Privacy Policy
Last Updated: August 30, 2026
ZNOWSOFT, LLC ("we," "us," or "our") operates the ZenStork desktop email client application ("App"). This Privacy Policy outlines our policies regarding the collection, use, and disclosure of information when you use our App.
1. Information We Collect
We are committed to user privacy and minimizing data collection. The information we collect depends on how you use the App.
a. Local-Only Use (Without a ZenCloud Account):
If you use the App without creating a ZenCloud account, all of your data, including email account credentials, email content, and application settings, is stored exclusively on your local device. The App contains no analytics SDK, advertising tracker, behavioral telemetry, or crash reporter. We do not collect, transmit, or have access to this information.
b. ZenStork Account Sync (Optional):
If you create a ZenStork account, we collect only what is needed to authenticate you, enforce the device policy, and carry your encrypted configuration:
- Account Information: Your email address and a hashed version of your password.
- Encrypted Configuration: Your clients encrypt one canonical configuration snapshot before upload. Our servers store the ciphertext and cannot read its contents. When decrypted by your client, it includes:
- IMAP/SMTP server details.
- Encrypted authentication credentials (passwords or OAuth tokens).
- UI preferences (e.g., theme, pane widths).
- Signature and trusted sender configurations.
- Sender-priority rules, reusable snippets, and other application preferences.
- Device Registry: A device identifier, display name, platform, app version, sync state, and recent connection times. Free accounts may have two active sync devices; Premium accounts may have unlimited active devices.
- Subscription Status: The applicable ZenStork tier and billing status supplied by ZnowSoft. Payment-card details are handled by the payment provider and are not stored by ZenStork.
- Minimal Service Events: When you use the optional account, sync, or billing services, our servers record a small set of account lifecycle events associated with your account email. These events cover account creation, billing actions, first device registration, successful encrypted-configuration syncs, and subscription-state changes. They never include mailbox content, message metadata, contacts, credentials, device names, filenames, or the encrypted configuration itself.
IMPORTANT: We NEVER store, process, transmit, or have access to the content of your emails (headers, body, or attachments). All email content is handled directly between the App on your device and your email provider's servers.
c. Application Updates:
- Update Checks: The App may contact our servers to check for available updates. This request may include your current App version and operating system type to provide the correct update package. This data is not linked to your personal identity.
2. Google API Services User Data Policy Disclosure
ZenStork's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This section provides transparency on how ZenStork accesses, uses, stores, and shares Google user data when you connect your Google Account (e.g., Gmail) to the App.
a. Data Accessed
To provide its email client functionality, ZenStork requests access to the following types of Google user data:
- Basic Profile Information: We access your name and email address (via
userinfo.emailanduserinfo.profilescopes) to display your account information within the App. - Email Data: We access your email messages, including headers, body, and attachments (via the
gmail.modifyscope), to allow you to read, write, send, search, and manage your emails.
b. Data Usage
The Google user data accessed by ZenStork is used exclusively to provide and improve the core user-facing features of the email client. This includes:
- Fetching, displaying, and caching your emails for online and offline access.
- Allowing you to compose, send, reply to, forward, and delete emails.
- Searching through your email content locally on your device.
- Organizing emails with labels, folders, or other management features.
We do not use your Google user data, especially the content of your emails, for any other purpose, such as advertising, marketing, or data analysis. ZenStork does not send your inbox to AI services and does not train machine learning models on your email data. Access is limited to providing the direct functionality of the email client as described.
c. Data Sharing
We do not share any of your Google user data with any third parties. All email data is processed directly between the ZenStork App on your device and Google's servers. Our optional ZenCloud Sync service is used only for application settings and does not access, store, or transmit your email content.
d. Data Storage & Protection
ZenStork is a local-first application. Your Google user data is stored securely on your local device as follows:
- Authentication Tokens: OAuth2 tokens, which grant the App access to your Google Account, are stored encrypted in your operating system's secure credential storage (for example, Windows Credential Manager).
- Email Content: Your emails and attachments are cached on your local device's file system to provide fast access and offline functionality. This local cache is protected by your operating system's standard file permissions.
All communication between the ZenStork App and Google's servers is encrypted in transit using Transport Layer Security (TLS). We do not store any of your Google email data on our own servers.
e. Data Retention & Deletion
You have full control over your Google user data within ZenStork.
- Data Retention: Data is retained on your local device as long as you keep your Google account connected to the App.
- Data Deletion: You can delete your Google user data from the App at any time by removing your Google account from the ZenStork settings. This action will permanently delete all associated locally cached emails, attachments, and authentication tokens from your device.
- Revoking Access: You can also revoke ZenStork's access to your Google Account at any time from your Google Account permissions page. This will prevent the App from accessing any further data.
For any questions or requests regarding your data, you can contact us at privacy@zenstork.app.
3. How We Use Your Information
- To Provide and Maintain the App: To allow the App to function on your device.
- To Provide the Sync Service: To back up and synchronize your settings across your devices if you opt-in.
- To Provide Updates: To notify you of and deliver application updates.
- To Communicate With You: We may use your email address (if you create a ZenCloud account) to send you important information about your account or the service, such as security notices or updates to our policies.
- To Operate Optional Services: We use bounded server-side lifecycle events to diagnose checkout and sync reliability and to understand adoption of account features. We do not build advertising profiles, track browsing behavior, or analyze mailbox activity.
4. Data Security
We implement robust security measures to protect your information. Your ZenCloud account password is a one-way hash, meaning we cannot read it. Synced configuration is encrypted by your client before transmission and additionally protected in transit using TLS. The server stores only the encrypted snapshot, its integrity hash, revision metadata, and the device registry needed to coordinate sync.
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may disclose your information only in the following situations:
- With Service Providers: We may employ third-party companies (e.g., hosting providers) to facilitate our service. These third parties have access to your information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
- To Comply with Laws: We will disclose your information where required to do so by law or subpoena or if we believe that such action is necessary to comply with the law and the reasonable requests of law enforcement or to protect the security or integrity of our service.
6. Your Data Rights
You have the right to access, update, or delete the information we have on you. If you have a ZenCloud account, you can manage your settings and delete your account from within the App. Deleting your ZenCloud account will permanently remove your synced settings from our servers.
7. Children's Privacy
Our service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us.
8. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy within the App and updating the "Last Updated" date at the top of this policy.
9. Contact Us
If you have any questions about this Privacy Policy, please contact us at privacy@zenstork.app.