Legal

Privacy Policy

Last updated: July 2026

The short version: Pantomime is a local-first email client. Your mailbox cache, attachments, contacts, calendars, and tasks remain on your device. We sync the cross-device data listed in Section 4, including temporary scheduled-send content. On iOS, we also store a Vault-encrypted copy of your Gmail refresh token and a push notification device token so notifications, badge counts, and snooze wake-up work while the app is closed. We collect no analytics or behavioral data, and we never sell your information.

1. Who we are

Pantomime is a desktop email client for Gmail developed by Ulitus. If you have questions about this policy, contact us at wecare@pantomime.app.

2. What Pantomime does NOT collect

Received mailbox content, calendar data, contacts, and tasks are fetched directly from Google's servers using your OAuth credentials and cached on your local device. Pantomime's servers process only the specific data listed in Section 4.

3. Data stored on your device

Pantomime stores the following data locally on your computer:

All local data is encrypted at rest using AES-256-GCM with keys derived from your device identity. Uninstalling Pantomime removes all local data.

4. Data synced to our servers

To enable cross-device functionality, the following preference data is synced to our backend (powered by Supabase, hosted in Australia):

Scheduled send payloads are stored temporarily until the email is sent. Once sent, they are immediately deleted from our servers. They are never used for any purpose other than delivering your email at the scheduled time.

The server-side Gmail refresh token and push device token support iOS notifications, badge counts, and server-side snooze wake-up. If Google reports the token revoked (for example, if you remove Pantomime's access at myaccount.google.com/permissions), we delete our stored copy automatically. You can also request deletion at any time — see Section 8.

Your data is associated with your Supabase user ID and protected by access controls. It is processed only to provide Pantomime and by the service providers listed in Section 6; it is not sold or used for advertising.

5. Google account access

Pantomime uses Google OAuth 2.0 to access your Gmail, Google Calendar, Google Contacts, Google Tasks, and Google Drive (metadata only). The OAuth scopes we request are:

Platform-appropriate installed-app OAuth client IDs are used within the same Google Cloud project. Pantomime requests the same functional scope set and does not request a second, narrower-scoped credential for notification processing. On iOS, a Vault-encrypted copy of your refresh token is stored server-side for the purposes described in Section 4.

Pantomime's use of Google user data complies with the Google API Services User Data Policy , including the Limited Use requirements. Your Google data is used solely to operate the app on your behalf and is never used for advertising, sold, or shared with third parties.

6. Third-party services

7. Account and authentication

Creating a Pantomime account requires an email address and password, handled by Supabase Auth. Your email address is used solely to:

We do not send marketing emails or newsletters.

8. Data retention and deletion

You can delete your Pantomime account at any time by contacting wecare@pantomime.app. Upon deletion, all data associated with your account on our servers (synced preferences, scheduled sends, snooze data, push notification tokens, and any stored Gmail refresh token) is permanently deleted.

Local data stored on your device is not affected by account deletion. To remove local data, uninstall Pantomime and delete the app data folder at %APPDATA%\pantomime (Windows) or ~/.config/pantomime (Linux) or ~/Library/Application Support/pantomime (macOS).

9. Children's privacy

Pantomime is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13.

10. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of Pantomime after changes constitutes acceptance of the updated policy.

11. Contact

If you have questions or concerns about this privacy policy or how we handle your data, please contact us at wecare@pantomime.app.