Sia E-Mail Client
Sia Makerlab 제품 포트폴리오 통합 페이지에서 제공하는 개인정보처리방침입니다.
Last Updated: July 11, 2026
Effective Date: July 11, 2026
Revision: 1.0
| Version | Date | Changes |
|---|---|---|
| 1.0 | July 11, 2026 | Initial release |
This Privacy Policy describes how Sia Makerlab ("we," "us," or "our") collects, uses, and shares information in connection with your use of the Sia E-Mail Client mobile application (the "App").
The App is an Android email client that connects to the mail accounts you configure using open standards — IMAP/SMTP, JMAP (RFC 8620/8621), and OAuth2. It communicates directly from your device to your own mail servers and OAuth providers. It does not require you to create an account with us, and we do not operate a server that stores your accounts, your credentials, or your email. By downloading, installing, or using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.
The App is designed to function without an account with us or personal information given to us. We do not collect your name, email address, phone number, or physical address.
To connect a mailbox, you provide its details — either through a provider preset with OAuth2 sign-in, or by entering IMAP/SMTP server settings and credentials manually. You may also import OpenPGP or S/MIME keys and certificates. This configuration is stored locally on your device and is not collected by us.
When you open a mailbox, the App communicates directly from your device to the mail servers and OAuth providers you specified using IMAP/SMTP, JMAP, and OAuth2. Your messages, folders, attachments, and account credentials travel between your device and those servers — not through any Sia Makerlab server. We do not see, receive, store, or read your email, your credentials, or your OAuth tokens. You are responsible for ensuring you are authorized to access any account you connect to.
The App stores the following data only on your device:
| Data | Collected | Stored | Shared | Purpose |
|---|---|---|---|---|
| Account settings | Yes | Device only | No | Provider, server (IMAP/SMTP/JMAP), and sync options for accounts you configure |
| Credentials & OAuth tokens | Yes | Device only (encrypted) | No | Passwords and OAuth2 access/refresh tokens encrypted with Android Keystore (AES-256-GCM) |
| Message cache | Yes | Device only | No | Messages, folders, and attachments cached locally in Room for offline reading and search |
| Encryption keys | Yes | Device only | No | OpenPGP keys and S/MIME certificates you import for end-to-end encryption |
| App settings | Yes | Device only | No | Theme, language, biometric/PIN app lock, swipe actions, and other preferences |
| Purchase state | Yes | Device only | No | Cached "remove ads" entitlement (reconciled with Google Play) |
This data is stored exclusively on your device. We do not have access to it, and it is never transmitted to our servers.
Certain intelligent features run entirely on your device with no network calls, and their results are never sent to us or to any third party:
For providers such as Outlook, Microsoft 365, and Gmail, the App uses OAuth2 (Authorization Code flow with PKCE via Custom Tabs) and connects to your mailbox using XOAUTH2. Sign-in happens between you and your provider; the App receives access and refresh tokens which are stored encrypted on your device and used only to send and retrieve your mail on your behalf, with automatic refresh-token renewal. We never receive these tokens. The scopes you grant authorize mail access only; you can revoke access at any time in your provider's account settings.
OpenPGP and S/MIME encryption are optional and controlled entirely by you. Keys and certificates you import remain on your device, and any encryption, decryption, or signing is performed locally. We are not a key server and do not have access to your keys or your decrypted message content.
If you enable the biometric or PIN app lock, authentication is performed by the Android operating system on your device. The App never receives, stores, or transmits your fingerprint or other biometric data.
INTERNET): required to connect to the mail servers and OAuth providers you configure and to serve ads.ACCESS_NETWORK_STATE): used to detect network availability for syncing.POST_NOTIFICATIONS): used to display local new-mail notifications. New-mail alerts are generated on your device from background mail synchronization — there is no push server and no Firebase Cloud Messaging (FCM).The App does not request location, camera, microphone, or contacts permissions.
Monetization is configured by the operator at deployment; where it is enabled and unless you purchase the ad-removal option, the App displays advertising through Google AdMob (banner, App Open, and native formats). Our advertising partner may collect:
Where required, the App uses Google's User Messaging Platform (UMP) to obtain your consent for personalized advertising. This data collection is governed by Google's Privacy Policy: https://policies.google.com/privacy
We explicitly do not collect:
Data stored on your device is used locally to:
Data collected by Google AdMob and Google UMP is used to display personalized or non-personalized advertisements (based on your consent) and to prevent fraud and abuse. Data collected by Google Play Billing is used to process and reconcile your purchase.
We do not sell, trade, or rent your personal information to third parties.
The App integrates the following third-party services, which handle data according to their own privacy policies:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google AdMob | Advertising | https://policies.google.com/privacy |
| Google User Messaging Platform (UMP) | Ad consent management | https://policies.google.com/privacy |
| Google Play Billing | Process the one-time ad-removal purchase | https://policies.google.com/privacy |
Separately, the App communicates directly with the mail servers and OAuth providers you specify (such as Gmail, Outlook, Microsoft 365, Yahoo, iCloud, Naver, and Daum/Kakao). Those services are operated by you or by parties you choose, and their handling of your accounts, mail, and credentials is governed by their own terms and privacy policies and is outside our control.
We may disclose information if required to do so by law or in response to valid requests by public authorities. As we hold no user content, such disclosure would be limited to information actually in our possession.
Data stored on your device — including cached messages, account settings, and encrypted credentials — remains until you remove the account within the App, clear app data in device settings, or uninstall the App.
Data collected by Google's advertising, consent, and billing services is retained according to their respective policies. Mail stored on your providers' servers is retained according to those providers' policies.
You have the right to:
Under the GDPR and applicable laws, you also have the rights to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. To exercise rights over data held by a third-party service or mail provider, contact that service directly.
Manage advertising consent through:
We implement reasonable technical measures to protect data on your device:
The App is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children.
Data collected by third-party services may be transferred to and processed in countries with different data protection laws. Please refer to Google's Privacy Policy for more information.
Gmail, Google, and AdMob are trademarks of Google LLC; Outlook, Hotmail, Live, and Microsoft 365 are trademarks of Microsoft Corporation; Yahoo is a trademark of Yahoo Inc.; iCloud is a trademark of Apple Inc.; Naver is a trademark of Naver Corporation; and Daum and Kakao are trademarks of Kakao Corporation. All other product names and logos are the property of their respective owners. Sia E-Mail Client is an independent email client and is not endorsed by, sponsored by, or affiliated with any of these providers. These names are used solely to identify the mail services with which the App is compatible.
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date and, for material changes, displaying a notice within the App.
We are not responsible for the data collection, use, or security practices of third-party services integrated into the App, including Google AdMob, Google UMP, and Google Play Billing, nor for the mail servers and OAuth providers you choose to connect to.
We are not responsible for any loss of data stored locally on your device, including cached messages, account settings, and imported keys.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES RESULTING FROM YOUR USE OF THE APP.
This Privacy Policy shall be governed by the laws of the Republic of Korea. For EU users, it shall be interpreted in accordance with applicable EU law including the GDPR.
Sia Makerlab
For GDPR-related inquiries from EEA residents, please include "GDPR Request" in the subject line.
| Data Type | Collected | Stored | Shared | Purpose |
|---|---|---|---|---|
| Account settings | Yes | Device only | No | Connecting to your mail servers and providers |
| Credentials & OAuth tokens | Yes | Device only (encrypted) | No | Authenticating to your mailboxes |
| Email, attachments & folders | No (synced device ↔ your servers) | Cached on device only | Only with servers/providers you specify | Reading and sending your mail |
| On-device summaries & phishing checks | No | Not retained by us | No | Local processing only |
| Encryption keys | No | Device only | No | OpenPGP/S-MIME under your control |
| Purchase state | Yes | Device only | No | Ad-removal entitlement |
| Advertising ID | Yes* | By Google | With Google | Advertising |
| Personal info | No | N/A | No | N/A |
*Collected by third-party services (Google), not by us directly.
This Privacy Policy is available in English. If translated versions are provided, the English version shall prevail in case of any discrepancy.