Privacy policy

Last updated: 7 October 2026

Iris is a mail and calendar app for macOS and Linux, published by Alberto Barrago (albz). It is a modified version of Penguin Mail, and like it, it works with Google accounts, through Google's APIs, with Microsoft accounts, through Microsoft Graph, and with other mail providers over IMAP and SMTP. It runs on your own computer. This policy explains what it accesses, where that data goes, and how it is protected.

What Iris accesses in a Google account

You grant access through Google's own sign-in page. Adding an account asks for every permission Iris uses, in one visit:

You may leave any of these unticked on Google's screen. Iris then turns off the feature that needs it and says why where you would use that feature, with a Grant Access button that asks Google again. An account added before Iris asked for all of them at once gets a bar at the top of its mail list that names what it lacks and offers the same button.

What Iris accesses in a Microsoft account

This covers Outlook.com, Hotmail, Live and Microsoft 365 accounts. You grant access through Microsoft's own sign-in page. Adding an account asks for every permission Iris uses, in one visit:

You may leave any of these unticked on Microsoft's screen. Iris then turns off the feature that needs it and says why where you would use that feature, with a Grant Access button that asks Microsoft again.

Your mail and events are downloaded from Microsoft straight to your computer and kept in the same local database as for a Google account. For these accounts Iris talks only to graph.microsoft.com and login.microsoftonline.com. Microsoft's refresh token stays in your system's keychain, as described below.

Where your data goes

How your data is protected

Keeping and removing data

Your data stays on your computer until you remove it. Removing an account in Iris deletes its downloaded mail and its sign-in token from your computer. Removing the app and deleting its folders removes everything else: ~/Library/Application Support/iris and ~/.cache/iris on macOS, or ~/.local/share/iris, ~/.config/iris and ~/.cache/iris on Linux. To revoke Iris's access on Google's side, visit https://myaccount.google.com/permissions. On Microsoft's side, visit https://account.live.com/consent/Manage for a personal account, or your organization's My Apps page for a work or school account.

Google API Services User Data Policy

Iris's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google APIs is used only to provide the features you see in the app, is never sold, is never used for advertising, and is never used to develop, improve or train generalized AI or machine learning models.

Contact

Questions about this policy: albertobarrago@gmail.com.