Last updated: July 22, 2026
mesSage is a desktop email client developed by DuWayne Caviness. This policy explains exactly what data the app accesses, how it is used, how it is protected, and how it is deleted.
All data — including email credentials, OAuth tokens, email content, and settings — is stored locally on your device. mesSage does not operate any servers and does not transmit your data to the developer or any third party, except as explicitly described in this policy.
mesSage connects to your Gmail account using Google's OAuth 2.0 authorization. The app requests the following scopes:
The specific Gmail data accessed includes: email messages and threads (subject, sender, recipients, body, attachments), email metadata (read/unread status, labels, flags), Gmail labels and filters, and your primary Gmail address.
Gmail data is used solely to provide the core functionality of the mesSage email client: displaying, composing, sending, searching, organizing, and managing your email directly within the app on your device. No Gmail data is used for advertising, analytics, profiling, or any purpose unrelated to email management.
Gmail data is not sold, shared, or transferred to any third party except in the following limited cases:
No Gmail data is transferred to data brokers, advertisers, analytics providers, or any other third party.
Your Gmail data is protected as follows:
Gmail data is retained locally on your device for as long as your account is connected in mesSage. Specifically:
mesSage does not retain any copies of your Gmail data on any server. There is no server-side data to request deletion of.
mesSage connects to Outlook and Hotmail accounts via Microsoft's OAuth 2.0 authorization and the Microsoft Graph API. Email data is fetched directly from Microsoft's servers to your device. The same access, use, protection, and deletion principles described above for Gmail apply equally to Outlook data. No Outlook data is stored or transmitted elsewhere by the developer.
For accounts connected via IMAP/SMTP (Yahoo Mail, Fastmail, iCloud, and others), your email address and app password are stored locally in your device's secure credential storage (Windows Credential Manager). Email content is fetched directly from the provider's servers to your device and is not transmitted to the developer.
mesSage includes an optional AI assistant. AI features are entirely opt-in and require you to configure your own API key or local model. Two options are available:
AI training restriction: mesSage does not use your email data, or any Google user data, to train, improve, or develop any AI or machine learning model. When email content is sent to Anthropic's API via the Claude integration, it is used solely to generate a response to your request and is subject to Anthropic's API data handling policies, which prohibit using API inputs to train their models without consent.
Google API Limited Use Compliance Statement: mesSage's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Raw or derived user data received from Google Workspace APIs is not used to develop, improve, or train AI or machine learning models, and is not transferred to any third-party service for the purpose of AI or machine learning model training.
mesSage may cache email metadata and message content in a local SQLite database on your device to enable offline access and faster loading. This cache is stored in your device's app data directory, is not accessible to the developer, and is deleted when you sign out or uninstall the app.
mesSage does not collect analytics, telemetry, crash reports, or any usage data. It contains no advertising. The developer has no visibility into how you use the app.
mesSage checks GitHub Releases for software updates. This request includes your IP address as part of the standard HTTPS connection, but no personal data is sent. Update packages are cryptographically signed and verified before installation.
mesSage is not directed at children under 13. We do not knowingly collect data from children.
If this policy changes materially, the updated version will be posted at this URL with a new "Last updated" date.
Questions? Contact: admin@cavinessproducts.com