Maru Mail privacy policy
Last updated September 1, 2026
The Creative Co. Marketing Firm LLC operates Maru Mail and the optional Maru account service. This policy explains what Maru handles, where it goes, and how you can delete it. The app is free and AGPL.
Mail and Google data
When you connect Gmail, Maru requests the gmail.modify permission. Maru uses it to:
- Read your threads, messages, headers, bodies, attachments, labels, and mailbox change history.
- Change labels, including archive, star, read status, your labels, and Trash status.
- Send messages that you compose or explicitly approve in Maru.
Mail never reaches the Maru account service. Each device gets mail directly from Google. Maru does not permanently delete Gmail messages or bypass Trash.
Data on your device
- Maru stores messages, threads, and attachment metadata in an encrypted local database.
- The operating system keychain stores OAuth tokens and local encryption keys.
- Maru stores settings, search indexes, agent grants, approvals, and the audit log locally.
- Maru fetches attachment contents from Gmail when you open or save them. It does not keep them in the database.
The optional Maru account
The service stores only vault ciphertext it cannot read, your email, device names, and a Stripe customer id. The encrypted vault can include settings, account addresses, and Gmail refresh tokens. The service never receives the account key. Access tokens never enter the vault.
The service keeps ten versions of your vault so you can restore an earlier version. If you delete your Maru account in the app, we purge its service data within 30 days.
Agents and data outside your device
Maru can connect to an AI agent through a local socket. Maru returns mail data only after you create the agent, grant access, and approve a time-limited session.
The agent is a separate program. It may send data to its model provider outside your device. Review the agent provider's terms before you grant access. Every send still needs your separate approval in Maru.
What we do not do
- Maru collects no telemetry, analytics, or automatic crash reports.
- Maru does not sell or rent your data.
- Maru does not use Google data for advertising or to train generalized AI or machine-learning models.
Sub-processors
We use these providers to operate the optional account service:
- Railway hosts the service and its database.
- Stripe processes web billing and holds payment data.
- Apple delivers content-free push notifications.
- Google Cloud provides Pub/Sub for content-free change notices.
Retention and your choices
- Local mail data remains while its Gmail account is connected.
- You can export your Maru account data through the app.
- You can delete your Maru account through the app. We purge its service data within 30 days.
- You can remove a Gmail account to delete its local cache, search entries, tokens, and encryption key.
- You can revoke Maru's Google access at myaccount.google.com/permissions.
You may also ask to access, correct, export, or delete your account information. Email support@getmaru.app. Your local controls remain the fastest way to export or delete data.
Google Limited Use
Maru's use and transfer of information from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Changes and contact
We will update the date above when this policy changes. The source history is public in Maru's repository.
Privacy and support questions: support@getmaru.app. Security reports: security@getmaru.app.