Mach by Ahmed Khaleel

Privacy policy

Mach, the mail app for Gmail on Mac and iPhone · Ahmed Khaleel · Effective 9 October 2026

Mach runs on your Mac or iPhone and talks to Google directly from there. Your mail, your contacts' pictures and your Google sign-in are kept on your device. The developer runs no server that receives any of it, and cannot see it.

01Who is responsible

Mach is made and published by Ahmed Khaleel, an individual developer based in Ontario, Canada. Questions about this policy go to ahmed@gitdiagram.com.

This policy covers the Mach apps for Mac and iPhone as the developer publishes them (the downloads on GitHub, and the TestFlight and App Store builds when they exist) and this website. Mach's source is open; a copy that someone else has changed and built is theirs to answer for.

02Google data Mach uses, and why

When you sign in with Google, Mach asks for four permissions. These are all of them, and each is used only for the feature beside it.

Read, compose and send your Gmailgmail.modify
What Mach reads: your Gmail address, your messages and conversations with their attachments, labels and drafts, your send-as names and signatures, and Gmail's record of what changed since the last check.
What Mach changes, when you do it: it sends mail and saves drafts, and it archives, trashes, stars, marks read or unread and snoozes conversations by changing their labels (snoozing adds a hidden label of Mach's own to your Gmail).
Why: this is the mail app itself. This permission does not let an app delete mail for good past the Trash.
See your contactscontacts.readonly
What Mach reads: two things about each contact, their email addresses and the address of their picture. No names, phone numbers, postal addresses or notes.
Why: to show a sender's face beside their mail, in lists, conversations and notifications.
See your "Other contacts"contacts.other.readonly
What Mach reads: the same two things, for people you have written with whom Google saved automatically.
Why: the same pictures. Most of the people who write to you are here, not in your contacts.
See your basic profileuserinfo.profile
What Mach reads: your own profile picture.
Why: to show it beside your own messages.

Mach never changes your contacts or your Google profile. You can turn pictures off in Mach's settings ("Profile pictures"); the mail app works the same without them.

03Where it is kept, and for how long

On your device, and nowhere else.

Your mail
A database in the app's own data folder (on a Mac, ~/Library/Application Support/Mach). It holds what Mach has fetched so that reading and search are instant and work offline.
Your Google sign-in
The tokens Google issues are kept in the system keychain of the device, one entry per account. Mach does not mark them for iCloud Keychain syncing. Mach never sees or stores your Google password: you type it on Google's own page.
Contact pictures
The list of email address to picture address, per account, in the same data folder, refreshed about once a day. The pictures themselves, and company logos, in the app's cache folder.
Attachments
The ones Mach has shown you a preview of, or that you opened, are downloaded once and kept in the app's cache folder.
Settings
Your choices in the app (theme, text size, swipes and so on) in the app's preferences.

It stays until you sign out of the account or delete the app; see Removing your data. Mach adds no time limit of its own, because it is your own copy of your own mailbox.

If you back up your device (Time Machine, iCloud Backup, a backup to a computer), your backup may include Mach's data like any other app's. That is between you and Apple; Mach does not send it anywhere.

04What leaves your device, and to whom

The developer receives nothing. These are all the places the app connects to.

Google
Sign-in, Gmail and contacts, over HTTPS, directly from your device, under your own account. Everything you do in Mach (sending, archiving, searching the whole mailbox) is a request to Gmail. Contact pictures are downloaded from the addresses Google gives.
Company logos
When a sender has no Google picture, Mach looks for the company's certified logo the way Gmail does (the BIMI standard). It asks Google's public DNS service for a record on the sender's domain, and downloads the logo certificate from wherever that record points, usually the company's or its certificate authority's server. These requests carry no sign-in and no part of your mail, but they do show the sender's domain to Google's DNS service and your IP address to the certificate's host. Turning off "Profile pictures" stops them.
Senders of your mail
Pictures, fonts and styling inside an email load from the sender's servers when you open it, as in most mail apps. That can tell a sender that you opened their message, roughly when, and your IP address. Mach has no switch to stop this yet. The system web view that draws the email keeps its own cache of what it loaded, and any cookies those servers set, on your device. Scripts in mail never run, and forms in mail cannot send.
Links you click
Open in your browser, outside Mach.
GitHub (Mac only)
The Mac app checks GitHub about once an hour for a new version and downloads it from there. It is a plain file download; GitHub sees your IP address as it would for any download. Nothing about you or your mail is sent.
Apple
On iPhone you get the app and its updates through Apple. In the published app, new-mail banners are made on the phone itself, so no mail passes through Apple's notification service.

05What Mach never does

  • No server of the developer's receives, stores or processes your mail, your contacts or your sign-in.
  • No analytics, no usage tracking, no crash reporting service, no advertising, no third-party SDKs that collect data.
  • Your data is not sold, rented, shared or transferred to anyone.
  • Your Google data is not used to develop, improve or train AI or machine-learning models. Mach has no AI features.
  • No person reads your mail. The developer has no access to it.
  • There is no Mach account. You only ever sign in to Google.

06Google API Services: Limited Use

Mach's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, and as described above:

  • Mach uses Google user data only to provide the mail features you see in the app.
  • Mach does not transfer Google user data to anyone. It stays on your device.
  • Mach does not use Google user data for advertising of any kind.
  • No human reads Google user data. The developer cannot reach it.
  • Mach does not use Google user data to train generalized or any other AI or machine-learning models.

The use of information received from Google Workspace APIs will likewise adhere to the Google Workspace API user data and developer policy, including its Limited Use requirements.

07The optional push relay: off, and not the developer's

Mach's source includes a small program, the relay, that makes notifications arrive the instant mail does. It is not part of the published apps. The developer does not run one for the public, and the apps you download are not set up to use one. Without it the app checks for mail itself.

You can run a relay yourself, on your own Cloudflare account, and point your own copy of Mach at it by adding a settings file. If you do, your device sends your relay your Gmail address, your Google sign-in token, the Google key your copy of Mach uses, and your iPhone's notification address; the relay then reads the sender, subject and first words of new mail, and your contacts' picture addresses, and sends notifications through Apple's notification service. All of that is on a server you own and control. The developer has no access to it.

08Security

  • Mach's own connections, to Google and to GitHub, use HTTPS. A picture inside an old email can still load over plain HTTP if its sender wrote it that way.
  • Sign-in happens on Google's own page, in your browser on a Mac and in the system sign-in sheet on iPhone, using PKCE. Mach never handles your password.
  • Sign-in tokens are in the system keychain. The mail database is protected by the device itself: your passcode and Apple's file encryption on iPhone, your login and FileVault (if you have it on) on a Mac. Mach adds no encryption of its own on top.
  • An open email is shown under a policy that runs no scripts from mail.
  • The source is public, so every claim here can be checked: github.com/ahmedkhaleel2004/mach.

If you find a security problem, please email ahmed@gitdiagram.com before making it public.

09Removing your data and Mach's access

  • Sign out. In Mach's settings, "Sign out" beside an account deletes that account's mail from Mach's database and its sign-in from the keychain.
  • Take away Mach's access at Google. Open myaccount.google.com/permissions, choose Mach and remove its access. From then on the sign-in on any device is worthless.
  • Delete the app. On iPhone, deleting Mach removes everything it stored. On a Mac, sign out first, move Mach to the Trash, and to clear what is left delete ~/Library/Application Support/Mach, the avatars4, attachments and com.ahmedkhaleel.mach.mac folders in ~/Library/Caches, and the items named com.ahmedkhaleel.mach.mac in ~/Library/WebKit, ~/Library/HTTPStorages and ~/Library/Preferences.

None of this touches your mail at Google: it is all still in Gmail. Because the developer holds none of your data, there is nothing for him to look up, correct or delete on request, but you are welcome to ask. If you are in Canada and are unhappy with an answer, you can also contact the Office of the Privacy Commissioner of Canada.

10Children

Mach is not directed to children under 13, and the developer does not knowingly collect personal information from anyone, of any age. To use Mach you need a Google account, which has Google's own age requirements.

11This website

mach.ahmedkhaleel.com is a few static pages. It sets no cookies and has no analytics, trackers, advertising, external fonts or third-party scripts. It is hosted on Cloudflare, which, like any web host, handles your IP address and the page you asked for in order to deliver it and keep the service secure. If you email the developer, he will have your address and what you wrote, and uses them only to answer you.

12Changes to this policy

If this policy changes, the new version is posted here with a new date, and the history of this page is public in Mach's source repository. If Mach ever changes how it uses Google user data, you will be told in the app and asked to agree before the change applies to you.

13Contact

Ahmed Khaleel, Ontario, Canada · ahmed@gitdiagram.com