Privacy.
How Mejla accesses, uses, stores, protects, and shares Google user data.
Overview
Mejla is a native macOS Gmail client developed by Ideäng Productions AB. The app connects your Mac directly to Google. Ideäng operates no mail server, runs no advertising or analytics, and does not receive your mailbox or OAuth credentials.
Google user data we access
After you choose a Google account and grant access, Mejla handles the account email address; Gmail messages, threads, sender and recipient headers, subjects, bodies, attachments, drafts, labels, read/starred state, and history identifiers; basic Gmail settings such as filters, vacation responder and available send-as identities; and names, email addresses, and available profile photos from Google Contacts and Other Contacts.
OAuth scopes
Mejla requests exactly: https://www.googleapis.com/auth/gmail.modify, https://www.googleapis.com/auth/gmail.settings.basic, https://www.googleapis.com/auth/contacts.readonly, and https://www.googleapis.com/auth/contacts.other.readonly.
How we use Google user data
The data is used only for visible app features: synchronizing and displaying mail across your signed-in accounts, local search and notifications, composing and sending, organizing mail, managing basic Gmail settings, showing contacts, and performing an action you explicitly request. Mejla and Ideäng do not use Google Workspace API data for advertising, credit or lending decisions, data brokerage, surveillance, or to develop, improve, or train generalized or non-personalized AI/ML models.
Storage, retention, and deletion
Mail, attachment metadata, contact presentation data, and settings are cached locally in Mejla’s macOS App Sandbox. Production OAuth tokens are stored in macOS Keychain, never in the mail database. Local mail data remains until you sign out and remove it or delete Mejla’s container. Redacted local crash logs are removed automatically after 30 days and are never uploaded. You can revoke access at myaccount.google.com/permissions and delete all app data in ~/Library/Containers/se.ideang.mejla/.
Sharing, transfer, and disclosure
Mejla does not sell Google user data, and Ideäng does not share it with advertisers, data brokers, information resellers, or unrelated third parties. Normal traffic goes directly between your Mac and Google’s OAuth, Gmail, and People APIs. Remote images are blocked by default; if you choose to load them, your Mac connects directly to the image host. Some direct builds can, only on your explicit request, send a bounded, reviewable mail selection through a separately installed local AI command-line tool to the provider you chose. The feature is off by default, never gives the tool a Google token, never sends mail automatically, and does not permit transfer for advertising or generalized AI training. TestFlight and Mac App Store builds do not contain that integration.
Protection of sensitive data
Google API and OAuth traffic uses HTTPS/TLS. OAuth uses PKCE and a unique state value, and production refresh tokens are protected by macOS Keychain. The local cache is protected by App Sandbox, operating-system file permissions, and your macOS account; FileVault provides disk encryption when enabled. Remote images are blocked by default, tracking pixels can be removed, and downloaded email attachments are quarantined before preview, open, or Finder reveal. OAuth tokens, authorization headers, and message bodies are excluded from crash reports.
Google Limited Use and contact
Mejla’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. If our handling changes, we will update this page before the new use begins and request any required consent. Privacy questions: [email protected]. Last updated August 31, 2026.