Privacy / the honest version

Your mailbox stays yours.

Jaymail gives you an interface for a mailbox you already have. We do not sell a mailbox, sell your data or fund Jaymail with advertising. The web app and the native iOS and Android apps take different technical routes, so we explain them separately below.

App policy: July 21, 2026 · v1.5. Public website analytics notice updated September 6, 2026.

At a glance

  • Jaymail access is a right to use the interface; it is separate from your mailbox login.
  • The hosted web app relays JMAP traffic to your Stalwart server through infrastructure operated by JD Studio.
  • The native iOS and Android apps connect from your device directly to your chosen Stalwart server.
  • No ads, marketing trackers, data sale or third-party analytics SDKs.
  • Mailbarn is not required and is not currently offered as a mailbox option.

Jaymail access and the waitlist

If you join the early-access waitlist, we store your email address and signup time so we can review and send an invite. An issued entitlement stores an opaque ID, your normalized invite email, a cryptographic hash of the access code, its active or revoked status, and the creation time. The plaintext code is not stored. After a successful check, your browser receives an encrypted, HttpOnly access cookie containing only the opaque ID and bounded timestamps. Revoking Jaymail access does not delete or change your provider mailbox.

Jaymail for Web

The web interface runs on infrastructure operated by JD Studio in the Netherlands. To overcome browser restrictions and provide one consistent interface, the hosted app connects to your Stalwart server over JMAP through a narrow Jaymail gateway. Your mailbox address, password or app password is sent over HTTPS to Jaymail and then to the validated provider endpoint. The resulting provider credential is held in an authenticated, encrypted, HttpOnly browser cookie; browser JavaScript receives an opaque Jaymail gateway token.

Mail, calendar, contact and submission responses therefore pass through our hardware in transit while you use the web app. The gateway is not a mailbox store and is designed not to persist message bodies, headers, recipients or attachments in application logs. Disconnecting an account removes its gateway credential. Your provider remains the system that stores and operates the mailbox.

Jaymail for iOS

The native iOS app connects directly from your device to your Stalwart server over JMAP. Your email address, server address and password stay in the iOS Keychain. Mail cache, search index, settings, snoozed messages and offline actions stay on the device under iOS Data Protection. Deleting the app deletes that local data. The optional push relay is the exception described next.

Jaymail for Android

The native Android app follows the same model as iOS: it connects directly from your device to your Stalwart server over JMAP. Your email address, server address and password are stored encrypted with a key in the Android Keystore. Mail cache, search index, settings, snoozed messages and reminders stay on the device, protected by Android’s file-based encryption. Deleting the app deletes that local data. The Android app does not yet offer server push; alerts such as snooze wake-ups and reminders are generated locally on the device.

Optional iOS push relay

If you enable new-mail alerts, our relay stores the Apple push token, an opaque registration ID, a one-way hash of a client secret, the APNs environment, verification status and opaque delivery state used to suppress duplicate alerts. It does not receive or store your email address, mail-server address, password, JMAP access token, sender, subject or message content.

The relay asks Apple to show a generic new-mail alert. When rich previews are enabled, a notification extension on your device fetches the sender, subject and preview directly from your mail server. Disabling alerts or removing the account removes the relay record and local preview context.

Diagnostics, logs and the public site

The web app can send a bounded technical error report to our own server logs: error message, truncated stack, page path without query parameters, browser user agent and time. It does not intentionally include mailbox content, search text or JMAP request URLs, and you can turn reporting off in Jaymail Settings. iOS uses Apple’s distribution diagnostics choices and does not include a third-party crash-reporting SDK. The Android app includes no crash-reporting or analytics SDK at all.

This public marketing site makes no third-party runtime requests and sets no cookies. We use self-hosted Umami to understand which public pages are useful and where visits come from. It records page paths, referring sites, approximate location, browser and device information without cookies or advertising profiles. Query strings and URL fragments are excluded. Umami processes the IP address to derive location and a rotating visitor identifier, but does not store the full IP address. Counts are estimates, not identified people. Enable Do Not Track in your browser to stop these website measurements. Separate infrastructure security logs may contain IP addresses and request details. These measurements apply only to jaymail.app, not to your mailbox or the Jaymail apps.

Third-party requests you control

  • Brand logos. Where enabled, Jaymail may query DNS and fetch a sender-published logo or favicon. You can turn brand logos off.
  • Remote images. Message images are blocked by default and load only after you choose to show them or trust a sender.
  • Unsubscribe. A one-tap unsubscribe request is sent only when you tap it.
  • Apple Push Notification service. Used only for iOS alerts you enable.

Your choices and rights

You can disconnect a mailbox without giving up Jaymail access, or ask us to revoke your Jaymail access without changing the mailbox at your provider. You can also ask to access, correct or erase personal data we hold, object to or restrict processing, and lodge a complaint with a supervisory authority such as the Dutch Autoriteit Persoonsgegevens.

Jaymail is developed and operated by JD Studio (Jordy Dost), Netherlands. For a privacy request, email jd@jdstudio.app. We process access and connection data to provide the service you request, and operational security data to keep that service reliable and protected.

Changes

We will update this page when the model changes and note the date above. Material changes will be called out before they take effect where reasonably possible.

Support ·hello@jdstudio.app