Privacy

Effective September 2, 2026 · applies to Snug Email for macOS and to this website.

There is no Snug server

Snug Email is a native macOS mail client. It talks to your mail provider over IMAP and SMTP the way any mail client does, and it keeps its cache on your Mac. We run no relay, no sync service and no account system. We cannot read your mail because it never passes through anything we operate.

This website has no analytics, no cookies and no third-party scripts. The fonts are served from this domain.

What Snug stores on your Mac

Your mail cache (headers, bodies, attachments you have opened, the search index and the records the concierge extracts from receipts and notifications) lives in ~/Library/Application Support/SnugEmail. It stays on that Mac. Nothing in it is uploaded to us or to anyone else.

Credentials go in the macOS Keychain under the service name snug.email: mail passwords and app passwords keyed by the account's address, and, for accounts that sign in through the browser, the OAuth refresh and access tokens keyed by oauth.<address>. Items use the WhenUnlocked protection class and are not synced to iCloud Keychain. Removing an account in Settings deletes its Keychain items.

The optional iPhone companion receives account credentials only through a QR code you show it, which expires ten minutes after it is drawn. Accounts that sign in through the browser are not carried to the phone.

Google, Microsoft and Zoho sign-in

When you sign into a Gmail, Microsoft or Zoho account through the browser, the provider hands Snug a token instead of your password. Snug requests the scopes it needs to read, send and file mail over IMAP and SMTP on your behalf (for Google, https://mail.google.com/) plus your email address, which it uses only to confirm that you signed into the mailbox you were setting up.

Tokens are stored in your Mac's Keychain and used from your Mac to connect directly to the provider's mail servers. They are never sent to us. Snug does not share, sell or transfer your mail or your tokens to any other party, does not use them for advertising, and no person at Snug reads your mail. You can revoke Snug at any time from your Google account's third-party access page, your Microsoft account's app permissions page, or the Zoho Accounts connected apps page; Snug then asks you to sign in again and nothing on the server is touched.

Snug Email's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI

The concierge classifies mail so it can file the informational majority and write the daily brief. It runs on-device by default using Apple's Foundation Models, which sends nothing off your Mac. If you add your own API key for a cloud model and switch on the consent toggle in Settings › Intelligence, the text of messages being classified or summarized is sent to the provider you chose (Anthropic, or an OpenAI-compatible endpoint you name) under that provider's terms. The toggle is off by default and the in-app privacy card shows the current state.

Every outbound connection

Besides your own mail servers and any AI provider you enabled, Snug can connect to these places, each for one reason:

Remote images in mail are blocked until you allow them for a sender; when you do, the fetch goes straight from your Mac to the sender's server, so that server learns your IP address.

Changes and contact

If this policy changes, the effective date above changes with it and the app's built-in help links here. Questions go to hello@snug.email.