Postroom

Legal

Privacy policy

This privacy policy applies to the Postroom app (hereby referred to as "Application") for iPhone, iPad and Mac, created by Supra Applications Inc (hereby referred to as "Service Provider") as a Commercial service. Postroom is an email app for Gmail, so most of what it handles is Google user data: this policy sets out exactly which Google user data it accesses, what it uses each part for, where that data goes, and what it deliberately does not do. The service is intended for use "AS IS".

Effective 18 August 2026

The short version

Postroom has no user accounts. There is no signup, no name, no password, and no profile. It reads the Gmail mailbox you sign it in to, and it keeps what it reads on your own devices.

Two parts of the Application are worth understanding separately, because they have different data footprints:

1. The app itself. Your mail is fetched from Google straight to your device and stays there. The sorting happens on your own devices. Nothing about your use is sent to the Service Provider.

2. Notifications (optional, off unless you turn them on). Getting an alert to your lock screen needs a small service run by the Service Provider, which reads the limited Google user data described below.

What Google user data the Application accesses

You grant access in Google's own sign-in screen, to your own device. The Application asks for one Gmail permission, and two sign-in permissions that carry no mailbox access:

Under those permissions, the Google user data the Application accesses is:

That is the whole list. The Application requests no access to Google Contacts, Google Calendar, Google Drive, Google Photos, or any other Google service, and holds no permission that would let it reach them.

How the Application uses Google user data

Every use, and the feature it exists for. Google user data is used only to provide and improve these user-facing features, and for nothing else:

Show you your mail
Message content and metadata are read so the Application can display your mailbox — senders, subjects, bodies, pictures and attachments. This is the part that makes it an email app rather than something else.
Sort your inbox
The text of a message is read to work out which bundle it belongs in, and to gather flights and hotels into Trips, parcels into Deliveries and invitations into Meetings. A booking confirmation looks like every other receipt from the outside, so the sorting has to read the message rather than just its headers. Where that reading happens is set out below.
Archive, pin, snooze and mark read
Label changes are written back to Gmail, so that Done, Sweep and Pin mean the same thing in every other mail app you use and on gmail.com. The only labels the Application writes are Gmail's own inbox, starred and unread, plus labels you ask for yourself. It never permanently deletes a message.
Send what you write
Your replies, forwards and new messages are sent through Gmail, and drafts are saved into Gmail so an unfinished message is there on your other devices. One-tap unsubscribe is sent the same way, as an ordinary message from you.
Show your labels
Your existing labels are listed so you can file with them, and one is created or renamed when you ask. The Application does not invent a label taxonomy of its own or reorganise your mailbox behind your back.
Say which account you are in
Your mailbox address and profile picture label the window, so that with more than one account signed in it is clear which mailbox you are reading and which address a reply will leave from.
Notify you of new mail
Only if you switch notifications on. A new message's sender, subject and one-line snippet become the text of the alert on your lock screen. Set out in full below.

The sorting

Sorting your mail into bundles requires a language model to read it. The Application gives you two ways to provide one, and both are yours:

Settings will accept the address of a hosted service as readily as one on your own network, and some people will want that. If you enter one, the mail sent for sorting is read by whoever runs that service, under their privacy policy and not this one. The Application says so on the screen where the address is typed. The Service Provider does not choose that destination, does not receive what is sent there, and cannot link it to anything here.

Notifications, if you switch them on

This is the one part of Postroom where Google user data is handled off your device. Gmail will not push to a phone directly, and Apple accepts pushes only from a service holding an Apple key, so a small service run by the Service Provider joins the two ends. To do that it holds, per mailbox:

When a new message arrives, the service reads that message's sender, subject and Gmail's one-line snippet, puts them in the alert, and sends it to Apple for delivery. It never reads the message body. Those contents are used for the alert and are not written down or stored afterwards. No other part of your mail is read, and none of it is used for any other purpose.

Leaving notifications off means none of this happens at all, and the Application works without them.

What the Application never does with Google user data

Limited Use

Postroom's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Where Google user data is stored

Mail is fetched from Google to your device and stored on your device, in the Application's own local database. The Service Provider does not receive a copy, does not hold your mailbox contents, and has no ability to read your mail. The one exception is the notification service described above, which reads a new message's sender, subject and snippet in order to send the alert and does not store them.

The permission you grant is stored in your device's own keychain, where other apps cannot reach it. The single copy that leaves the device is the refresh token held by the notification service, and only if you switch notifications on.

What you have done with a message

Whether a conversation is done, snoozed or pinned is information the Application creates, rather than Google user data. It lives on your device, and if you use more than one device it is passed between them through your own iCloud account, which the Service Provider cannot see into. What travels is that app-owned state and facts derived from your mail — which bundle a conversation is in, a trip's dates and cities. Message bodies, subjects and headers are not synced.

Does the Application collect precise real time location information of the device?

No. The Application does not collect the location of your device. Trips name cities because your own booking confirmations name them, which is information you were sent by mail and not a measurement of where you are.

Is there any analytics, advertising or tracking?

No. There is no analytics, no third-party crash reporting, no advertising, and no advertising identifier. Nothing in the Application identifies you across other apps or websites, and nothing about how you use it is reported to the Service Provider.

Do third parties see and/or have access to information obtained by the Application?

The Service Provider does not sell your information to anyone, and does not share it except as needed to run the parts described above. Those parts involve:

Google user data is not transferred to anyone else, and none of these is permitted to use it for their own purposes.

Data retention and deletion

Mail stored on your device is removed when you remove the mailbox from the Application or delete the Application.

The notification service holds a mailbox address, its registered devices and its refresh token only for as long as notifications are switched on. Turn them off, remove the mailbox, or delete the Application, and the record is discarded.

You may also revoke the Application's access to your Google account at any time from myaccount.google.com/permissions, which stops all of it regardless of what the Application does.

To ask for the deletion of anything held for you, email support@travelersvpn.com.

What are my opt-out rights?

You can stop all information handling by deleting the Application. You can stop the only part that collects by leaving notifications switched off, or switching them off later. Neither prevents you from using the rest of the Application.

Children

The Application is not used to knowingly solicit data from or market to children under the age of 13.

The Service Provider does not knowingly collect personally identifiable information from children. The Service Provider encourages all children to never submit any personally identifiable information through the Application and/or Services. The Service Provider encourages parents and legal guardians to monitor their children's Internet usage and to help enforce this Policy by instructing their children never to provide personally identifiable information through the Application and/or Services without their permission. If you have reason to believe that a child has provided personally identifiable information to the Service Provider through the Application and/or Services, please contact the Service Provider (support@travelersvpn.com) so that they will be able to take the necessary actions. You must also be at least 16 years of age to consent to the processing of your personally identifiable information in your country (in some countries we may allow your parent or guardian to do so on your behalf).

Security

The Service Provider is concerned about safeguarding the confidentiality of your information and takes reasonable measures to protect the limited information described above. Mail on your device is protected by the device's own encryption, traffic to Google and to the notification service is encrypted in transit, and the permission the notification service holds is kept where only that service can reach it. No method of transmission over the internet or method of electronic storage is completely secure, however, so the Service Provider cannot guarantee absolute security.

Changes

This Privacy Policy may be updated from time to time for any reason. The Service Provider will notify you of any changes to their Privacy Policy by updating this page with the new Privacy Policy. You are advised to consult this Privacy Policy regularly for any changes, as continued use is deemed approval of all changes.

This privacy policy is effective as of 2026-08-18.

Your Consent

By using the Application, you are consenting to the processing of your information as set forth in this Privacy Policy now and as amended by the Service Provider.

Contact Us

If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at support@travelersvpn.com.