What Pebble Accesses
When you connect a Gmail account, Pebble requests Google OAuth permissions needed to work as a desktop mail client.
- Google account identity: your email address and basic profile name from Google userinfo scopes.
- Gmail mailbox access: the
https://mail.google.com/scope may allow Pebble to read, compose, send, modify, and delete Gmail messages as needed for mail-client features. - Mail content and metadata: message headers, subject lines, senders, recipients, dates, snippets, bodies, labels, folders, thread IDs, read/starred state, drafts, and attachments.
- OAuth tokens: access tokens, refresh tokens, expiration data, and granted scopes used to keep your account connected.
- Local app data: accounts, settings, rules, Kanban cards, search index data, trusted senders, pending mail operations, and preferences.
How Pebble Uses Data
Pebble uses your data only to provide email features you choose to use, including account connection, mailbox sync, message viewing, search, compose and send, draft management, archive, trash, labels, read/starred state, rules, snooze, and Kanban workflows.
Pebble does not use Google user data for advertising, credit evaluation, surveillance, or unrelated analytics.
Local Storage and Security
Pebble stores mail data on your device by default. The local SQLite database, search index, attachments, rules, and settings are stored under the app data directory. OAuth tokens and credentials are encrypted at rest with a per-device key.
Pebble does not operate a Pebble-hosted cloud mailbox service and does not collect telemetry from the desktop app.
When Data Leaves Your Device
Pebble sends data over the network only when a feature requires it:
- Mail providers: Gmail, Outlook, or IMAP/SMTP servers receive requests needed to sync mail, send mail, update labels, archive, trash, or manage drafts.
- Translation: if you use translation, the selected text may be sent to the translation provider or LLM endpoint you configure.
- WebDAV settings backup: if you enable backup, Pebble uploads settings, rules, Kanban data, translation config, and account metadata to the WebDAV server you provide. It does not include email messages, attachments, or OAuth secrets.
- External message images: if you choose to load external images in an email, those image hosts may receive network requests from your device.
- Public website: this website may load fonts from Google Fonts and links to GitHub resources.
Sharing, Sale, and Limited Use
Pebble does not sell Google user data, transfer it to advertising platforms, or use it for serving ads. Pebble does not allow humans to read your Google user data unless you explicitly provide it for support, it is required for security, or it is required by law.
Pebble's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your Choices
- You can disconnect accounts in Pebble and remove local account data from the app.
- You can revoke Pebble's Google access from your Google Account permissions page.
- You can delete Pebble's local app data from your device according to your operating system's app data controls.
- You can choose whether to use translation, WebDAV backup, external image loading, and other optional network features.
Children
Pebble is not directed to children under 13 and does not knowingly collect data from children.
Changes
If this policy changes, the updated version will be posted on this page with a new update date. If Pebble changes how it uses Google user data, users should review the updated policy before continuing to use the affected features.
Contact
For privacy questions, contact the developer at sq2180802265@gmail.com.
Quick Summary
Pebble is local-first. Connecting Gmail gives Pebble OAuth access to your Google account identity and Gmail data needed for email-client features.
Mail, search indexes, attachments, rules, and settings stay on your device by default. OAuth tokens and credentials are encrypted locally.
Data leaves your device only when you use a feature that requires it, such as mail sync, sending mail, translation, WebDAV backup, or external image loading.