|
|
<!DOCTYPE html>
|
|
|
<html xmlns="http://www.w3.org/1999/xhtml" lang="" xml:lang="">
|
|
|
<head>
|
|
|
<meta charset="utf-8" />
|
|
|
<meta name="generator" content="pandoc" />
|
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0, user-scalable=yes" />
|
|
|
<title>FairEmail - privacy</title>
|
|
|
<style>
|
|
|
html {
|
|
|
color: #1a1a1a;
|
|
|
background-color: #fdfdfd;
|
|
|
}
|
|
|
body {
|
|
|
margin: 0 auto;
|
|
|
max-width: 36em;
|
|
|
padding-left: 50px;
|
|
|
padding-right: 50px;
|
|
|
padding-top: 50px;
|
|
|
padding-bottom: 50px;
|
|
|
hyphens: auto;
|
|
|
overflow-wrap: break-word;
|
|
|
text-rendering: optimizeLegibility;
|
|
|
font-kerning: normal;
|
|
|
}
|
|
|
@media (max-width: 600px) {
|
|
|
body {
|
|
|
font-size: 0.9em;
|
|
|
padding: 12px;
|
|
|
}
|
|
|
h1 {
|
|
|
font-size: 1.8em;
|
|
|
}
|
|
|
}
|
|
|
@media print {
|
|
|
html {
|
|
|
background-color: white;
|
|
|
}
|
|
|
body {
|
|
|
background-color: transparent;
|
|
|
color: black;
|
|
|
font-size: 12pt;
|
|
|
}
|
|
|
p, h2, h3 {
|
|
|
orphans: 3;
|
|
|
widows: 3;
|
|
|
}
|
|
|
h2, h3, h4 {
|
|
|
page-break-after: avoid;
|
|
|
}
|
|
|
}
|
|
|
p {
|
|
|
margin: 1em 0;
|
|
|
}
|
|
|
a {
|
|
|
color: #1a1a1a;
|
|
|
}
|
|
|
a:visited {
|
|
|
color: #1a1a1a;
|
|
|
}
|
|
|
img {
|
|
|
max-width: 100%;
|
|
|
}
|
|
|
h1, h2, h3, h4, h5, h6 {
|
|
|
margin-top: 1.4em;
|
|
|
}
|
|
|
h5, h6 {
|
|
|
font-size: 1em;
|
|
|
font-style: italic;
|
|
|
}
|
|
|
h6 {
|
|
|
font-weight: normal;
|
|
|
}
|
|
|
ol, ul {
|
|
|
padding-left: 1.7em;
|
|
|
margin-top: 1em;
|
|
|
}
|
|
|
li > ol, li > ul {
|
|
|
margin-top: 0;
|
|
|
}
|
|
|
blockquote {
|
|
|
margin: 1em 0 1em 1.7em;
|
|
|
padding-left: 1em;
|
|
|
border-left: 2px solid #e6e6e6;
|
|
|
color: #606060;
|
|
|
}
|
|
|
code {
|
|
|
font-family: Menlo, Monaco, Consolas, 'Lucida Console', monospace;
|
|
|
font-size: 85%;
|
|
|
margin: 0;
|
|
|
hyphens: manual;
|
|
|
}
|
|
|
pre {
|
|
|
margin: 1em 0;
|
|
|
overflow: auto;
|
|
|
}
|
|
|
pre code {
|
|
|
padding: 0;
|
|
|
overflow: visible;
|
|
|
overflow-wrap: normal;
|
|
|
}
|
|
|
.sourceCode {
|
|
|
background-color: transparent;
|
|
|
overflow: visible;
|
|
|
}
|
|
|
hr {
|
|
|
background-color: #1a1a1a;
|
|
|
border: none;
|
|
|
height: 1px;
|
|
|
margin: 1em 0;
|
|
|
}
|
|
|
table {
|
|
|
margin: 1em 0;
|
|
|
border-collapse: collapse;
|
|
|
width: 100%;
|
|
|
overflow-x: auto;
|
|
|
display: block;
|
|
|
font-variant-numeric: lining-nums tabular-nums;
|
|
|
}
|
|
|
table caption {
|
|
|
margin-bottom: 0.75em;
|
|
|
}
|
|
|
tbody {
|
|
|
margin-top: 0.5em;
|
|
|
border-top: 1px solid #1a1a1a;
|
|
|
border-bottom: 1px solid #1a1a1a;
|
|
|
}
|
|
|
th {
|
|
|
border-top: 1px solid #1a1a1a;
|
|
|
padding: 0.25em 0.5em 0.25em 0.5em;
|
|
|
}
|
|
|
td {
|
|
|
padding: 0.125em 0.5em 0.25em 0.5em;
|
|
|
}
|
|
|
header {
|
|
|
margin-bottom: 4em;
|
|
|
text-align: center;
|
|
|
}
|
|
|
#TOC li {
|
|
|
list-style: none;
|
|
|
}
|
|
|
#TOC ul {
|
|
|
padding-left: 1.3em;
|
|
|
}
|
|
|
#TOC > ul {
|
|
|
padding-left: 0;
|
|
|
}
|
|
|
#TOC a:not(:hover) {
|
|
|
text-decoration: none;
|
|
|
}
|
|
|
code{white-space: pre-wrap;}
|
|
|
span.smallcaps{font-variant: small-caps;}
|
|
|
div.columns{display: flex; gap: min(4vw, 1.5em);}
|
|
|
div.column{flex: auto; overflow-x: auto;}
|
|
|
div.hanging-indent{margin-left: 1.5em; text-indent: -1.5em;}
|
|
|
/* The extra [class] is a hack that increases specificity enough to
|
|
|
override a similar rule in reveal.js */
|
|
|
ul.task-list[class]{list-style: none;}
|
|
|
ul.task-list li input[type="checkbox"] {
|
|
|
font-size: inherit;
|
|
|
width: 0.8em;
|
|
|
margin: 0 0.8em 0.2em -1.6em;
|
|
|
vertical-align: middle;
|
|
|
}
|
|
|
.display.math{display: block; text-align: center; margin: 0.5rem auto;}
|
|
|
</style>
|
|
|
<link rel="shortcut icon" href="https://raw.githubusercontent.com/M66B/FairEmail/master/app/src/main/ic_launcher-web.png">
|
|
|
<style>
|
|
|
body { font-family: Arial, sans-serif; }
|
|
|
.table-wrapper { overflow-x: auto; white-space: nowrap; }
|
|
|
table { border-collapse: collapse; }
|
|
|
table colgroup col { width: auto !important; }
|
|
|
table, th, td { border: 1px solid black; }
|
|
|
td { padding: 3px; }
|
|
|
</style>
|
|
|
</head>
|
|
|
<body>
|
|
|
<header id="title-block-header">
|
|
|
<h1 class="title">FairEmail</h1>
|
|
|
</header>
|
|
|
<p><img width="72" height="72" src="https://raw.githubusercontent.com/M66B/FairEmail/master/app/src/main/res/mipmap-hdpi/ic_launcher.png"></p>
|
|
|
<p><sup>Provided by <a href="https://www.faircode.eu/">FairCode
|
|
|
B.V.</a></sup></p>
|
|
|
<h2 id="privacy-policy">Privacy policy</h2>
|
|
|
<p><a
|
|
|
href="https://translate.google.com/translate?hl=&sl=en&u=https%3A%2F%2Fraw.githubusercontent.com%2FM66B%2FFairEmail%2Fmaster%2FPRIVACY.md">🌎
|
|
|
Google Translate</a></p>
|
|
|
<p><br /></p>
|
|
|
<p>This privacy policy will be updated as needed, such as when there are
|
|
|
changes in the app or when regulations or laws change.</p>
|
|
|
<p>Last update: <strong>June 2, 2024</strong></p>
|
|
|
<p><br /></p>
|
|
|
<p>First of all, FairEmail’s main goal is to help you protect your
|
|
|
privacy. What follows is a complete overview of all the data that will
|
|
|
be stored on the device and that <strong>can be</strong> sent to the
|
|
|
internet. The latter is in the end always your choice and therefore
|
|
|
optional.</p>
|
|
|
<p>Except for error reports (disabled by default), the app does not send
|
|
|
any data to the developer. Error reports will automatically be deleted
|
|
|
after one month, or earlier upon request.</p>
|
|
|
<p>Data collected on the device will <strong>never</strong> be sold or
|
|
|
shared in any way.</p>
|
|
|
<p>Data collected on the device will <strong>never</strong> be used for
|
|
|
profiling, (AI) training or advertisements.</p>
|
|
|
<p>There are <strong>no ads</strong> in the app.</p>
|
|
|
<p>You have the right to lodge a complaint with a supervisory data
|
|
|
protection authority, please <a
|
|
|
href="https://en.wikipedia.org/wiki/National_data_protection_authority">see
|
|
|
here</a> for a list.</p>
|
|
|
<p><br></p>
|
|
|
<p>The
|
|
|
<a href="https://play.google.com/store/apps/datasafety?id=eu.faircode.email">data
|
|
|
safety</a> in the Play Store says:</p>
|
|
|
<p>“<em>The developer says this app doesn’t share user data with other
|
|
|
companies or organizations.</em>”.</p>
|
|
|
<p>Unfortunately, there is no way to say that the app doesn’t share data
|
|
|
with the developer. Except for error reporting (explicitly opt-in)
|
|
|
<strong>no data will be shared with the developer</strong>. It is
|
|
|
important to note that collecting data on the device isn’t synonymous
|
|
|
with sending data off the device!</p>
|
|
|
<p><br /></p>
|
|
|
<h3 id="overview">Overview</h3>
|
|
|
<p>FairEmail <strong>does not</strong> send account information and
|
|
|
message data elsewhere than to your email provider.</p>
|
|
|
<p>FairEmail <strong>does not</strong> allow other apps access to
|
|
|
message data without your approval.</p>
|
|
|
<p>FairEmail <strong>does not</strong> require unnecessary permissions.
|
|
|
For more information on permissions, see <a
|
|
|
href="https://github.com/M66B/FairEmail/blob/master/FAQ.md#faq1">this
|
|
|
FAQ</a>.</p>
|
|
|
<p>FairEmail <strong>does</strong> use modern and secure transport
|
|
|
protocols by default.</p>
|
|
|
<p>Android <a
|
|
|
href="https://source.android.com/docs/security/features/encryption">encrypts
|
|
|
all user data by default</a>, so all data, including account
|
|
|
credentials, is stored encrypted by default.</p>
|
|
|
<p>FairEmail <strong>does</strong> follow the recommendations of <a
|
|
|
href="https://www.eff.org/deeplinks/2019/01/stop-tracking-my-emails">this
|
|
|
EFF article</a>.</p>
|
|
|
<p>FairEmail is 100 % <strong>open source</strong>, see <a
|
|
|
href="https://github.com/M66B/FairEmail/blob/master/LICENSE">the
|
|
|
license</a>.</p>
|
|
|
<p>Error reporting via Bugsnag <strong>is opt-in</strong>, see <a
|
|
|
href="https://github.com/M66B/FairEmail/blob/master/FAQ.md#faq104">here</a>
|
|
|
for more information.</p>
|
|
|
<p>FairEmail <strong>adheres</strong> to the <a
|
|
|
href="https://developers.google.com/terms/api-services-user-data-policy">Google
|
|
|
API Services User Data Policy</a>, including the <a
|
|
|
href="https://developers.google.com/terms/api-services-user-data-policy#additional_requirements_for_specific_api_scopes">Limited
|
|
|
Use requirements</a>. Google API Services are used only to authenticate
|
|
|
Gmail accounts through OAuth.</p>
|
|
|
<p>The use of information received from Gmail APIs will adhere to the
|
|
|
Google User Data Policy, including the Limited Use requirements.”</p>
|
|
|
<p>All stored information (account details, messages, etc.) is
|
|
|
<strong>protected by encryption</strong>. All information is sent and
|
|
|
received through <strong>secure connections</strong>. Of course, you
|
|
|
should also protect your device by using a PIN code, pattern and/or
|
|
|
biometric authentication.</p>
|
|
|
<p>FairEmail <strong>can use</strong> these services if they are
|
|
|
explicitly enabled (off by default) or are explicitly used by you:</p>
|
|
|
<ul>
|
|
|
<li><a href="https://ipinfo.io/">ipinfo.io</a> – <a
|
|
|
href="https://ipinfo.io/privacy-policy">Privacy policy</a></li>
|
|
|
<li><a href="https://www.spamhaus.org/">Spamhaus</a> – <a
|
|
|
href="https://www.spamhaus.org/organization/privacy/">Privacy
|
|
|
policy</a></li>
|
|
|
<li><a href="https://www.spamcop.net/">Spamcop</a> – <a
|
|
|
href="https://www.spamcop.net/fom-serve/cache/168.html">Privacy
|
|
|
policy</a></li>
|
|
|
<li><a
|
|
|
href="https://www.barracudacentral.org/rbl/how-to-use">Barracuda</a> –
|
|
|
<a
|
|
|
href="https://www.barracuda.com/company/legal/trust-center/data-privacy/privacy-policy">Privacy
|
|
|
policy</a></li>
|
|
|
<li><a
|
|
|
href="https://wiki.mozilla.org/Thunderbird:Autoconfiguration">Thunderbird
|
|
|
autoconfiguration</a> – <a
|
|
|
href="https://www.mozilla.org/privacy/">Privacy policy</a></li>
|
|
|
<li><a href="https://www.deepl.com/">DeepL</a> – <a
|
|
|
href="https://www.deepl.com/privacy/">Privacy policy</a></li>
|
|
|
<li><a href="https://languagetool.org/">LanguageTool</a> – <a
|
|
|
href="https://languagetool.org/legal/privacy">Privacy policy</a></li>
|
|
|
<li><a href="https://www.virustotal.com/">VirusTotal</a> – <a
|
|
|
href="https://support.virustotal.com/hc/en-us/articles/115002168385-Privacy-Policy">Privacy
|
|
|
policy</a></li>
|
|
|
<li><a href="https://openai.com/">OpenAI</a> – <a
|
|
|
href="https://openai.com/policies/privacy-policy">Privacy
|
|
|
policy</a></li>
|
|
|
<li><a href="https://gemini.google.com/">Google Gemini</a> – <a
|
|
|
href="https://support.google.com/gemini/answer/13594961">Privacy
|
|
|
policy</a></li>
|
|
|
<li><a href="https://gravatar.com/">Gravatar</a> (GitHub version only) –
|
|
|
<a href="https://automattic.com/privacy/">Privacy policy</a></li>
|
|
|
<li><a href="https://www.libravatar.org/">Libravatar</a> (GitHub version
|
|
|
only) – <a href="https://www.libravatar.org/privacy/">Privacy
|
|
|
policy</a></li>
|
|
|
<li><a href="https://github.com/">GitHub</a> (GitHub version only) – <a
|
|
|
href="https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement">Privacy
|
|
|
policy</a></li>
|
|
|
<li><a href="https://haveibeenpwned.com/">Have I Been Pwned?</a> – <a
|
|
|
href="https://haveibeenpwned.com/Privacy">Privacy policy</a></li>
|
|
|
<li><a href="https://www.bugsnag.com/">Bugsnag</a> – <a
|
|
|
href="https://smartbear.com/privacy/">Privacy policy</a></li>
|
|
|
<li><a href="https://developer.android.com/identity/data/backup">Google
|
|
|
data backup</a> – <a href="https://policies.google.com/privacy">Privacy
|
|
|
policy</a></li>
|
|
|
<li><a
|
|
|
href="https://developer.android.com/distribute/play-billing">Google Play
|
|
|
Billing</a> – <a
|
|
|
href="https://wallet.google.com/files/privacy.html">Privacy
|
|
|
policy</a></li>
|
|
|
</ul>
|
|
|
<p>FairEmail <strong>can access</strong> the websites at the domain
|
|
|
names of email addresses (username@domain.name) if <a
|
|
|
href="https://en.wikipedia.org/wiki/Brand_Indicators_for_Message_Identification">Brand
|
|
|
Indicators for Message Identification</a> (BIMI) or <a
|
|
|
href="https://en.wikipedia.org/wiki/Favicon">favicons</a> were
|
|
|
explicitly enabled (off by default).</p>
|
|
|
<p>FairEmail <strong>will access</strong> the website at the link
|
|
|
address if you tap the <em>Fetch title</em> button in the insert link
|
|
|
dialog (from version 1.1905).</p>
|
|
|
<p>FairEmail obviously <strong>will access</strong> the configured email
|
|
|
servers.</p>
|
|
|
<p>FairEmail <strong>is</strong> <a href="https://gdpr.eu/">GDPR
|
|
|
compliant</a>.</p>
|
|
|
<p><br /></p>
|
|
|
<h3 id="summary-of-stored-collected-data">Summary of stored (collected)
|
|
|
data</h3>
|
|
|
<p>The following data is stored on the device or, in other words,
|
|
|
collected, but not sent off the device:</p>
|
|
|
<div class="table-wrapper">
|
|
|
<table>
|
|
|
<colgroup>
|
|
|
<col style="width: 57%" />
|
|
|
<col style="width: 22%" />
|
|
|
<col style="width: 20%" />
|
|
|
</colgroup>
|
|
|
<thead>
|
|
|
<tr class="header">
|
|
|
<th>Data stored (collected)</th>
|
|
|
<th>Purpose</th>
|
|
|
<th>Related Android permissions</th>
|
|
|
</tr>
|
|
|
</thead>
|
|
|
<tbody>
|
|
|
<tr class="odd">
|
|
|
<td>Names and email addresses (account and contact data)</td>
|
|
|
<td>To configure accounts</td>
|
|
|
<td>GET_ACCOUNTS</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td></td>
|
|
|
<td>To suggest email addresses</td>
|
|
|
<td>READ_CONTACTS</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>Email messages, including meta data (headers)</td>
|
|
|
<td>To list and display messages</td>
|
|
|
<td></td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td></td>
|
|
|
<td>To search for messages</td>
|
|
|
<td></td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>Attachment files (audio, sound, music, voice, photos, video,
|
|
|
documents, etc.)</td>
|
|
|
<td>To play media (audio, video)</td>
|
|
|
<td>READ_EXTERNAL_STORAGE</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td></td>
|
|
|
<td>To view images, documents, etc.</td>
|
|
|
<td>READ_EXTERNAL_STORAGE</td>
|
|
|
</tr>
|
|
|
</tbody>
|
|
|
</table>
|
|
|
</div>
|
|
|
<p>By default, personal data as mentioned above will be stored on your
|
|
|
device for 30 days.</p>
|
|
|
<p>Under the General Data Protection Regulation (GDPR), the California
|
|
|
Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act
|
|
|
(VCDPA), Lei Geral de Proteção de Dados (LGPD), and other regulations,
|
|
|
you have the right to know whether your personal data is stored, shared
|
|
|
or sold to third parties, used for (targeted) advertising, profiling
|
|
|
(for decision making), etc., and you have the right to access, rectify
|
|
|
and delete personal data. Data stored on the device, see above for
|
|
|
details, will never be shared, sold, used for advertising, profiling,
|
|
|
etc. You can access and change this data through the app. You can delete
|
|
|
this data, and you can opt-out of storing this data by uninstalling the
|
|
|
app. To exercise your rights, or if you have questions about data
|
|
|
retention, etc., you can contact the developer, see for contact
|
|
|
information below.</p>
|
|
|
<p><br /></p>
|
|
|
<h3 id="summary-of-shared-data">Summary of shared data</h3>
|
|
|
<p>This table provides a complete overview of all shared data and the
|
|
|
conditions under which data will be shared:</p>
|
|
|
<div class="table-wrapper">
|
|
|
<table>
|
|
|
<colgroup>
|
|
|
<col style="width: 11%" />
|
|
|
<col style="width: 41%" />
|
|
|
<col style="width: 46%" />
|
|
|
</colgroup>
|
|
|
<thead>
|
|
|
<tr class="header">
|
|
|
<th>Service/function</th>
|
|
|
<th>Data sent</th>
|
|
|
<th>When the data will be sent</th>
|
|
|
</tr>
|
|
|
</thead>
|
|
|
<tbody>
|
|
|
<tr class="odd">
|
|
|
<td>Mozilla autoconfig</td>
|
|
|
<td>Domain name of email address of email accounts</td>
|
|
|
<td>Upon configuring an email account with the quick setup wizard</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>Email server</td>
|
|
|
<td>Login credentials (email address/password), messages sent</td>
|
|
|
<td>Upon configuring and using an account or identity and upon sending
|
|
|
messages</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>ipinfo.io</td>
|
|
|
<td>IP (network) address of domain names of links or email
|
|
|
addresses</td>
|
|
|
<td>Upon pressing a button in the link confirmation dialog</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>Spamhaus</td>
|
|
|
<td>IP (network) address of domain names of links or email
|
|
|
addresses</td>
|
|
|
<td>If spam blocklists are enabled, upon receiving a message</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>Spamcop</td>
|
|
|
<td>IP (network) address of domain names of links or email
|
|
|
addresses</td>
|
|
|
<td>If spam blocklists are enabled, upon receiving a message</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>Barracuda</td>
|
|
|
<td>IP (network) address of domain names of links or email
|
|
|
addresses</td>
|
|
|
<td>If spam blocklists are enabled, upon receiving a message</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>DeepL</td>
|
|
|
<td>Received or entered message text and target language code</td>
|
|
|
<td>If translating is enabled, upon pressing a translate button</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>LanguageTool</td>
|
|
|
<td>Entered message texts</td>
|
|
|
<td>If LanguageTools is enabled, upon long pressing the save draft
|
|
|
button</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>VirusTotal</td>
|
|
|
<td><a href="https://en.wikipedia.org/wiki/SHA-2">SHA-256 hash</a> of
|
|
|
attachments</td>
|
|
|
<td>If VirusTotal is enabled, upon long pressing a scan button (*)</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>VirusTotal</td>
|
|
|
<td>Attached file contents</td>
|
|
|
<td>If VirusTotal is enabled, upon long pressing an upload button
|
|
|
(*)</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>OpenAI/ChatGPT</td>
|
|
|
<td>Received and entered message texts</td>
|
|
|
<td>If configured and upon pressing a button or using a menu item</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>Google Gemini</td>
|
|
|
<td>Received and entered message texts</td>
|
|
|
<td>If configured and upon pressing a button or using a menu item</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>Gravatar</td>
|
|
|
<td><a href="https://en.wikipedia.org/wiki/MD5">MD5 hash</a> of email
|
|
|
addresses</td>
|
|
|
<td>If Gravatars are enabled, upon receiving a message (*)</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>Libravatar</td>
|
|
|
<td><a href="https://en.wikipedia.org/wiki/MD5">MD5 hash</a> of email
|
|
|
addresses</td>
|
|
|
<td>If Libravatars are enabled, upon receiving a message (*)</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>GitHub</td>
|
|
|
<td>None, but see the remarks below</td>
|
|
|
<td>Upon downloading AdGuard tracking parameter list</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td></td>
|
|
|
<td></td>
|
|
|
<td>Upon downloading Disconnect’s Tracker Protection lists</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td></td>
|
|
|
<td></td>
|
|
|
<td>Upon checking for updates (*)</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>Have I Been Pwned?</td>
|
|
|
<td>The first 5 characters of the SHA1 hash of passwords</td>
|
|
|
<td>Upon checking for being pwned</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>BIMI</td>
|
|
|
<td>Domain name of email addresses</td>
|
|
|
<td>If BIMI is enabled, upon receiving a message (*)</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>Favicons</td>
|
|
|
<td>Domain name of email addresses</td>
|
|
|
<td>If favicons are enabled, upon receiving a message</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>Link title</td>
|
|
|
<td>Link address</td>
|
|
|
<td>Upon pressing a download button in the insert link dialog</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>Bugsnag</td>
|
|
|
<td>Information about warnings and errors</td>
|
|
|
<td>If error reporting is enabled, upon detecting an abnormal
|
|
|
situation</td>
|
|
|
</tr>
|
|
|
<tr class="odd">
|
|
|
<td>Android data backup</td>
|
|
|
<td>Account configuration, selected settings</td>
|
|
|
<td>If Android’s data backup is enabled on the miscellaneous settings
|
|
|
tab page</td>
|
|
|
</tr>
|
|
|
<tr class="even">
|
|
|
<td>Google Play Billing</td>
|
|
|
<td>“insight into API usage and service connection issues”</td>
|
|
|
<td>Not disclosed by Google (**) (endpoint:
|
|
|
firebaselogging.googleapis.com)</td>
|
|
|
</tr>
|
|
|
</tbody>
|
|
|
</table>
|
|
|
</div>
|
|
|
<p>(*) Only available in the GitHub version of the app</p>
|
|
|
<p>(**) Only available in the Play Store version of the app</p>
|
|
|
<p>All data is sent to improve the user experience in some way, like to
|
|
|
simplify account setup, identify spam and malicious messages, display
|
|
|
message and sender information, find bugs and errors, etc.</p>
|
|
|
<p>Note that any internet connection reveals your current <a
|
|
|
href="https://en.wikipedia.org/wiki/Network_address">network
|
|
|
address</a>. Also, when downloading content, like images and files, the
|
|
|
<a href="https://en.wikipedia.org/wiki/User_agent">browser’s user agent
|
|
|
string</a> will be sent. There is a privacy option to minimize the
|
|
|
information being sent, but please be aware that this can result in
|
|
|
problems in some cases.</p>
|
|
|
<p>Under the General Data Protection Regulation (GDPR), the California
|
|
|
Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act
|
|
|
(VCDPA), Lei Geral de Proteção de Dados (LGPD), and other regulations,
|
|
|
you have the right to know whether your personal data is stored, shared
|
|
|
or sold to third parties, used for (targeted) advertising, profiling
|
|
|
(for decision making), etc., and you have the right to access, rectify
|
|
|
and delete personal data. To exercise these rights, or if you have
|
|
|
questions about data retention, etc., you can contact the service
|
|
|
providers listed above. You can opt-out of having your data stored,
|
|
|
shared, sold, used for (targeted) advertising, profiling (for decision
|
|
|
making), etc. by not using these optional services/functions.</p>
|
|
|
<p><br /></p>
|
|
|
<h3 id="definitions-of-terms">Definitions of terms</h3>
|
|
|
<p>This section defines some terms and words. Knowing those terms will
|
|
|
help you understand the following sections.</p>
|
|
|
<ul>
|
|
|
<li><em>Data subject</em> – the user of the app</li>
|
|
|
<li><em>Personal data</em> – any data the data subject could be
|
|
|
identified with</li>
|
|
|
<li><em>Data controller</em> – the person / entity providing the
|
|
|
app</li>
|
|
|
<li><em>Data processor</em> – the person / entity providing the app</li>
|
|
|
<li><em>Sub-processor</em> – a third party processing data</li>
|
|
|
<li><em>Data protection officer</em> – the person responsible for any
|
|
|
privacy related enquiries</li>
|
|
|
</ul>
|
|
|
<p><br></p>
|
|
|
<h3 id="contact-details">Contact details</h3>
|
|
|
<p>Please feel free to contact me if you have any concerns:</p>
|
|
|
<pre><code>FairCode BV
|
|
|
Represented by the managing director Marcel Bokhorst
|
|
|
Van Doesburg-Erf 194
|
|
|
3315 RG Dordrecht
|
|
|
the Netherlands
|
|
|
marcel+privacy@faircode.eu</code></pre>
|
|
|
<p>FairCode BV is the data controller. Its data protection officer is
|
|
|
Marcel Bokhorst, reachable via the aforementioned address. For any legal
|
|
|
issues, the place of jurisdiction is Dordrecht, the Netherlands.</p>
|
|
|
<p><br></p>
|
|
|
<h3 id="a.-general-information-on-data-processing">A. General
|
|
|
information on data processing</h3>
|
|
|
<h4 id="i.-scope-of-personal-data-processing">I. Scope of personal data
|
|
|
processing</h4>
|
|
|
<p>This privacy policy / data protection declaration applies to the
|
|
|
Android app FairEmail.</p>
|
|
|
<p>The data processor only processes personal data insofar as absolutely
|
|
|
required for providing a functioning email client as well as the
|
|
|
explicitly requested services. Users’ personal data is usually only
|
|
|
processed if required for fulfilling contractual or legal obligations or
|
|
|
with the user’s consent.</p>
|
|
|
<h4 id="ii-purpose-of-data-processing">II Purpose of data
|
|
|
processing</h4>
|
|
|
<p>The purpose of any data processed is to provide you with the service
|
|
|
requested. The app by default exclusively processes data that is
|
|
|
necessary for the proper functioning of the app and its intended purpose
|
|
|
of being an email client.</p>
|
|
|
<h4 id="iii.-data-storage-and-data-deletion">III. Data storage and data
|
|
|
deletion</h4>
|
|
|
<p>By default, all data (both personal and non-personal) remains on the
|
|
|
data subject’s Android device for as long as not explicitly sent or
|
|
|
shared by the data subject. The data stored on the data subject’s device
|
|
|
can be deleted by the data subject at any time.</p>
|
|
|
<h4 id="iv.-sub-processors">IV. Sub-processors</h4>
|
|
|
<p>The services of all sub-processors are disabled by default. The data
|
|
|
subject’s data is sent to and processed by sub-processors if and only if
|
|
|
explicitly enabled or requested by the data subject.</p>
|
|
|
<p>The sub-processors are:</p>
|
|
|
<ul>
|
|
|
<li><a href="https://www.bugsnag.com/">Bugsnag</a> – <a
|
|
|
href="https://docs.bugsnag.com/legal/privacy-policy/">Privacy
|
|
|
policy</a></li>
|
|
|
</ul>
|
|
|
<h4 id="v.-permissions">V. Permissions</h4>
|
|
|
<p>The app only requests permissions that are necessary for the expected
|
|
|
behavior of an email app. For more information on permissions, see <a
|
|
|
href="https://github.com/M66B/FairEmail/blob/master/FAQ.md#faq1">this
|
|
|
FAQ</a>.</p>
|
|
|
<h4 id="vi.-logging">VI. Logging</h4>
|
|
|
<p>The app does not send any log entries to the data processor by
|
|
|
default. The error reporting system utilizes Bugsnag and is disabled by
|
|
|
default. See <a
|
|
|
href="https://github.com/M66B/FairEmail/blob/master/FAQ.md#faq104">this
|
|
|
FAQ</a> for more information.</p>
|
|
|
<h4 id="vii.-legal-basis">VII. Legal basis</h4>
|
|
|
<p>FairEmail is fully <a href="https://gdpr.eu/">GDPR compliant</a>. The
|
|
|
legal basis for any data processing is Art. 6 (1) a - c GDPR.</p>
|
|
|
<p><br></p>
|
|
|
<h3 id="b.-support-requests">B. Support requests</h3>
|
|
|
<h4 id="i.-description-and-scope-of-data-processing">I. Description and
|
|
|
scope of data processing</h4>
|
|
|
<p>The data subject may contact the data processor to request support
|
|
|
through channels offered by the data processor. When the data subject
|
|
|
contacts the data processor, any provided personal data is stored by the
|
|
|
data controller.</p>
|
|
|
<h4 id="ii.-purpose-of-data-processing">II. Purpose of data
|
|
|
processing</h4>
|
|
|
<p>The personal data is exclusively processed for finding a specific
|
|
|
solution to support queries whilst recording and/or processing them. It
|
|
|
is essential in this respect for the data controller to be able to
|
|
|
contact the person requesting support.</p>
|
|
|
<h4 id="iii.-sub-processors">III. Sub-processors</h4>
|
|
|
<p>The data processor utilizes the services of the following
|
|
|
sub-processors in order to process support requests:</p>
|
|
|
<ul>
|
|
|
<li>Google LLC, if support request sent via email – <a
|
|
|
href="https://policies.google.com/privacy?hl=en">Privacy policy</a></li>
|
|
|
<li>Amazon Web Services EMEA SARL, if support request sent via the
|
|
|
contact form – <a href="https://aws.amazon.com/privacy/">Privacy
|
|
|
policy</a></li>
|
|
|
</ul>
|
|
|
<h4 id="iv.-legal-basis">IV. Legal basis</h4>
|
|
|
<p>Any support requests are sent voluntarily by the data subject,
|
|
|
including any personal data that might be attached. As such, the
|
|
|
explicit consent as outlined in Art. 6 (1) a GDPR forms the legal basis
|
|
|
for processing.</p>
|
|
|
<p>Copyright © 2018-2025 Marcel Bokhorst.</p>
|
|
|
</body>
|
|
|
</html>
|