Privacy policy

MailCode · Effective 7 October 2026

MailCode is a personal-use macOS utility that copies verification codes from connected Google mailboxes. This policy describes the app’s handling of Google user data.

Access and purpose

With your authorisation, MailCode uses the Gmail read-only permission to access account addresses, message metadata and email content. Google grants access to the whole mailbox; MailCode uses that access to identify new verification emails and extract codes locally. It excludes Spam, Trash, Drafts and sent messages. It does not modify your mailbox.

Local processing and storage

MailCode requests email directly from Google and processes it on your Mac. Access tokens, email content and detected codes are held in memory. Email bodies and verification codes are not saved to files by MailCode. Recent codes are kept in memory for up to five minutes, with at most 20 entries.

Refresh tokens and OAuth-client configuration are stored in non-synchronising macOS Keychain items. Local settings contain account identifiers and addresses, account labels, preferences, synchronisation cursors and bounded processed-message identifiers. These settings support account management and prevent duplicate copying.

Clipboard and notifications

Detected codes are copied to the macOS clipboard, replacing its current contents. Copies carry confidentiality and transience markers for compatible clipboard managers. Other applications with clipboard access may read or retain them; MailCode cannot guarantee that every clipboard manager honours these markers. MailCode clears its own entry after five minutes only if the clipboard is still unchanged, and does not retain or restore the previous contents. Optional system notifications contain an account label, not the verification code.

Sharing and Google data

MailCode has no app-operated backend, advertising, analytics or AI processing. It does not sell Google user data or transfer email content or codes to an app-operated server. Google receives the authentication and API requests needed to connect and read mail. Your operating system, clipboard applications and Google remain subject to their own settings and policies.

MailCode’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Your choices and deletion

You can pause processing globally or for one account. Removing an account deletes its local credentials and account settings, removes its recent codes, and requests revocation at Google. If remote revocation cannot be completed, revoke access through Google Account connections. Quitting clears recent codes from memory. Uninstalling the app alone may leave Keychain items and local settings on your Mac.

Policy changes

This policy will be updated if MailCode’s data practices change.