Privacy & Data: Where Your Email Lives

Kanmail is built privacy-first. This page explains, plainly, how your data is handled.

No servers in the middle

Kanmail is a native desktop application that connects directly to your email provider over standard IMAP and SMTP (or the provider’s OAuth endpoint). Your mail is fetched straight from, and sent straight to, your provider.

There is no intermediary service, relay, or third-party server in the path. Your email never touches an Oxygem/Kanmail server, because there isn’t one in the loop. That means:

How sign-in and passwords are handled

Kanmail uses two authentication methods depending on provider:

Credentials and OAuth tokens are stored in your operating system’s secure credential storage.

What’s stored on your device

Your email and account data live locally on your machine. Because everything is on-device, your privacy is only as exposed as your own computer is: there’s no cloud copy to breach.

Tracking protection, by default

Kanmail strips tracking pixels and hides remote images by default, so senders can’t tell whether or when you opened a message. You can load images on individual messages when you want to see them. (More on how this works: How to Block Email Tracking Pixels.)

One-click unsubscribe, locally

Unsubscribe from mailing lists from inside the app, without visiting an external unsubscribe page. Requires support from the sender, Kanmail will display an “unsubscribe” button when viewing the email thread.

In short

Your mail stays between you and your provider, on your own device, with passwords you never hand to Kanmail. For the full technical detail, see the security overview on the Kanmail site.