Legal
Privacy Policy
Last updated: July 2026
The short version: Pantomime is a local-first email client. Your mailbox cache, attachments, contacts, calendars, and tasks remain on your device. We sync the cross-device data listed in Section 4, including temporary scheduled-send content. On iOS, we also store a Vault-encrypted copy of your Gmail refresh token and a push notification device token so notifications, badge counts, and snooze wake-up work while the app is closed. We collect no analytics or behavioral data, and we never sell your information.
1. Who we are
Pantomime is a desktop email client for Gmail developed by Ulitus. If you have questions about this policy, contact us at wecare@pantomime.app.
2. What Pantomime does NOT collect
- Received email bodies or attachments (scheduled-send content is the limited exception described in Section 4)
- Your contacts or address book data
- Your calendar events or tasks
- Behavioral analytics, usage telemetry, or crash reports
- Advertising identifiers or tracking cookies
- Your IP address for profiling purposes
Received mailbox content, calendar data, contacts, and tasks are fetched directly from Google's servers using your OAuth credentials and cached on your local device. Pantomime's servers process only the specific data listed in Section 4.
3. Data stored on your device
Pantomime stores the following data locally on your computer:
- Email cache — message headers, bodies, and attachments, stored in an encrypted SQLite database on your device
- Google OAuth tokens — your access and refresh tokens, encrypted with AES-256-GCM using a device-derived key. On iOS, a copy of your refresh token is also stored server-side to enable push notifications — see Section 4
- Contacts & calendar cache — a local copy of your Google Contacts and Calendar, encrypted on disk
- Tasks cache — a local copy of your Google Tasks, encrypted on disk
- App preferences — window size, theme, font, and other UI settings, stored encrypted locally
All local data is encrypted at rest using AES-256-GCM with keys derived from your device identity. Uninstalling Pantomime removes all local data.
4. Data synced to our servers
To enable cross-device functionality, the following preference data is synced to our backend (powered by Supabase, hosted in Australia):
- Snooze schedule — which message IDs you have snoozed and until when (not message content)
- Scheduled sends — email payloads for send-later messages (body text, recipients, subject) until the email is sent, then deleted
- Task preferences — deleted task metadata, list colors, and recurrence rules
- Automation flows — your snooze rules and automation configurations
- Profile avatar — a custom profile photo if you set one (optional)
- Recent label history — recently used label names for faster compose suggestions
- Push notification device token — a Firebase Cloud Messaging (FCM) identifier for your device, used only to route notifications to your phone
- Gmail refresh token (iOS only) — transmitted over TLS and encrypted at rest in Supabase Vault. It is used server-side to inspect Gmail history and unread counts for accurate push alerts and badges, and to restore snoozed messages to the Inbox by updating Gmail labels when their wake time arrives. It is not used to send email
Scheduled send payloads are stored temporarily until the email is sent. Once sent, they are immediately deleted from our servers. They are never used for any purpose other than delivering your email at the scheduled time.
The server-side Gmail refresh token and push device token support iOS notifications, badge counts, and server-side snooze wake-up. If Google reports the token revoked (for example, if you remove Pantomime's access at myaccount.google.com/permissions), we delete our stored copy automatically. You can also request deletion at any time — see Section 8.
Your data is associated with your Supabase user ID and protected by access controls. It is processed only to provide Pantomime and by the service providers listed in Section 6; it is not sold or used for advertising.
5. Google account access
Pantomime uses Google OAuth 2.0 to access your Gmail, Google Calendar, Google Contacts, Google Tasks, and Google Drive (metadata only). The OAuth scopes we request are:
- Gmail — read, compose, send, and manage your email
- Calendar — read and manage calendar events
- Contacts — read and manage your Google Contacts
- Tasks — read and manage Google Tasks
- Drive — metadata only (to open attached files)
Platform-appropriate installed-app OAuth client IDs are used within the same Google Cloud project. Pantomime requests the same functional scope set and does not request a second, narrower-scoped credential for notification processing. On iOS, a Vault-encrypted copy of your refresh token is stored server-side for the purposes described in Section 4.
Pantomime's use of Google user data complies with the Google API Services User Data Policy , including the Limited Use requirements. Your Google data is used solely to operate the app on your behalf and is never used for advertising, sold, or shared with third parties.
6. Third-party services
- Supabase — Our backend database for cross-device sync. Data is stored in Australia. See Supabase's privacy policy.
- Firebase Cloud Messaging (Google) — Used to deliver push notifications to the mobile app. Firebase receives your device push token and notification routing data. New-mail pushes use your account address and a generic message notice; snooze reminders can include the scheduled message subject. See Firebase's privacy policy.
- Gravatar — When displaying sender photos, we may request a profile image from Gravatar using an MD5 hash of the sender's email address. This is a read-only lookup and no data is stored on Gravatar's servers.
- Open-Meteo — Weather data for the calendar view is fetched from Open-Meteo using your approximate location. Open-Meteo is GDPR-compliant and does not store personal data. See Open-Meteo terms.
- IP geolocation — To determine your location for weather, Pantomime may make a one-time request to a public IP geolocation service (ipwho.is, ipinfo.io, or freeipapi.com). Your location is cached locally for 24 hours to minimize requests. You can disable weather in the app settings.
- Cloudflare Turnstile — Used during account sign-up to prevent automated registrations. Cloudflare processes the CAPTCHA challenge. See Cloudflare's privacy policy.
7. Account and authentication
Creating a Pantomime account requires an email address and password, handled by Supabase Auth. Your email address is used solely to:
- Identify your account and sync your preferences across devices
- Send a one-time confirmation email when you register
- Allow password reset if requested
We do not send marketing emails or newsletters.
8. Data retention and deletion
You can delete your Pantomime account at any time by contacting wecare@pantomime.app. Upon deletion, all data associated with your account on our servers (synced preferences, scheduled sends, snooze data, push notification tokens, and any stored Gmail refresh token) is permanently deleted.
Local data stored on your device is not affected by account deletion.
To remove local data, uninstall Pantomime and delete the app data folder
at %APPDATA%\pantomime (Windows) or
~/.config/pantomime (Linux) or
~/Library/Application Support/pantomime (macOS).
9. Children's privacy
Pantomime is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13.
10. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of Pantomime after changes constitutes acceptance of the updated policy.
11. Contact
If you have questions or concerns about this privacy policy or how we handle your data, please contact us at wecare@pantomime.app.