1. Operator and contact
Seamark Mail is operated by Junhoi Park / Gagasoft (“Seamark,” “we,” “us,” or “our”).
Email: admin@gagasofts.com
Address: 150 Samseong-ro, Gangnam-gu, Seoul 06288, South Korea
2. Scope
This Privacy Policy applies to the Seamark Mail Android application, the Seamark server used by the application, and this website. Gmail, Microsoft-hosted Outlook/Hotmail/Live/Microsoft 365, and Zoho Mail can currently be connected through OAuth. iCloud Mail, Fastmail and other compatible accounts can be connected with user-entered IMAP/SMTP settings. Yahoo Mail and AOL Mail connectivity is implemented but remains unavailable in production until each provider separately approves the required mail scopes and production credentials are configured.
3. Information we access and process
| Category | Examples | Where it is handled |
|---|---|---|
| Google account profile | Google account identifier, email address, display name and profile picture URL | Stored with the connected Seamark account |
| Microsoft account profile | Microsoft account identifier, email address or user principal name, and display name | Stored with the connected Seamark account |
| Yahoo account profile | Yahoo account identifier, email address, display name and profile picture URL | Stored with the connected Seamark account after Yahoo access is approved and you connect the account |
| AOL account profile | AOL account identifier, email address, display name and profile picture URL | Stored with the connected Seamark account only after separate AOL access is approved, configured and authorized |
| Zoho account profile | Zoho user and mail-account identifiers, email address, display name, and approved regional account and Mail API endpoints | Stored with the connected Seamark account so later OAuth refresh and mail requests use the verified Zoho data center |
| Password-authenticated account settings | Email address, display name, public IMAP/SMTP host, port, security mode, username and password or app-specific password | Both servers are verified before saving. Passwords are encrypted with AES-256-GCM on the Seamark server and are never returned to the Android app |
| Gmail data | Message IDs, senders, recipients, subject, snippets, timestamps, labels, message bodies, attachment names and metadata, drafts and sent content | Retrieved from Gmail when needed; recently opened message data may be held in the application-encrypted reader cache described below, but attachment file bytes are not stored in that cache |
| Microsoft mail data | Message and conversation IDs, folders, flags, senders, recipients, subject, preview, timestamps, bodies, attachments, drafts and sent content | Retrieved from Microsoft Graph when needed; recently opened message data may be held in the application-encrypted reader cache described below, but attachment file bytes are not stored in that cache |
| Yahoo mail data | Immutable email and thread IDs, folders, flags, senders, recipients, subject, timestamps, bodies, attachments, drafts and sent content | Retrieved through OAuth-protected Yahoo IMAP or transmitted through Yahoo SMTP when needed; recently opened message data may be held in the application-encrypted reader cache described below, but attachment file bytes are not stored in that cache |
| AOL mail data | Mailbox/message identifiers, folders, flags, senders, recipients, subject, timestamps, bodies, attachments, drafts and sent content | Retrieved through OAuth-protected AOL IMAP or transmitted through AOL SMTP when needed after separate approval and authorization; the same bounded encrypted reader cache applies |
| Zoho mail data | Account, folder, message and thread identifiers; flags; senders; recipients; subject; preview; timestamps; bodies; attachments; drafts and sent content | Retrieved from or transmitted to the approved regional Zoho Mail API when needed; recently opened message data may be held in the bounded encrypted reader cache |
| Optional online sender photos | Only after you enable Online sender photos, the authenticated app sends the selected account ID and sender email address to the Seamark server. For eligible providers, the server normalizes the address and creates the SHA-256 identifier required to request a public Gravatar image. If no Gravatar exists for a validated domain, the server may request that domain’s public favicon from Google’s fixed favicon service | The Android app does not contact Gravatar or Google’s favicon service directly. Gravatar receives the identifier, while Google receives only the validated sender domain; both receive the Seamark server’s standard request data rather than your device IP address. Images and negative results may be held temporarily in bounded server memory and app-private memory. Common personal mailbox domains are skipped for favicon quality, Yahoo and AOL accounts are excluded from external sender-photo lookup, and turning the setting off prevents new remote lookups |
| On-demand AI data | For translation, summary or reply drafting: the eligible message subject and visible body, your requested language, time zone, reply instruction and a pseudonymous safety identifier. For new-email drafting: your instruction, current editable subject and current editable body, requested language, time zone and pseudonymous safety identifier | Sent through the Seamark server to the configured external AI provider only after you tap the corresponding AI control. Recipient addresses, attachments and OAuth credentials are excluded. Yahoo and AOL message content is rejected before external message processing. Production currently uses OpenAI |
| AI output on the device | Translated subject/body; summary overview and key points; zero to five suggested actions with supporting source quotes; editable reply drafts; and editable new-email subject/body drafts | Returned to the app for review. Cached translation and summary output is encrypted with an Android Keystore-backed key for up to 30 days. Reply and new-email drafts are placed in the editable composer and are not automatically sent. The Seamark database does not store these outputs |
| AI usage and cost metadata | Internal Seamark user ID, feature type, provider and model, provider request ID, token counts, rate snapshot, calculated cost and timestamp | Stored in the Seamark database for cost control and operational accounting. It does not contain the provider message ID, subject, body, translation, summary or suggested actions |
| Premium subscription and purchase data | Seamark user ID, Google Play purchase token, product and base-plan ID, current lifecycle state, auto-renewal state, start and expiry time, region code, acknowledgement state, linked purchase token, order ID, currency, gross amount, tax, developer revenue, refund amount and time, and whether the purchase is a test purchase | Purchase tokens are sent by the app to the Seamark server and used with the Google Play Developer API to verify entitlement. Verified lifecycle data is stored in the subscribes table; order and revenue records are stored in subscribe_payments. Seamark does not receive your full payment-card details |
| Advertising and ad-delivery data | For non-premium users, Google Mobile Ads may process device and app information, IP address, advertising or app identifiers, diagnostics and ad views or interactions, depending on device settings, region and consent choices | Processed by Google’s Mobile Ads services until the server verifies an active premium entitlement. Seamark does not send provider account identity, OAuth credentials, mailbox contents or sender/recipient data for ad selection or personalization |
| Analytics and crash diagnostics | Firebase Analytics processes app lifecycle and session information, coarse geography derived from a masked IP address, app-instance or advertising identifiers, device/app information, and closed-label events such as screen, feature, provider category, mailbox category, result, boolean state and count, size or duration range. Firebase Crashlytics processes crash and ANR stack traces, relevant app/device state, installation/session identifiers, closed-label breadcrumbs, and sanitized non-fatal exception categories | Processed by Google Firebase in release builds to measure feature reliability and diagnose failures. Seamark does not set a Firebase user ID or send names, email addresses, provider account/message IDs, sender or recipient data, subject/body text, search text, attachment names or bytes, OAuth credentials, AI prompts or AI output as Analytics parameters, Crashlytics custom keys or custom logs |
| User-selected device content | Files, photos or a photo captured through another camera app that you explicitly select to attach to an outgoing message | Encrypted in the app’s private storage while a send is pending, transmitted through the Seamark server to the selected provider, and deleted from pending-mail storage after send, final failure or discard |
| Authorization data | OAuth scope record and Google, Microsoft, Yahoo, AOL or Zoho refresh token; or encrypted IMAP/SMTP credentials for a manual account | Refresh tokens and manual-account passwords are encrypted on the Seamark server. Short-lived OAuth access tokens are obtained when needed; Zoho access tokens may be cached in server memory until shortly before expiry |
| Seamark account data | Internal user/account IDs, sync and default-sender selections, account display settings and Seamark pin IDs | Stored in the Seamark database to provide account and pin features |
| Mailbox synchronization and notification data | Gmail history/watch state; Microsoft Graph subscription ID, hashed client state and expiration; custom-account IMAP IDLE ownership and UID cursors; Firebase installation data; and new-mail message ID, sender, recipient, subject and short preview | Sync state and installation data are stored while needed. Gmail/Microsoft preview fields are sent transiently through Firebase. Custom-account previews may be held in a retry outbox until delivery and are removed no later than the configured seven-day outbox retention period |
| Security data | Hashed app sessions, hashed one-time login codes, OAuth state hashes, expiry times and optional device label | Stored temporarily to authenticate and protect requests |
| Technical request data | Network address, request timing and error information that hosting or network systems may process | Processed as needed to deliver, secure and troubleshoot the service |
To make recently opened messages load promptly, Seamark may keep message headers, recipients, body content, flags and attachment metadata in an application-encrypted cache on the Seamark server and in the app’s private cache. Entries expire no later than 24 hours after retrieval and may be removed earlier by size limits, provider change signals, account disconnect, app-data removal or operating-system cache eviction. Attachment file bytes are not stored in this reader cache. Separately, encrypted translation and summary results may remain in the app’s private cache for up to 30 days. These caches are used only for user-facing mail and AI features and are not used for advertising, analytics, profiling or model training.
The Android app requests network access and, on supported Android versions, notification permission. It does not request contacts, location, camera or microphone permission. When you add an attachment, Android’s document or photo picker—or a separate camera app—provides only the item you choose. On Android 9 and earlier, the app declares legacy storage write permission so an attachment you request can be saved to Downloads.
4. How we use information
We use the information described above only to:
- connect and identify the supported OAuth or IMAP/SMTP mail accounts you authorize;
- display mailboxes and messages and perform the mail actions you request;
- after you explicitly enable Online sender photos, display an eligible sender’s public Gravatar image or business-domain favicon when available, or otherwise use a provider account image or locally generated initial;
- send, reply to and forward messages from the account you select;
- maintain multi-account selection, Seamark pins and secure sessions;
- detect Gmail, Microsoft or compatible custom-account Inbox changes and send either a content-free refresh signal or a new-mail preview; Yahoo, AOL and Zoho do not currently use this push path;
- translate or summarize an eligible message after you press the corresponding control, using the configured external provider; Yahoo and AOL mail are excluded;
- create an editable AI reply or new-email draft after you enter an instruction and request it, without sending the draft automatically;
- show only source-supported suggested actions and open a composer or an appropriate Android app after you select one; Seamark does not execute suggested actions automatically;
- verify Google Play purchases, maintain premium entitlement across devices, acknowledge qualifying purchases, record order/refund accounting and remove ads while premium is active;
- load and display native ads for non-premium users through Google Mobile Ads without supplying provider mail or OAuth data for advertising;
- measure coarse app and feature usage and diagnose crashes, ANRs and sanitized non-fatal failures through Firebase Analytics and Crashlytics without attaching provider mail content or account identifiers;
- revoke access and delete account records when you disconnect an account;
- protect, operate, troubleshoot and comply with legal obligations for the service.
We do not sell personal information. We do not use connected-account mail data for advertising, profiling, unrelated marketing or training generalized AI models.
Legal bases where the GDPR applies
Where European data-protection law applies, Seamark relies on performance of the service contract to connect accounts and perform requested mail actions; your affirmative request for optional actions such as translation, summary and notification previews; legitimate interests in securing, troubleshooting and measuring the cost of the service where those interests are not overridden by your rights; and compliance with legal obligations where required. You may withdraw a consent-based choice or object to certain processing by not using the optional feature, disconnecting the account or contacting us, subject to processing that remains necessary for legal or security reasons.
5. Provider user data and OAuth
Seamark uses Google OAuth, OpenID Connect user information and the Gmail API. After you choose to connect Gmail, Seamark requests openid, email, profile and the restricted https://mail.google.com/ scope.
The Gmail scope allows the app, at your direction, to read messages and attachments; compose, send, reply to and forward mail; change labels and state; move messages to spam or trash; restore them; and permanently delete them. These permissions are required for the mail functions described on our home page.
Seamark uses the restricted https://mail.google.com/ scope instead of narrower Gmail scopes because it currently provides user-confirmed immediate permanent deletion of individual messages and user-confirmed emptying of Spam or Trash. The narrower gmail.modify scope does not permit permanent deletion that bypasses Trash. Seamark does not request Gmail permissions for planned providers or other unimplemented features.
Google user data is used only to provide or improve the user-facing email features described in this policy. We do not allow people to read Gmail data unless you first give affirmative permission for specific data, access is necessary for security or legal compliance, or the data is aggregated for internal operations in accordance with applicable law. Gmail data is not used for generalized AI or machine-learning model training.
Google receives and processes information under your Google account settings and Google’s own terms and privacy policies. Seamark is not affiliated with or endorsed by Google.
Microsoft accounts and Microsoft Graph
After you choose Microsoft mail, Seamark uses the Microsoft identity platform’s common endpoint so personal Microsoft accounts and work or school accounts can sign in. It requests openid, profile, email, offline_access, delegated User.Read, Mail.ReadWrite and Mail.Send.
User.Read identifies the connected account. Mail.ReadWrite lets Seamark display and organize mail, access attachments and perform confirmed deletion. Mail.Send is separately required to compose, reply and forward. offline_access allows encrypted refresh-token storage so access tokens can be renewed while the account remains connected.
Microsoft Graph change-notification subscriptions are renewed before expiration and use a hashed secret client state to reject forged webhook notices. Microsoft does not provide this flow with an endpoint to revoke only one stored refresh token. Disconnecting deletes Seamark’s credential and subscription; you can additionally revoke Seamark from your Microsoft account privacy page or your organization’s My Apps portal. Organizational administrators may require or withdraw consent.
Yahoo Mail and OAuth-protected IMAP/SMTP
After Yahoo approves Seamark for mail access and you choose Yahoo Mail, Seamark requests openid, profile, email, mail-r and mail-w. The identity scopes identify the account. mail-r permits mailbox, message and attachment reading. mail-w permits sending and the message changes you request, including read state, starring, moving and confirmed deletion.
Yahoo no longer provides its former proprietary Mail APIs for this use. Seamark uses Yahoo’s standard IMAP and SMTP interfaces over TLS with OAuth2 bearer authentication. It does not request Yahoo contacts or calendar scopes. Yahoo’s restricted mail scopes are not self-service; production Yahoo access remains disabled until Yahoo reviews and approves Seamark.
The Yahoo access token is short lived. Seamark encrypts the refresh token on the server and uses it to obtain a new access token as needed. Disconnecting deletes the local credential and requests Yahoo token revocation. Yahoo mail bodies and attachment metadata are retrieved only for the action you request and may enter the bounded application-encrypted reader cache described in this policy; attachment file bytes are not stored in that cache.
AOL Mail and OAuth-protected IMAP/SMTP
AOL support uses a separate OAuth client and credential from Yahoo, even though the providers share parts of their identity infrastructure. When separately approved and configured, Seamark requests openid, profile, email, mail-r and mail-w, stores the encrypted refresh token, and uses OAuth-protected AOL IMAP/SMTP over hostname-verified TLS. Production AOL access is currently disabled because approved AOL credentials are not configured. AOL content is excluded from external AI and external avatar/domain-icon lookup.
Zoho Mail OAuth and regional Mail API
Zoho Mail uses a server-based OAuth flow and requests ZohoMail.accounts.READ, folder read/update, and message read/create/update/delete scopes. Seamark validates Zoho’s callback data-center values against a fixed allowlist, stores the approved regional endpoints with the encrypted refresh token, and sends later token and mail requests only to that region. Disconnecting requests refresh-token revocation and removes the local credential.
Password-authenticated IMAP/SMTP accounts
For iCloud Mail, Fastmail and other compatible accounts, you provide the public server addresses, ports, security modes, usernames and password or app-specific password. Seamark rejects raw-IP and private-network hosts, requires hostname-verified TLS or required STARTTLS, authenticates both IMAP and SMTP before saving, and encrypts passwords on the server. Compatible IMAP servers may use a read-only IDLE connection for new-mail notification delivery.
Optional external message and drafting AI
When you tap Translate, Summarize or Create AI reply draft for an eligible message, Seamark retrieves that message and sends its subject and visible body text, up to the configured processing limit, to the server-selected AI provider. Reply drafting also includes the instruction you enter. Summary and drafting requests include the requested output language and your device time-zone identifier; summaries also include the message timestamp so dates can be interpreted. When you request help writing a new email, Seamark sends the instruction you enter and the current editable subject and body so the provider can return a replacement draft. Recipient addresses, attachments and provider OAuth tokens are not included. Yahoo and AOL message content is blocked before every external message AI request.
Production currently selects OpenAI. OpenAI requests include store=false; this does not eliminate security or abuse-monitoring logs. OpenAI states that API data is not used to train its models unless the customer opts in and that default abuse-monitoring logs may be retained for up to 30 days. Seamark has not enabled Gemini in production: the production deployment does not expose a Gemini key while paid-service data-processing terms and billing status remain unverified. Provider processing is governed by the applicable OpenAI API data controls and, if separately enabled in a reviewed environment, Gemini API terms.
The server does not persist the AI source or generated output in a dedicated AI-result table and does not write them to application logs. It stores only the content-free usage and cost metadata described above. The Android app encrypts translated and summarized outputs in its private cache for up to 30 days. Reply and new-email drafts are returned directly to the editable composer and are never sent automatically. Summary recommendations are restricted to calendar events, reminders, reply drafts, web links, maps and phone dialing; the server requires supporting source text, and the app acts only after you select a recommendation. Calendar and reminder intents open a compatible app for review rather than silently writing calendar data.
7. Storage and retention
- Recently opened provider messages: message headers, recipients, body content, flags and attachment metadata may be stored in an application-encrypted server cache and Android private cache for no longer than 24 hours after retrieval. Reads do not extend that lifetime. Entries may be removed earlier by size limits, provider change signals, account disconnect, app-data removal or operating-system cache eviction. Attachment file bytes are not stored in this cache. The cache is only for the user-facing mail reader and is not used for advertising, analytics, profiling or model training.
- Optional sender profile images: not stored in the Seamark database. When Online sender photos is enabled, positive results may remain in bounded Seamark server memory for up to 24 hours and app-private memory for up to 12 hours; missing-image results may remain for up to one hour. These caches are process-local, use non-plaintext cache keys, and are removed on process restart, eviction, app-data clearing or when no longer needed. Turning the setting off prevents new requests.
- AI source and output: the external provider handles source text, instructions, current editable draft and output for the requested operation and may retain security or abuse-monitoring records under its terms. Seamark does not store AI source or output in a dedicated server-side AI-result table. Encrypted translation and summary outputs may remain in the app’s private cache for up to 30 days; reply and new-email drafts remain in the composer only as part of the email you edit or send. Account disconnect, clearing app data or operating-system eviction may remove local records earlier.
- AI usage and cost metadata: retained as an operational accounting record until it is no longer reasonably necessary for cost control, security, troubleshooting or legal compliance; it contains no message content or message identifier.
- Subscription and order records: retained while the related Seamark profile exists and as long afterward as reasonably required for payment reconciliation, fraud prevention, tax, accounting, dispute handling or other legal obligations. Disconnecting the final email account deletes subscription rows linked to the Seamark profile from the application database, but Google Play and legally required processor/accounting records remain subject to their own retention rules.
- Outgoing attachments selected on your device: stored encrypted in the app’s private pending-mail directory while needed for background sending and removed after successful send, final failure or discard. The Seamark server holds attachment bytes only while forwarding the request to the selected provider; it does not intentionally persist them.
- Account profile, encrypted refresh token and Seamark pins: retained while the provider account remains connected.
- Gmail watch or Microsoft subscription state and Firebase installation ID: retained while related accounts remain connected and deleted with the related account or profile.
- Firebase Analytics and Crashlytics records: lifecycle, closed-label interaction, installation/session, crash, ANR and sanitized non-fatal diagnostic records are retained under the Firebase/Google Analytics controls and retention settings applicable to the service. Clearing app data or uninstalling resets local Firebase identifiers, and you may contact us for an applicable deletion request.
- Custom-account notification state: IMAP IDLE ownership and UID cursors are retained while the related account remains connected. A new-mail preview in the durable retry outbox is removed after delivery and no later than the configured seven-day retention period.
- App sessions: expire after 30 days and are stored only as hashes on the server.
- OAuth attempts and login codes: expire after approximately 10 minutes and 2 minutes respectively; expired security records are removed on a recurring cleanup schedule.
- Operational records: retained only as long as reasonably necessary for security, troubleshooting and legal compliance, then deleted or de-identified where appropriate.
Disconnecting your only email account also removes the associated Seamark profile, sessions and application subscription/payment rows linked by that profile. It does not cancel a Google Play subscription; cancel or manage renewal separately in Google Play. If more than one account is connected, only the account you select and its dependent mail records are removed, while the profile-level premium entitlement remains available to the remaining accounts.
8. Security
Seamark uses HTTPS in transit; secure-browser OAuth for Google, Microsoft, Yahoo, AOL and Zoho; S256 PKCE for the app callback and Microsoft authorization; authorization-attempt nonce binding where supported; fixed allowlists for Zoho regional endpoints; public-host validation and hostname-verified TLS or required STARTTLS for IMAP/SMTP; AES-256-GCM encryption for stored refresh tokens, manual-account passwords and the server reader cache; hashed sessions, one-time codes and webhook client state; and Android Keystore-backed encryption for local sessions, mail and AI-result caches.
No security measure is absolute. Protect your device and provider account. If access may be compromised, disconnect the account in Seamark, change any manual-account password or app-specific password, and review connected-app access at your OAuth provider.
9. Your choices and rights
Disconnect and delete a connected account
In Seamark Mail, open account management, select the account, choose Disconnect selected email account, and confirm. Seamark deletes the selected account’s encrypted credential, reader and AI caches, notification state and related records. Google, Yahoo, AOL and Zoho token revocation is requested where supported; for Microsoft, use Microsoft’s account or organization portal if you also want to revoke the provider-side app grant. For a manual account, you can additionally revoke or change the app-specific password at your email provider.
Revoke from Google
You can also remove Seamark Mail from the third-party access section of your Google Account. Revoking at Google stops future Gmail API access but may not by itself remove Seamark account metadata; contact us or disconnect in the app for that request.
Revoke from Microsoft
Personal Microsoft users can review app access from their Microsoft account privacy dashboard. Work or school users can use the My Apps portal or contact their administrator. Provider-side revocation stops future Graph access but does not by itself delete Seamark account metadata.
Revoke from Yahoo
Disconnecting a Yahoo account asks Yahoo to revoke the stored grant and removes Seamark’s local credential. You can also review or remove connected applications in your Yahoo account security settings. Provider-side revocation stops future Yahoo mail access but does not by itself delete Seamark account metadata.
Revoke from AOL or Zoho
Disconnecting asks the provider to revoke the stored refresh token where supported and removes Seamark’s local credential. You can also review connected applications in the provider’s account-security settings. Provider-side revocation stops future access but does not by itself delete Seamark account metadata.
Privacy requests
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection or portability. Email admin@gagasofts.com. We may ask for information needed to verify that the request relates to your account.
Advertising choices
Device, Google account and regional consent settings may affect how Google Mobile Ads processes advertising data. You can use Android and Google advertising controls where available. Seamark stops requesting ads after it verifies an active premium entitlement, and resumes the non-premium ad path only after that entitlement expires or is revoked. Seamark does not use provider mail or OAuth data for personalized advertising. Contact us if you need help exercising an applicable access, deletion, objection or opt-out right relating to Seamark’s own processing.
10. International use
Seamark’s service infrastructure is operated in South Korea. Information may also be processed by Google, Google Play, Microsoft, Yahoo, AOL, Zoho, OpenAI, Google Mobile Ads, Firebase, Gravatar or another listed processor in locations described in their policies. Gemini is not enabled in production. Where applicable, we use required contractual and technical safeguards for cross-border processing.
11. Children’s privacy
Seamark Mail is a general email utility and is not directed to children under 13 or a higher minimum age required by local law. We do not knowingly collect a child’s personal information without valid authorization. If you believe a child has provided information improperly, contact us so we can investigate and take appropriate action.
12. Changes to this policy
We may update this policy when the product, providers, infrastructure or legal requirements change. The updated policy will be posted at this URL with a revised “last updated” date. Material changes may also be announced in the app when appropriate.
13. Contact
For privacy questions or requests:
Junhoi Park / Gagasoft
150 Samseong-ro, Gangnam-gu, Seoul 06288, South Korea
admin@gagasofts.com
See also the Seamark Mail Terms of Service.