Last updated: 6 August 2026
Vexa Mail is a desktop application that connects to email accounts you already own and helps you understand what is in them. This policy explains what the application does with your data, what leaves your device, and what your rights are.
The short version. Your email is stored on your own computer, not on our servers. We do not sell it, do not use it for advertising, do not use it to train AI models, and do not read it. Optional AI features send only the specific message you act on to our AI provider, and are off until you turn them on.
The data controller is Vibra Lab S.L., CIF B22903801, Calle Santa Cristina 3, Edificio Embarcadero, Local 1, 10195 Caceres, Spain. Contact: support@vexamail.com.
For most of what Vexa Mail does, we are not a controller in any practical sense: the processing happens on your device, under your control, and we never receive the data. We are named as controller for the limited cases described in sections 4 and 5, where data does reach us or a provider acting for us.
Vexa Mail accesses the email accounts you explicitly connect. For each one it may read and store, on your device:
It also stores the credentials needed to reach those accounts. Passwords and OAuth tokens are kept in your operating system's keychain, never in plain files and never on our servers.
In a database file in your own user account on your own computer. We do not host your mailbox, we do not receive a copy of it, and we cannot read it. If you delete the application's data directory, or remove an account inside the app, the corresponding data is gone from your device.
Backups of that file are whatever your own computer's backup system does. We have no access to them.
If you connect a Gmail account, Vexa Mail uses Google's OAuth flow. We never see or store your Google password. The application requests these scopes:
| Scope | Why it is needed |
|---|---|
gmail.modify |
To read your messages so they can be shown and analyzed on your device, and to carry out the triage you perform in the app - marking read, starring, archiving, applying labels, moving to trash. It is never used to delete mail permanently. |
gmail.send |
To send the replies and messages you compose and explicitly choose to send. |
userinfo.email, userinfo.profile |
To identify which account you connected and label it correctly in the interface. |
Limited Use disclosure. Vexa Mail's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, and for Google user data specifically:
You can revoke Vexa Mail's access at any time at myaccount.google.com/permissions. Removing the account inside the app deletes its stored data from your device.
Three things, and nothing else:
The application talks directly to your provider (your IMAP server, or Google's API) over an encrypted connection, exactly as any email client does. That traffic does not pass through us.
Some features - writing a draft for you, summarizing a long thread, analyzing a message that simple rules cannot classify - are performed by an AI provider acting as our processor. When one of these runs, the content of the specific message or thread involved is sent to that provider over an encrypted connection, processed, and returned.
The rules around this:
To show a sender's icon, the application requests it directly from that sender's own domain and caches it locally. No third-party icon or tracking service is used, and no information about which messages you read is sent anywhere.
Email can contain special categories of personal data about you or third parties. Vexa Mail does not seek out such data or treat it differently, and it stays on your device like everything else.
Data stored on your device is kept until you delete it - by removing an account, deleting individual data in the app, or uninstalling and deleting the data directory. Because we hold no copy, we cannot delete it for you and we cannot recover it for you.
Content sent to the AI provider for an optional feature is processed and discarded; it is not retained to build a profile of you.
Under GDPR you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time. For data on your device, you exercise most of these directly inside the application, which is faster than asking us. For anything we do hold - support correspondence, for example - write to support@vexamail.com and we will respond within one month.
If you believe we have handled your data improperly you may complain to the Spanish supervisory authority, the Agencia Espanola de Proteccion de Datos (aepd.es), or to the authority in your country of residence.
Credentials are stored in the operating system keychain. Connections to your provider and to the AI provider use TLS. Message HTML is sanitized before display and rendered in an isolated frame, and remote content is blocked by default, so a message cannot execute code or phone home.
No system is perfect. If you find a security issue, please report it to support@vexamail.com and we will act on it.
Vexa Mail is not directed at children under 14 and we do not knowingly process their data.
If this policy changes materially, the updated version will be published here with a new date, and where the change concerns data leaving your device you will be told inside the application before it takes effect.
Vibra Lab S.L., CIF B22903801
Calle Santa Cristina 3, Edificio Embarcadero, Local 1, 10195 Caceres,
Spain
support@vexamail.com