diff --git a/PRIVACY.md b/PRIVACY.md index 81879e1a8a..5489cf6533 100644 --- a/PRIVACY.md +++ b/PRIVACY.md @@ -37,7 +37,7 @@ FairEmail **does not** send account information and message data elsewhere than FairEmail **does not** allow other apps access to message data without your approval. FairEmail **does not** require unnecessary permissions. -For more information on permissions, see [this FAQ](https://github.com/M66B/FairEmail/blob/master/FAQ.md#user-content-faq1). +For more information on permissions, see [this FAQ](https://m66b.github.io/FairEmail/#faq1). FairEmail **does** use modern and secure transport protocols by default. @@ -47,7 +47,7 @@ FairEmail **does** follow the recommendations of [this EFF article](https://www. FairEmail is 100 % **open source**, see [the license](https://github.com/M66B/FairEmail/blob/master/LICENSE). -Error reporting via Bugsnag **is opt-in**, see [here](https://github.com/M66B/FairEmail/blob/master/FAQ.md#user-content-faq104) for more information. +Error reporting via Bugsnag **is opt-in**, see [here](https://m66b.github.io/FairEmail/#faq104) for more information. FairEmail **adheres** to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the [Limited Use requirements](https://developers.google.com/terms/api-services-user-data-policy#additional_requirements_for_specific_api_scopes). @@ -70,10 +70,12 @@ FairEmail **can use** these services if they are explicitly enabled (off by defa * [LanguageTool](https://languagetool.org/) – [Privacy policy](https://languagetool.org/legal/privacy) * [VirusTotal](https://www.virustotal.com/) – [Privacy policy](https://support.virustotal.com/hc/en-us/articles/115002168385-Privacy-Policy) * [OpenAI](https://openai.com/) (GitHub version only) – [Privacy policy](https://openai.com/policies/privacy-policy) +* [Google Gemini](https://gemini.google.com/) (GitHub version only) – [Privacy policy](https://support.google.com/gemini/answer/13594961) * [Gravatar](https://gravatar.com/) (GitHub version only) – [Privacy policy](https://automattic.com/privacy/) * [Libravatar](https://www.libravatar.org/) (GitHub version only) – [Privacy policy](https://www.libravatar.org/privacy/) * [GitHub](https://github.com/) (GitHub version only) – [Privacy policy](https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement) -* [Have I Been Pwned?](https://haveibeenpwned.com/) (GitHub version only) – [Privacy policy](https://haveibeenpwned.com/Privacy) +* [Have I Been Pwned?](https://haveibeenpwned.com/) – [Privacy policy](https://haveibeenpwned.com/Privacy) +* [Bugsnag](https://www.bugsnag.com/) – [Privacy policy](https://smartbear.com/privacy/) FairEmail **can access** the websites at the domain names of email addresses (username@domain.name) if [Brand Indicators for Message Identification](https://en.wikipedia.org/wiki/Brand_Indicators_for_Message_Identification) (BIMI) @@ -106,7 +108,8 @@ This table provides a complete overview of all shared data and the conditions un | LanguageTool | Entered message texts | If LanguageTools is enabled, upon long pressing the save draft button | | VirusTotal | [SHA-256 hash](https://en.wikipedia.org/wiki/SHA-2) of attachments | If VirusTotal is enabled, upon long pressing a scan button (*) | | VirusTotal | Attached file contents | If VirusTotal is enabled, upon long pressing an upload button (*) | -| OpenAI | Received and entered message texts | Upen pressing a button in a navigation bar (*) | +| OpenAI/ChatGPT | Received and entered message texts | If configured and upon pressing a button or using a menu item (*) | +| Google Gemini | Received and entered message texts | If configured and upon pressing a button or using a menu item (*) | | Gravatar | [MD5 hash](https://en.wikipedia.org/wiki/MD5) of email addresses | If Gravatars are enabled, upon receiving a message (*) | | Libravatar | [MD5 hash](https://en.wikipedia.org/wiki/MD5) of email addresses | If Libravatars are enabled, upon receiving a message (*) | | GitHub | None, but see the remarks below | Upon downloading AdGuard tracking parameter list | @@ -195,13 +198,13 @@ The sub-processors are: #### V. Permissions The app only requests permissions that are necessary for the expected behavior of an email app. -For more information on permissions, see [this FAQ](https://github.com/M66B/FairEmail/blob/master/FAQ.md#user-content-faq1). +For more information on permissions, see [this FAQ](https://m66b.github.io/FairEmail/#faq1). #### VI. Logging The app does not send any log entries to the data processor by default. The error reporting system utilizes Bugsnag and is disabled by default. -See [this FAQ](https://github.com/M66B/FairEmail/blob/master/FAQ.md#user-content-faq104) for more information. +See [this FAQ](https://m66b.github.io/FairEmail/#faq104) for more information. #### VII. Legal basis diff --git a/privacy/index.html b/privacy/index.html index 4bb3aed517..471108ffe8 100644 --- a/privacy/index.html +++ b/privacy/index.html @@ -43,12 +43,12 @@

Overview

FairEmail does not send account information and message data elsewhere than to your email provider.

FairEmail does not allow other apps access to message data without your approval.

-

FairEmail does not require unnecessary permissions. For more information on permissions, see this FAQ.

+

FairEmail does not require unnecessary permissions. For more information on permissions, see this FAQ.

FairEmail does use modern and secure transport protocols by default.

Android encrypts all user data by default, so all data, including account credentials, is stored encrypted by default.

FairEmail does follow the recommendations of this EFF article.

FairEmail is 100 % open source, see the license.

-

Error reporting via Bugsnag is opt-in, see here for more information.

+

Error reporting via Bugsnag is opt-in, see here for more information.

FairEmail adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google API Services are used only to authenticate Gmail accounts through OAuth.

The use of information received from Gmail APIs will adhere to the Google User Data Policy, including the Limited Use requirements."

All stored information (account details, messages, etc.) is protected by encryption. All information is sent and received through secure connections. Of course, you should also protect your device by using a PIN code, pattern and/or biometric authentication.

@@ -63,10 +63,12 @@
  • LanguageToolPrivacy policy
  • VirusTotalPrivacy policy
  • OpenAI (GitHub version only) – Privacy policy
  • +
  • Google Gemini (GitHub version only) – Privacy policy
  • Gravatar (GitHub version only) – Privacy policy
  • Libravatar (GitHub version only) – Privacy policy
  • GitHub (GitHub version only) – Privacy policy
  • -
  • Have I Been Pwned? (GitHub version only) – Privacy policy
  • +
  • Have I Been Pwned?Privacy policy
  • +
  • BugsnagPrivacy policy
  • FairEmail can access the websites at the domain names of email addresses (username@domain.name) if Brand Indicators for Message Identification (BIMI) or favicons were explicitly enabled (off by default).

    FairEmail will access the website at the link address if you tap the Fetch title button in the insert link dialog (from version 1.1905).

    @@ -141,56 +143,61 @@ If VirusTotal is enabled, upon long pressing an upload button (*) -OpenAI +OpenAI/ChatGPT Received and entered message texts -Upen pressing a button in a navigation bar (*) +If configured and upon pressing a button or using a menu item (*) +Google Gemini +Received and entered message texts +If configured and upon pressing a button or using a menu item (*) + + Gravatar MD5 hash of email addresses If Gravatars are enabled, upon receiving a message (*) - + Libravatar MD5 hash of email addresses If Libravatars are enabled, upon receiving a message (*) - + GitHub None, but see the remarks below Upon downloading AdGuard tracking parameter list - + Upon downloading Disconnect’s Tracker Protection lists - + Upon checking for updates (*) - + Have I Been Pwned? The first 5 characters of the SHA1 hash of passwords Upon checking for being pwned - + BIMI Domain name of email addresses If BIMI is enabled, upon receiving a message (*) - + Favicons Domain name of email addresses If favicons are enabled, upon receiving a message - + Link title Link address Upon pressing a download button in the insert link dialog - + Bugsnag Information about warnings and errors If error reporting is enabled, upon detecting an abnormal situation @@ -238,9 +245,9 @@ marcel+privacy@faircode.eu
  • BugsnagPrivacy policy
  • V. Permissions

    -

    The app only requests permissions that are necessary for the expected behavior of an email app. For more information on permissions, see this FAQ.

    +

    The app only requests permissions that are necessary for the expected behavior of an email app. For more information on permissions, see this FAQ.

    VI. Logging

    -

    The app does not send any log entries to the data processor by default. The error reporting system utilizes Bugsnag and is disabled by default. See this FAQ for more information.

    +

    The app does not send any log entries to the data processor by default. The error reporting system utilizes Bugsnag and is disabled by default. See this FAQ for more information.

    FairEmail is fully GDPR compliant. The legal basis for any data processing is Art. 6 (1) a - c GDPR.