Sia Makerlab
홈회사소개서비스포트폴리오공지사항문의하기

© since 2025 Sia Makerlab. All rights reserved.

사업자등록번호: 649-11-03282 | 대표: 이장욱

통신판매업신고번호: 제2025-충북제천-0264호

Sia E-Mail Client

개인정보처리방침

Sia Makerlab 제품 포트폴리오 통합 페이지에서 제공하는 개인정보처리방침입니다.

개인정보처리방침v1.0

Privacy Policy

Last Updated: July 11, 2026

Effective Date: July 11, 2026

Revision: 1.0

Revision History

VersionDateChanges
1.0July 11, 2026Initial release

1. Introduction

This Privacy Policy describes how Sia Makerlab ("we," "us," or "our") collects, uses, and shares information in connection with your use of the Sia E-Mail Client mobile application (the "App").

The App is an Android email client that connects to the mail accounts you configure using open standards — IMAP/SMTP, JMAP (RFC 8620/8621), and OAuth2. It communicates directly from your device to your own mail servers and OAuth providers. It does not require you to create an account with us, and we do not operate a server that stores your accounts, your credentials, or your email. By downloading, installing, or using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.

2. Information We Collect

2.1 Information You Provide

The App is designed to function without an account with us or personal information given to us. We do not collect your name, email address, phone number, or physical address.

To connect a mailbox, you provide its details — either through a provider preset with OAuth2 sign-in, or by entering IMAP/SMTP server settings and credentials manually. You may also import OpenPGP or S/MIME keys and certificates. This configuration is stored locally on your device and is not collected by us.

2.2 Email You Sync (Direct Device-to-Server Connections)

When you open a mailbox, the App communicates directly from your device to the mail servers and OAuth providers you specified using IMAP/SMTP, JMAP, and OAuth2. Your messages, folders, attachments, and account credentials travel between your device and those servers — not through any Sia Makerlab server. We do not see, receive, store, or read your email, your credentials, or your OAuth tokens. You are responsible for ensuring you are authorized to access any account you connect to.

2.3 Information Stored on Your Device

The App stores the following data only on your device:

DataCollectedStoredSharedPurpose
Account settingsYesDevice onlyNoProvider, server (IMAP/SMTP/JMAP), and sync options for accounts you configure
Credentials & OAuth tokensYesDevice only (encrypted)NoPasswords and OAuth2 access/refresh tokens encrypted with Android Keystore (AES-256-GCM)
Message cacheYesDevice onlyNoMessages, folders, and attachments cached locally in Room for offline reading and search
Encryption keysYesDevice onlyNoOpenPGP keys and S/MIME certificates you import for end-to-end encryption
App settingsYesDevice onlyNoTheme, language, biometric/PIN app lock, swipe actions, and other preferences
Purchase stateYesDevice onlyNoCached "remove ads" entitlement (reconciled with Google Play)

This data is stored exclusively on your device. We do not have access to it, and it is never transmitted to our servers.

2.4 On-Device Processing

Certain intelligent features run entirely on your device with no network calls, and their results are never sent to us or to any third party:

  • AI email summarization produces short summaries of messages locally.
  • Smart category classification (newsletters, promotions, social, notifications) is performed on-device.
  • Spam/phishing heuristics analyze messages locally to warn about sender spoofing and link-domain mismatches.

2.5 OAuth2 Authorization

For providers such as Outlook, Microsoft 365, and Gmail, the App uses OAuth2 (Authorization Code flow with PKCE via Custom Tabs) and connects to your mailbox using XOAUTH2. Sign-in happens between you and your provider; the App receives access and refresh tokens which are stored encrypted on your device and used only to send and retrieve your mail on your behalf, with automatic refresh-token renewal. We never receive these tokens. The scopes you grant authorize mail access only; you can revoke access at any time in your provider's account settings.

2.6 End-to-End Encryption (User-Controlled)

OpenPGP and S/MIME encryption are optional and controlled entirely by you. Keys and certificates you import remain on your device, and any encryption, decryption, or signing is performed locally. We are not a key server and do not have access to your keys or your decrypted message content.

2.7 Biometric / PIN App Lock

If you enable the biometric or PIN app lock, authentication is performed by the Android operating system on your device. The App never receives, stores, or transmits your fingerprint or other biometric data.

2.8 Permissions

  • Internet (INTERNET): required to connect to the mail servers and OAuth providers you configure and to serve ads.
  • Network state (ACCESS_NETWORK_STATE): used to detect network availability for syncing.
  • Notifications (POST_NOTIFICATIONS): used to display local new-mail notifications. New-mail alerts are generated on your device from background mail synchronization — there is no push server and no Firebase Cloud Messaging (FCM).

The App does not request location, camera, microphone, or contacts permissions.

2.9 Advertising Data (Third-Party)

Monetization is configured by the operator at deployment; where it is enabled and unless you purchase the ad-removal option, the App displays advertising through Google AdMob (banner, App Open, and native formats). Our advertising partner may collect:

  • Advertising ID (Android Advertising ID)
  • Device information (device type, operating system version)
  • IP address
  • General location data (country/region level)
  • Ad interaction data

Where required, the App uses Google's User Messaging Platform (UMP) to obtain your consent for personalized advertising. This data collection is governed by Google's Privacy Policy: https://policies.google.com/privacy

2.10 Information We Do NOT Collect

We explicitly do not collect:

  • Personal or contact information
  • Your email, attachments, mail accounts, credentials, or OAuth tokens
  • Your encryption keys or decrypted message content
  • Analytics or usage tracking data by us directly
  • Precise location data
  • Payment or card information (handled by Google Play)

3. How We Use Information

3.1 Local Data Usage

Data stored on your device is used locally to:

  • Establish the connections you configure and sync your mail with your servers and providers
  • Cache messages and attachments for offline reading and search
  • Run on-device summarization, category classification, and phishing heuristics
  • Apply your settings, app lock, and preferences
  • Apply your ad-removal entitlement

3.2 Third-Party Data Usage

Data collected by Google AdMob and Google UMP is used to display personalized or non-personalized advertisements (based on your consent) and to prevent fraud and abuse. Data collected by Google Play Billing is used to process and reconcile your purchase.

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data

We do not sell, trade, or rent your personal information to third parties.

4.2 Third-Party Service Providers

The App integrates the following third-party services, which handle data according to their own privacy policies:

ServicePurposePrivacy Policy
Google AdMobAdvertisinghttps://policies.google.com/privacy
Google User Messaging Platform (UMP)Ad consent managementhttps://policies.google.com/privacy
Google Play BillingProcess the one-time ad-removal purchasehttps://policies.google.com/privacy

Separately, the App communicates directly with the mail servers and OAuth providers you specify (such as Gmail, Outlook, Microsoft 365, Yahoo, iCloud, Naver, and Daum/Kakao). Those services are operated by you or by parties you choose, and their handling of your accounts, mail, and credentials is governed by their own terms and privacy policies and is outside our control.

4.3 Legal Requirements

We may disclose information if required to do so by law or in response to valid requests by public authorities. As we hold no user content, such disclosure would be limited to information actually in our possession.

5. Data Retention

5.1 Local Data

Data stored on your device — including cached messages, account settings, and encrypted credentials — remains until you remove the account within the App, clear app data in device settings, or uninstall the App.

5.2 Third-Party Data

Data collected by Google's advertising, consent, and billing services is retained according to their respective policies. Mail stored on your providers' servers is retained according to those providers' policies.

6. Your Rights and Choices

6.1 For All Users

You have the right to:

  • Access: View your data within the App
  • Delete: Remove accounts in the App, or clear app data or uninstall the App to remove all local data
  • Revoke access: Revoke the App's OAuth2 access at any time from your provider's account settings
  • Opt out of personalized ads: Manage ad personalization through your device's advertising settings or the UMP consent options

6.2 For Users in the EEA, United Kingdom, and Switzerland

Under the GDPR and applicable laws, you also have the rights to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. To exercise rights over data held by a third-party service or mail provider, contact that service directly.

6.3 Managing Consent

Manage advertising consent through:

  • In-App: privacy/consent options provided via Google UMP
  • Device Settings: Android Settings > Google > Ads

7. Data Security

We implement reasonable technical measures to protect data on your device:

  • Credentials and OAuth tokens are encrypted with Android Keystore (AES-256-GCM)
  • OAuth2 uses the Authorization Code flow with PKCE; plaintext connections are rejected and TLS is enforced
  • Optional biometric/PIN app lock, and OpenPGP/S/MIME end-to-end encryption under your control
  • Data is stored only on your device; we operate no server and keep no copies of your mail
  • No cloud synchronization through us and no user accounts with us
  • Network access is used only to reach the mail servers and OAuth providers you configure and to serve third-party advertising

8. Children's Privacy

The App is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children.

9. International Data Transfers

Data collected by third-party services may be transferred to and processed in countries with different data protection laws. Please refer to Google's Privacy Policy for more information.

10. Trademarks and Non-Affiliation

Gmail, Google, and AdMob are trademarks of Google LLC; Outlook, Hotmail, Live, and Microsoft 365 are trademarks of Microsoft Corporation; Yahoo is a trademark of Yahoo Inc.; iCloud is a trademark of Apple Inc.; Naver is a trademark of Naver Corporation; and Daum and Kakao are trademarks of Kakao Corporation. All other product names and logos are the property of their respective owners. Sia E-Mail Client is an independent email client and is not endorsed by, sponsored by, or affiliated with any of these providers. These names are used solely to identify the mail services with which the App is compatible.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date and, for material changes, displaying a notice within the App.

12. Disclaimer of Liability

12.1 Third-Party Services

We are not responsible for the data collection, use, or security practices of third-party services integrated into the App, including Google AdMob, Google UMP, and Google Play Billing, nor for the mail servers and OAuth providers you choose to connect to.

12.2 Data Loss

We are not responsible for any loss of data stored locally on your device, including cached messages, account settings, and imported keys.

12.3 Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES RESULTING FROM YOUR USE OF THE APP.

13. Governing Law

This Privacy Policy shall be governed by the laws of the Republic of Korea. For EU users, it shall be interpreted in accordance with applicable EU law including the GDPR.

14. Contact Us

Sia Makerlab

  • Email: sia@siamakerlab.com
  • Website: https://siamakerlab.com

For GDPR-related inquiries from EEA residents, please include "GDPR Request" in the subject line.


Summary of Data Practices

Data TypeCollectedStoredSharedPurpose
Account settingsYesDevice onlyNoConnecting to your mail servers and providers
Credentials & OAuth tokensYesDevice only (encrypted)NoAuthenticating to your mailboxes
Email, attachments & foldersNo (synced device ↔ your servers)Cached on device onlyOnly with servers/providers you specifyReading and sending your mail
On-device summaries & phishing checksNoNot retained by usNoLocal processing only
Encryption keysNoDevice onlyNoOpenPGP/S-MIME under your control
Purchase stateYesDevice onlyNoAd-removal entitlement
Advertising IDYes*By GoogleWith GoogleAdvertising
Personal infoNoN/ANoN/A

*Collected by third-party services (Google), not by us directly.


This Privacy Policy is available in English. If translated versions are provided, the English version shall prevail in case of any discrepancy.

Sia E-Mail Client 제품 페이지로 돌아가기