QuickMail for iPhone

Privacy Policy

QuickMail is built to know as little about you as possible. This policy explains what the app stores on your device, what it sends over the network, and what Quivren can and cannot see.

Summary

  • We do not collect, transmit, or sell any of your personal data.
  • The app contains no advertising, analytics, or tracking.
  • Your mail lives on the QuickMail server you deploy and control.
  • Quivren has no access to your server, mailbox, or pairing credential.

Who this policy covers

This policy covers the QuickMail app for iPhone, published by Quivren. It does not cover the self-hosted QuickMail server you connect to, the email providers that deliver your mail on your behalf (such as Resend or Cloudflare Email Service), or websites you visit through links in messages.

What is stored on your device

  • Pairing credential. After you pair with your server, a bearer session token is stored in the iOS Keychain. It is marked so it never leaves that specific device and is removed when you sign out, revoke the device from your server's settings, or wipe local data.
  • Offline cache. A small local cache of your most recent inbox page lets you read saved mail without a network. The cache does not contain your session credential and is keyed by hashed account identifiers. You can clear it at any time from the app.
  • Preferences. Choices such as appearance, selected sending address, App Lock, and remote-image loading are stored in standard iOS app preferences on your device only.

What the app sends over the network

The app talks directly to the QuickMail server origin you chose during pairing, over HTTPS. Requests contain your session token and the mailbox actions you perform: reading threads, searching, sending mail, managing attachments, and updating settings. The app connects to no Quivren-operated endpoint, relay, or telemetry service.

Remote images inside email HTML are blocked by default and load only after an explicit per-message choice or privacy preference. When they load, requests go from your device to the sender's image host; the hardened message viewer disables JavaScript, cookies, forms, frames, navigation, and link previews.

What Quivren can see

Nothing about your usage. Because the app connects only to servers its users deploy themselves, there is no Quivren-hosted mailbox, no central log of activity, and no mechanism for us to read your mail, your contacts, or your attachments. If you email quickmail-support@quivren.com, we use your message only to help you and delete it once resolved.

Device permissions

  • Camera: used only to scan a QR pairing code. Pairing by manual entry is always available instead.
  • Face ID / Touch ID: used only if you enable App Lock. Authentication happens entirely on-device via Apple's LocalAuthentication framework.

Children

QuickMail is a general-purpose mail client intended for people who operate their own mail infrastructure. We do not knowingly collect data from children, and we could not even if we wanted to, because no data reaches us.

Changes to this policy

If the app ever adds a feature that changes how data is handled, we will update this policy before that version ships and note the change here. The current policy applies to all versions of QuickMail for iOS released as of August 24, 2026.

Contact

Questions about this policy can be sent to quickmail-support@quivren.com or raised publicly on the project's GitHub issue tracker.