Summary
Cindr is an iPhone email-cleanup application. The app communicates directly from your device to an email service you choose, such as Google Gmail or Microsoft Outlook/Microsoft 365. Cindr does not operate a server that receives or stores your mailbox content.
Information Cindr processes
Account authorization data
When you connect an email provider, Cindr receives OAuth access and refresh tokens, token expiration information, granted scopes, and basic account identity such as an email address or provider account identifier. Cindr never asks for or receives your email password.
Mailbox data
To provide the cleanup experience, Cindr may process message identifiers, sender information, subject lines, dates, short previews, labels or folder state, and unsubscribe metadata. Full message content is requested only when you open a message. Message bodies and attachments are not persisted by Cindr.
Your decisions and app state
Cindr stores the decisions needed to perform and undo actions, unfinished session summaries, queued actions, aggregate progress counts, goals, preferences, milestones, and one-way SHA-256 sender or domain pattern keys used for local recommendations. Widget data contains aggregate counts only.
Purchases
If paid features become available, Apple processes the purchase. Cindr may receive subscription status and transaction identifiers from StoreKit to unlock features. Cindr does not receive your payment-card details.
How information is used
- Display a limited stack of messages for you to review.
- Open a message you explicitly choose to inspect.
- Carry out your explicit Keep, Trash, Undo, or unsubscribe decision.
- Reconnect after token expiration and maintain provider sessions.
- Save unfinished cleanup progress and show aggregate history or widgets.
- Generate transparent, on-device recommendations from aggregate patterns.
- Protect the app, prevent duplicate actions, and recover safe queued operations after connectivity returns.
Cindr does not automatically permanently delete email. Trash actions move a message to the email provider’s Trash or deleted-items location, subject to that provider’s retention policy.
Storage and retention
OAuth tokens are stored in the iOS Keychain using device-only protection. Other Cindr state is stored in protected Application Support files on your device. Aggregate widget values are stored in the Cindr App Group. The app does not persist rendered message bodies or attachments.
Local information remains until it is no longer needed for an unfinished action, you disconnect a provider, you use Delete all Cindr data, or you remove the app. Provider-side mail remains subject to the provider’s own retention rules. Apple separately manages App Store purchase history and subscriptions.
Disclosure and sharing
Cindr sends requests directly to your chosen email provider to retrieve data and perform actions you request. A confirmed standards-based one-click unsubscribe may contact the HTTPS endpoint identified by the sender. If you choose a web or email unsubscribe method, your selected browser or mail app handles it.
Cindr does not sell personal information. It does not share mailbox information with data brokers, advertisers, analytics networks, or AI training services. The production app does not include a mailbox-content analytics service.
Google API Services User Data
Cindr’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google user data is used only to provide or improve the user-facing email-cleanup features you request. It is not used for targeted advertising, advertising profiles, creditworthiness, lending, or sale. Humans do not read Google user data except when you provide specific data for support, when required for security or legal compliance, or with your affirmative agreement for a particular purpose.
Cindr requests the Gmail authorization scope required to list and modify mailbox messages. Read-only access cannot perform an explicit Trash or Undo decision, while broader send or full-mail scopes are not requested.
Your choices and controls
- Disconnect: Remove a connected provider from Cindr Settings.
- Delete: Choose Delete all Cindr data to revoke or disconnect where supported, remove Keychain tokens, delete local and App Group state, and return to onboarding.
- Provider revocation: Revoke Cindr independently through your Google or Microsoft account security settings.
- Notifications: Control Cindr notifications in iOS Settings. Notifications do not include message sender or subject by default.
- Subscriptions: Manage subscriptions separately through your Apple account.
See the Data Deletion page for detailed instructions. To ask a privacy question or request assistance, contact dukesbarlow.web@gmail.com.
Security
Cindr uses OAuth with PKCE, the system authentication session, iOS Keychain, file Data Protection, encrypted HTTPS connections, state validation, and narrowly scoped provider permissions. Message HTML is reduced to inert text; remote images, tracking pixels, and JavaScript are not loaded in the native viewer.
No security system is perfect. If you believe you found a vulnerability, follow the instructions on the Security page.
Children
Cindr is not directed to children under 13 or the minimum age required to independently use the connected email provider in their jurisdiction. We do not knowingly collect information from children through a Cindr-operated service.
International processing
Your email provider and Apple may process information in the locations described by their own policies. Cindr’s mailbox processing occurs on your device and through direct connections to the provider you select.
Changes to this policy
We may update this policy as the product or legal requirements change. The new effective date will appear above. Material changes will be communicated through the website, the app, or another appropriate channel.
Contact
Privacy questions: dukesbarlow.web@gmail.com
General support: dukesbarlow.web@gmail.com
Before launch, these contact addresses and the identification of the legal operator should be reviewed and finalized. This policy is a product-accurate starting point, not individualized legal advice.