PRIVACY POLICY

Townes Mail CLI Privacy Policy

Effective date:

This policy explains how Townes Mail CLI accesses, uses, stores, and shares your Google user data. Townes Mail CLI is a command-line tool made by Townes & Co., LLC ("Townes & Co", "Townes", "we") that lets your AI assistant or agent work with your own Gmail and Google Calendar. This policy covers Townes Mail CLI only. For what the tool does and who it is for, see the Townes Mail CLI home page.

In short: Townes Mail CLI runs on your own computer and talks directly to Google. There is no Townes server in between, so Townes never receives your mail or calendar data. The tool keeps only what it needs on your computer, and you can revoke its access at any time.

THE DATA IT ACCESSES

When you sign in, you approve three Google permissions. With them, Townes Mail CLI can access:

  • Gmail (https://www.googleapis.com/auth/gmail.modify): your messages and conversations, including their senders, recipients, subjects, dates, bodies, and attachments; your labels and drafts; and your send-as addresses and signature, so that mail it sends comes from the right address.
  • Calendar events (https://www.googleapis.com/auth/calendar.events): events on the calendars you can access, including their titles, times, descriptions, locations, guests, and Google Meet links, and your responses to invitations.
  • Your calendar list, read-only (https://www.googleapis.com/auth/calendar.calendarlist.readonly): the names, ids, and time zones of the calendars in your calendar list, your access level on each, and whether each allows Google Meet links.
  • Your Google account email address, which it checks against the account you signed in, so that it always acts on the account you meant.

It reads only what a command asks for. It does not sync your mailbox or calendar, and it does not run in the background, apart from an optional weekly job that you install yourself to keep your sign-in active. That job only refreshes the sign-in and checks your account's email address with Google.

HOW IT USES THE DATA

Townes Mail CLI uses Google user data only to carry out the command that you, or your AI assistant on your behalf, runs on your computer. A search returns the matching messages, a send sends the email you wrote, and a calendar command creates or changes the event you described. The tool prints each result to the program that ran the command, on your computer.

Townes does not use Google user data for advertising, does not sell it, and does not use it to develop, improve, or train non-personalized AI or machine-learning models. Townes never receives the data through this tool, and the tool gives no one at Townes a way to see it; someone at Townes would see it only if you send it to them, for example by sharing a log file when asking for help.

YOUR AI ASSISTANT

Townes Mail CLI is built to be run by an AI assistant, such as Claude Code, that you choose and set up on your computer. Townes Mail CLI passes Google user data only to the program that ran the command, usually the AI assistant you run it from, and only to carry out the request you made. The assistant may send that data to its AI model provider to produce its response. Other than that, the tool sends Google user data only to Google, to do what a command asks, and some commands reach other people through Google (see Sharing). It never passes the data on for developing, improving, or training non-personalized AI or machine-learning models.

You control what the assistant may run. Every action that can put content in front of other people (sending, replying to, or forwarding mail, sending a draft, and creating, changing, deleting, or answering calendar events) has its own command, so you can require your approval before the assistant runs it.

WHAT IT STORES, AND FOR HOW LONG

Everything Townes Mail CLI stores is on your own computer, in files that only your user account can read. It keeps no copy of your mailbox or calendar. The paths below are the defaults on both Linux and macOS; they follow the standard XDG_* settings if you have changed them.

WHATWHERE AND WHYHOW LONG
Sign-in token The long-lived Google token that lets the tool act without asking you to sign in again. Stored in your operating system's keychain: Secret Service on Linux, the login Keychain on macOS. Only if you explicitly opt in, it is kept instead in a file under ~/.local/share/mail-cli/tokens/. Until you run mail-cli auth logout. If you revoke access in your Google Account instead, the token stops working at once but stays stored until you log out.
Short-lived tokens Access tokens, kept so each command does not have to refresh the token, and the details of a sign-in in progress. Both are in a private per-user temporary folder: $XDG_RUNTIME_DIR/mail-cli, or $TMPDIR/mail-cli-<uid> on macOS. Access tokens: until you log out, the next refresh replaces them, or the temporary folder is cleared; each stops working within about an hour. A sign-in: it stops working after 15 minutes, and stays until a sign-in started after that removes it or the folder is cleared.
Settings ~/.config/mail-cli/config.toml: the email addresses of the accounts you signed in, their short names, and preferences such as your time zone. Until you delete it.
Account status ~/.local/state/mail-cli/accounts/: when access was granted and last refreshed, and the last error code, if any. Until you log out or delete it.
Send record ~/.local/state/mail-cli/ledger/: one-way hashes and Google message, conversation, and draft ids, so that a retried command does not send the same email twice (unless it was run with --allow-duplicate). It holds no subjects, bodies, or recipients. Entries expire after 24 hours, or 30 days for a send with an explicit retry key or of an existing draft. Expired entries are removed by a cleanup that runs when the tool next writes to the record, about once a day, or sooner if the record grows large.
Logs ~/.local/state/mail-cli/logs/, one file per day, for troubleshooting. Details below. Deleted automatically once they are more than 30 days old, the next time the tool runs (the weekly keepalive job, if installed, runs it). Turning the log file off also stops this cleanup.
Attachments you save Saved only when a mail-cli attachment command asks for them, to ~/.cache/mail-cli/attachments/ or the location named in the command. Until you delete them.

What the logs contain. The logs record the commands run, the names of the options used, and the values of a few that hold no content, such as result limits and ids; the email addresses of your accounts; Google ids of messages, conversations, drafts, labels, events, and calendars; the Gmail and Calendar search queries sent to Google; the email addresses of the recipients and calendar guests a command checks or sends to (including drafts and invitations); and timings, error codes, and the name of the program that ran the command. They never record sign-in tokens or other secrets, message bodies, snippets, or subjects, attachment names or contents, or event titles, descriptions, or locations, except where such words appear in a search query that you or your assistant write, which is logged as written. The tool never sends its logs anywhere. Setting the environment variable MAIL_CLI_LOG=off turns the log file off.

SHARING

Townes Mail CLI does not share your Google user data with Townes or with anyone else. Townes does not receive, sell, rent, or trade it, and the tool sends no analytics or usage data anywhere.

The tool sends data to Google only to do what a command asks. Some commands reach other people through Google by design. Sending, replying to, or forwarding mail delivers it to its recipients. Creating, changing, deleting, or responding to an event that has other guests shares that change with them through Google: it can appear on their calendars, and a response, with any note you add, is shown to the organizer. Google emails them about the change only when the command's --notify choice says to.

Results go to the program that ran the command, as described under Your AI assistant.

SECURITY

  • Every connection goes directly to Google over HTTPS.
  • You sign in on Google's own consent screen, using OAuth with PKCE. You type your password only into Google, and Google returns you to the tool on your own computer, either through a page it serves locally or through a link you paste back to it. Townes never sees your password or your tokens.
  • The long-lived sign-in token is kept in your operating system's keychain (or, if you opt in, in a file only your user account can read), and every file the tool writes can be read only by your user account.
  • Tokens, secrets, and message content are kept out of logs and error messages, and automated tests check this across the tool's commands, including their failures.

LIMITED USE

Townes Mail CLI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

REVOKING ACCESS AND DELETING YOUR DATA

  • Run mail-cli auth logout <account> --yes. It revokes Townes Mail CLI's access to that Google account at Google and deletes the sign-in token, access tokens, and account status from your computer. Every installed copy of the tool shares one Google app registration, so this signs the account out on all your computers. Add --keep-grant to remove it from this computer only.
  • Or remove Townes Mail CLI's access in your Google Account at myaccount.google.com/permissions. That also stops it on every computer.
  • To remove everything else the tool stored, delete these folders: ~/.config/mail-cli, ~/.local/state/mail-cli, ~/.cache/mail-cli, the temporary folder $XDG_RUNTIME_DIR/mail-cli (on macOS, $TMPDIR/mail-cli-<uid>), and, if you opted into file storage, ~/.local/share/mail-cli; and delete any attachments you saved to a location you named with -o. Deleting the program does not remove any of these.
  • Townes holds no copy of your Google data, so there is nothing for us to delete on our side. Mail and events the tool created or changed are in your Google account, where you manage them as usual.

CHANGES TO THIS POLICY

When this policy changes, we will update this page and the effective date at the top.

CONTACT

Questions or requests about Townes Mail CLI and your data: Townes & Co., LLC (Townes & Co), robert@townes.ai.