← Spool

Spool

Privacy Policy

Effective September 28, 2026

Spool is a Mac email client made by Joe Designs, LLC (“Joe Designs”, “we”). This policy covers the Spool app and this web page. The app is built so that your mail stays between your Mac and your mail provider. We don’t run a Spool server, and nothing in the app sends your mail, your contacts or your usage to us.

The short version

  • Your mail, attachments, drafts and settings are stored on your Mac.
  • Spool has no analytics, no telemetry and no crash uploads. We don’t have an account system, and we never receive your mail.
  • Passwords and sign-in tokens go in the macOS Keychain.
  • The app connects to your mail servers and to GitHub for update checks. It connects to Google, OpenAI or anyone else only when you use a feature that needs them.

What Spool stores on your Mac

To show and search your mail, Spool keeps a local copy of it in a SQLite database at ~/.local/share/spool/mail.db. That copy includes message headers, bodies, attachments, drafts, a search index and messages waiting to be sent. Settings and account details (server names, ports, usernames) are kept in ~/.config/spool.

Passwords, Google sign-in tokens and ChatGPT sign-in tokens are stored in your macOS login Keychain and never written to those files. If you remove an account, Spool deletes its Keychain entries.

Spool doesn’t add its own encryption to the mail database. It relies on your Mac’s file permissions and on disk encryption such as FileVault, which we recommend turning on. If Spool crashes, it writes a crash report to ~/.local/share/spool/panic.log, and that file stays on your Mac. A crash report can include part of whatever the app was handling at the time. Nothing is sent unless you choose to share it with us.

To remove everything Spool has stored, quit the app, delete those two folders and delete the Spool entries from Keychain Access.

What leaves your Mac, and where it goes

This is the complete list of what the app connects to. None of these connections go to Joe Designs.

Your mail servers

Spool connects to the IMAP and SMTP servers you set up to download, organise and send your mail. Your provider handles that mail under its own privacy policy. Spool uses TLS by default. It lets you choose an unencrypted connection if a server requires one, but we advise against it. Setting up an account doesn’t involve any lookup service: Spool connects only to the servers you enter, or to Gmail’s servers if you choose Gmail.

Google, if you sign in with Google

If you add a Gmail account with “Sign in with Google”, Google’s sign-in page opens in your browser, and Spool receives a token that lets it reach your Gmail over IMAP and SMTP. Spool asks for full mailbox access (https://mail.google.com/) because a mail client has to read, move, delete and send your mail. It also asks for your email address to label the account. The token is stored in your Keychain and is sent only to Google.

Spool’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Spool uses Gmail data only to show and manage your mail on your Mac. Joe Designs doesn’t receive it, sell it, use it for advertising or use it to train AI models. It reaches another company only if you turn on one of the features below that sends it there.

You can revoke Spool’s access at any time from your Google Account.

OpenAI, if you turn on the writing tools

The writing tools are off until you sign in with your own ChatGPT account under Settings → Writing. Once you do, the text needed for each request is sent to OpenAI under your account, and OpenAI handles it under its own terms and privacy policy. Spool asks OpenAI not to store these requests. We don’t see them. Depending on the tool, a request can include:

  • Rewrite, Proofread, Shorten and the tone tools: the passage you selected, or your own text in the draft.
  • Write an email and reply suggestions: your draft, its recipients and subject, and when you’re replying, the name and address of the person who wrote to you and the text of the message or conversation you’re replying to. Reply suggestions are requested as soon as you open the writing line on a reply, before you type anything.

Sign out under Settings → Writing and nothing more is sent.

GitHub, for updates

Each time Spool launches, and whenever you choose Check for Updates, it asks GitHub for the latest release. The request carries the app’s version number and nothing that identifies you; like any web request, it reveals your IP address to GitHub. Spool downloads or installs an update only when you click to do so.

Remote images

Emails often contain images hosted elsewhere, and senders use them to see when and where a message was opened. Spool blocks remote images by default. If you allow them for a message, for a sender or for all mail, Spool loads them from the sender’s servers, and those servers can see that the message was opened, along with your IP address.

Unsubscribe

If you press Unsubscribe, Spool contacts the mailing list the way its message asks. It either sends a one-click request to the list’s web address or sends an unsubscribe email from your account. If neither is offered, it opens the list’s page in your browser. This happens only when you press the button.

Extensions you install

Spool doesn’t come with any extensions. An extension you install yourself runs in a sandbox. It can reach your mail only if it declares that permission, and it can connect only to the HTTPS hosts it declares. Its developer is responsible for what it does with your data, so read an extension’s permissions, and trust its developer, before installing it. An extension’s settings, including any API keys you give it, are stored as plain text in its folder.

Links

Links you click in a message open in your default browser. From there, the site you visit and your browser’s own privacy settings apply.

What we don’t collect

Joe Designs receives none of the following from the app: your mail, contacts, drafts, attachments, search history, account details, usage statistics, device identifiers or crash reports. Spool has no sign-up and no Spool account, and it makes no connections to Joe Designs. Because we don’t hold your data, we can’t sell, share or lose it.

We see only what you choose to send us, such as a message through our contact form, an email or a GitHub issue. We use that only to reply to you and to fix what you reported. GitHub issues are public, so don’t include personal information or mail in them.

This website and the download

This page uses Umami, a privacy-focused analytics tool that counts page views without cookies and without building a profile of you. The Spool download is served by GitHub, which handles download requests under its own privacy policy. We see only a total count of downloads.

Your choices and rights

Nearly everything Spool knows about you is on your own Mac, so you control it directly. You can view it, export it with any SQLite tool, or delete it as described above. Depending on where you live (including the EU, the UK and California), you may have rights to access, correct, delete or move personal data a company holds about you. For anything you’ve sent us directly, contact us through the form below and we’ll help. We don’t sell or share personal information as the California Consumer Privacy Act defines those terms.

Children

Spool isn’t directed at children under 13, and we don’t knowingly collect personal information from them.

Changes to this policy

If a future version of Spool handles data differently, for example by connecting to a new service, we’ll update this page before that version is released and change the effective date above. If a change is significant, we’ll mention it in the release notes.

Contact

Questions about this policy or your data can go to Joe Designs, LLC in Albuquerque, New Mexico, through our contact form.