Legal

Privacy Policy

This policy explains how Zee Mail handles your data. In short: the app is a mail client running on your own device, connecting directly to your organisation's Zimbra server. Your mail, calendar and contacts never pass through a developer server.

Last updated: 2 October 2026 · App version 1.0.0

Where your data goes

When you sign in, the app connects directly to your organisation's Zimbra server over HTTPS using Zimbra's standard SOAP/JSON interfaces. Messages, calendar events and contacts travel in one direction only:

Your phone ↔ Your organisation's Zimbra server

The developer operates no intermediary server, no backup service for message content, and no ability to read your mail. We do not sell or share this data with third parties.

Data stored on your device

To open quickly and stay usable without a connection, the app keeps a local copy of what you have synced (mail, calendar, contacts). That copy lives in a database encrypted with SQLCipher; the key is stored in the operating system's secure store (Keychain, Keystore or Credential Manager), not in the app.

This data is not carried across to other devices by local backups. When you sign out, all data for that account is removed from the device.

System permissions

The app requests only the following, and only for features you enable yourself:

  • Contacts (read/write) — for the optional sync of contacts to your phone.
  • Calendar (read/write) — for the optional display of phone calendar alongside Zimbra.
  • Notifications — for local appointment reminders.

The app does not request overlay permission, does not access other people's contacts, and does not read your location.

Passwords and sessions

Your password is not stored. The app keeps only the session token issued by the Zimbra server, and that token also lives in the system secure store. When it expires, the app asks you to sign in again.

If your organisation enables an out-of-office auto-reply and you write the reply text yourself, that text is stored on your organisation's server, not on any developer machine.

Mail content and tracking

The app is designed not to reveal that you read a message, unless you act on it:

  • Images fetched from the internet are blocked by default. If you enable "Automatically download external images" in Settings, the sender's server may learn that you opened the message.
  • Instant new-mail notifications are not enabled yet. The app syncs periodically (roughly every 60 seconds while open, roughly every 15 minutes in the background), so the server does not see the app running.
  • Tapping a link always asks first and shows the real destination before opening.

If push notifications are enabled later

To deliver instant notifications, a future release will need a relay service to forward notifications from your organisation's Zimbra server to the device. When that feature is enabled, we will state it here plainly: the relay handles minimal notification data only (message ID, subject and status), does not read message content, and does not retain it.

Your rights

Your mail, calendar and contacts remain your organisation's property and stay on your organisation's Zimbra server. You can:

  • Remove all local data for an account by choosing Sign out.
  • Uninstall the app to remove local data entirely.
  • Ask your organisation to back up or delete server-side data under its internal policy.

Contact

Questions about this policy, about your data, or about security: nlthien@icloud.com.