metadata are retained while the account is
connected, to keep your inbox and search responsive.
Attachment file contents are never stored.
5. Sharing & sub-processors
We share data only with the service providers needed to run the app:
Google Safe Browsing — when you use the "Verify" feature on a message, the
web links (URLs) contained in that message are sent to Google Safe Browsing to check whether
they are known malware or phishing sites. Only the links are sent, only when you verify a
message, and the result is cached so the same link isn't re-checked.
Firebase Cloud Messaging (Google) — to deliver push notifications.
OVHcloud — server hosting.
Your chosen email providers (e.g. Gmail) — accessed over IMAP/SMTP when you connect an account.
AI spam detection does not add a sub-processor: it runs entirely on our own backend, so your message content is never shared with a third-party AI service for spam analysis.
We do not sell or rent your data to anyone.
6. Deleting your data
You can disconnect an account in the app at any time, which removes that account and its synced data from
our server.
Reinstalling the app on the same device removes the previous anonymous account and its data.
For Gmail and similar providers, you can revoke the app password you created for AIMA at any time from your
provider's security settings (for Google:
App passwords).
To request full deletion of your data, email us at the address below and we will delete it.
7. Your rights
Depending on where you live, you may have the right to access, correct, or delete your personal data, or to
object to or restrict its processing. To exercise these rights, contact us.
8. Children
AIMA is not directed to children under 16, and we do not knowingly collect their data.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the date above.