Mail Privacy Notice

UniversalVersion 5Last updated 2 October 2026

Mail Privacy Notice

Effective Date: 2 October 2026 Last Updated: 2 October 2026

This notice covers DiscoverWorthy Mail, our mail app for Windows, Android and iPhone. It sits alongside our Privacy Policy and adds to it — everything in that policy still applies. Where this notice is more specific about the mail app, this notice governs.

It exists because a mail app is different from the rest of the platform, and because there are now two kinds of mailbox it can hold. One of them we are not part of at all. The other one we run. Those are different promises and this notice keeps them apart rather than averaging them.


1. The short version

Which kind of mailbox you have decides what we hold.

A mailbox you already had — Outlook, Microsoft 365, Gmail, or any IMAP account. We do not receive your mail. The app connects your device directly to that provider. Your messages go between your device and them. They do not pass through us and we do not store them.

A DiscoverWorthy mailbox — an address on your domain that we host for you. We do receive your mail, because we are the mail server. It arrives at us, we store it, and your device fetches it from us. There is no way to host a mailbox without holding what arrives in it, and we would rather say so in the first paragraph than in a footnote.

You can tell which you have: if you set the mailbox up in your DiscoverWorthy dashboard and it gave you a password, it is a DiscoverWorthy mailbox. If you signed in with your own provider, it is not. The app also labels it.

There is one further exception for both kinds, described in section 6: if you connect a DiscoverWorthy business account, some features send us specific things - mostly when you press specific buttons, and in one case by itself: a short note of mail you send to your own customers. Connecting is off unless you switch it on.


2. What is kept on your device

DataWhy it is there
Your messages — headers, bodies and attachmentsSo mail can be read, searched and replied to without a connection
A full-text search indexSo search is instant rather than a round trip
Your folder list, tags, pins, snoozes and draftsThe state of your mailbox as you left it
Mail credentials — a password, an OAuth token, or a hosted mailbox passwordSo the app can reconnect without asking every time
The sorting model it learns from your taggingSo it can sort mail for you
Your app settingsWhich way a swipe goes, which colourway, and so on

How that is protected:

  • The device's storage is encrypted at rest by the operating system.
  • On Android, mail credentials are additionally sealed with an AES-256-GCM key generated inside the Android Keystore — on most phones, the secure element — so the key cannot be extracted even by code running as root. On Windows they are held in the operating system's credential store.
  • On iPhone, mail credentials are held in the iOS Keychain, marked for this device only. They are not included in iCloud or computer backups, so a phone restored from a backup has your mail but asks you to sign in to each mailbox again. That is deliberate: a backup is a copy of your phone that lives somewhere else.
  • Uninstalling the app removes all of it. Removing one mailbox removes that mailbox's mail.

The model is built on your device, from your own tagging, and is never uploaded. It is also kept separate per mailbox: what you teach a work mailbox does not change how a personal one behaves. This is true of a DiscoverWorthy mailbox too — we hold the messages, but what you have taught the app about them stays on your device.


3. A DiscoverWorthy mailbox

This section applies only if you asked us to host an address on your domain. If you signed in to an existing mailbox, none of it applies to you.

What we hold. Every message sent to that address: its content, its attachments, and the envelope it arrived with — who sent it, and who it was addressed to, including anyone blind-copied, because that is delivered separately from the message and cannot be recovered from it.

Where. In Australia, in Microsoft Azure, in storage that is not publicly readable. The message itself is kept as the exact bytes that arrived, so that it can be handed back to any mail program, including ours.

Who can read it. Your organisation, through the password the mailbox was given. Our staff can reach the underlying storage in the course of running the service — the same as any hosted system — and do so only where operating or supporting it requires. We do not read hosted mail to build profiles, to train models, or to sell anything, and we do not let anybody else read it.

How long. For as long as the mailbox exists. Deleting a mailbox removes its messages from our systems; closing your account removes all of them.

Getting it out. The messages are stored in the standard format every mail program reads, and can be exported. A mailbox you cannot leave with is not one worth having.

Spam and filtering. Mail sent to the address is checked as it arrives, so that obvious abuse does not reach you. The checks are automated and run on our own mail server, in Australia:

  • The internet address of the server delivering the message is looked up in Abusix's blocklist. Abusix learns that one address — the mail server's, never your device's — and nothing about the message: not who it is from, who it is for, or what it says.
  • The sender's domain is asked, through the ordinary public DNS, whether that server is allowed to send its mail. This is the standard check called SPF.
  • A sender we have not seen before, whose domain could not vouch for it, is asked to try again a couple of minutes later — real mail servers do, and most spam never comes back. To recognise it when it returns, our server remembers the sending network, the sender's address and your address, in memory only, for up to 36 days.

Our mail server also keeps a log of which servers connected to it and whether their mail was accepted. It is used to run and troubleshoot the service, and is deleted after 30 days.

Sending. A DiscoverWorthy mailbox receives. When you reply, the reply goes out through one of your other mailboxes, from that provider, and answers come back to your DiscoverWorthy address.


4. What the app connects to, and when

It connects toWhenWhat is sent
Your mail provider, over IMAP and SMTP with TLSContinuously, to fetch and send mailYour credentials, and the mail you send
Your provider's own sign-in pageOnly when you add a mailbox using one-tap sign-inThe sign-in happens on your provider's page. We never see the password
DiscoverWorthyOnly if you have a DiscoverWorthy mailbox, to fetch what arrived in itThe mailbox's password, and a push token so we can tell your device mail came
DiscoverWorthy's push relayOn a phone, for a Microsoft 365 or Outlook.com mailbox, so mail can arrive while the app is closedA push token. The app asks Microsoft to tell the relay when a message arrives in that mailbox; Microsoft sends the time and its own reference for the message, never who sent it, its subject or its content
Nothing else, by default——

Push tells your device that something arrived, and nothing more. The message we send through Google's and Apple's push services says which mailbox changed. On an iPhone it is a silent push, which shows nothing by itself. It does not carry a subject, a sender, a count, or any part of a message. Your device then fetches the mail itself and decides whether to show you anything.

The app has no analytics, no crash reporting and no advertising identifier. It does not report which features you use, whether you opened it, or that it was installed. We do not know how many people use it except as the numbers Google Play and the App Store show us.

Remote images do not load until you ask. The app strips the fetching attribute out of the message rather than relying on you not to tap it, which is what stops the tracking pixel in a newsletter telling the sender that you read it and roughly where you were.

Sender logos ship inside the app. They are not fetched per sender — not from us, and not from the sender's own domain. A mail app asking a server for a logo each time would be handing over the list of who emails you, and unlike a password vault, you did not choose your senders.

Link checking happens on the device. When the app warns you that a link does not go where it says, it worked that out from the address and the words in front of it. No reputation service is consulted, because consulting one would send the links in your mail to a third party.


5. What the app asks permission for

  • Internet — to reach your mail provider.
  • Notifications — to tell you mail arrived. Decline it and the app still works; you are simply not told.
  • Background work — so mail can arrive while the app is closed. On Android the app runs a short sync when a push says a mailbox changed, and about every fifteen minutes as a fallback, including after the phone restarts; it keeps nothing running in between. On iPhone, iOS wakes the app briefly for a silent push, and from time to time through Background App Refresh. You can turn Background App Refresh off in iOS Settings; mail then arrives when you open the app.

It does not ask for location, contacts, camera, microphone, or access to your files.


6. Connecting a DiscoverWorthy account (optional)

If you use DiscoverWorthy for your business, the app can connect to it so that mail from a customer shows what you already know about them. This is off until you turn it on, and it is turned on per installation. It is separate from having a DiscoverWorthy mailbox, and applies to every kind of mailbox.

Two different things happen, and the difference is deliberate:

Looking somebody up sends one email address — the sender's — to ask whether it belongs to a customer of yours. It happens by itself each time you open a message, so it is held to the strictest line: never a subject, never a body, never an attachment, never a list of who you have been talking to.

An action sends what that action needs, and only when you press its button - with one exception, described below the table:

ActionWhat it sends
Log an email to a contact's recordIts subject, its date, its Message-ID, and a few lines the app writes on your device from the opening of the message — never the message itself
Check an email against a signed quoteThe message, because that is the thing being read. There is no setting: it goes only when you press that button, about that one message
Ask for a first draft of a replyThe message, because that is the thing being replied to. Off until you turn it on
Sync your sender-icon library between your devicesA domain, and a picture of that company's logo. Never a message, a subject, or an address anybody has written to. Off until you turn it on

Mail you send logs itself. When you send an email, the app checks each recipient's address against your contacts, and logs the email - exactly as the Log button would - to the record of each one who is already a contact. Nobody new is added: an address that is not a contact is answered "not a contact" and nothing is kept. This is on by default when you connect, and you can switch it off in the app's Mailboxes settings.

A logged email is a short note, not a copy. The few lines on the record are picked by the app on your device - the opening of what was written, with the greeting, the signature and the earlier messages in the thread taken off. No AI and no other company is involved in writing them, and the message itself never leaves your device for this. The record's "Open in Mail" link uses the email's Message-ID to open it in the app, on a device where that mailbox is set up.

Where a feature sends a message to be read or answered by AI, that processing is covered by the AI provisions of our Privacy Policy. Nothing about your mail is sent for any other purpose, and nothing is sent to train anybody's model.


7. What we hold about you

For the app itself: nothing. There is no account, no profile, and no record that you installed it.

If you have a DiscoverWorthy mailbox, we hold what section 3 describes, and your organisation's record of that mailbox.

If you connect a DiscoverWorthy account, the requests above reach your own organisation's data, which our Privacy Policy already covers. Disconnecting the app stops it immediately.

Google Play and Apple's App Store hold whatever an app store holds about a download — see their own policies.


8. Children

The app is not directed at children and is rated for a general audience. What it shows you is your own mail.


9. Contact

Questions about this notice, or about what the app does with your mail:

Email: dpo@discoverworthy.com Address: 140 Keilor Road, ESSENDON NORTH, VIC 3041