Privacy Policy
Last updated 9 August 2026
AxMail is an email client published by Norsou (org. no. 934788680), Skovveien 1, 0257 Oslo, Norway — the business behind the QNgin brand at qngin.com. It runs on your own device and connects directly to your mail provider, exactly as Outlook or Thunderbird does.
We never store your mail. Your messages are fetched by your device from your provider and kept on your device. There is no copy of your mailbox on any machine of ours, and there is no way for us to produce one if we were ordered to.
We do run one optional service, AxMail Cloud, which does two jobs: it can watch your mailbox so your phone is told the moment mail arrives, and it can run the AI features without you needing an API key. Both are off until you switch them on, each asks first, and the section below sets out exactly what each one sends and stores. If you never turn them on, nothing about your mail ever reaches us.
This policy explains all of it: what the app touches, what stays on your device, every case where something leaves it, and the rights you have.
Who is responsible for your data
For almost everything AxMail does, QNgin is not the data controller — not as a technicality, but because the processing happens on your device, under your control, and we never receive the data. You hold your own mail; your mail provider is the controller for the mailbox itself.
QNgin is the controller for the information you deliberately send us: the diagnostics and support you choose to submit, and whatever AxMail Cloud receives once you switch it on. For that:
- Controller: Norsou (org. no. 934788680), trading as QNgin
- Address: Skovveien 1, 0257 Oslo, Norway
- Email: post@qngin.com
What AxMail accesses
To be a working mail client, AxMail needs access to the mailbox you add to it: your messages and their attachments, your folders, contacts as they appear in mail you have sent and received, and calendar invitations.
It reads this over the standard IMAP protocol and sends mail over SMTP, both directly between your device and your mail provider, over an encrypted connection.
Google user data
If you sign in with a Google account, AxMail requests the
https://mail.google.com/ scope. This is Gmail's full IMAP and
SMTP access, and it is the only Google scope under which a standard mail
client can function. AxMail uses it to read, send, organise, delete and search
your own mail, at your direction.
Limited Use disclosure. AxMail's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, we do not and will not:
- use Gmail data for anything other than the mail features you see in the app;
- transfer Gmail data to anyone, except where you direct it — sending a message is a transfer you asked for, and so is pressing Summarise with AI Copilot switched on;
- use Gmail data for advertising, profiling or building a marketing audience;
- use Gmail data to train, create or improve any AI or machine-learning model, ours or anyone else's;
- sell Gmail data under any circumstances;
- read your mail, or let anyone else read it. Nothing we operate ever fetches the content of a message.
The one place Gmail content can pass through equipment of ours is the AI relay, and only for the request you just made: you select a message and ask for a summary, a translation or a suggested reply, that text is sent to our server, forwarded to the model, and the answer comes back. It is held in memory for the length of the request, never written to disk, never logged and never used for training. It is described in full below. With AI Copilot off — which is how it ships — no such request is ever made.
The same is true of Microsoft accounts and of any other IMAP mailbox you add. Google is called out separately only because Google requires it.
Where your data is stored
| What | Where it lives |
|---|---|
| Messages, folders, attachments, calendar events, contacts | A database file on your own device, so the app works offline and can search quickly. It is never uploaded anywhere. |
| Passwords, app passwords and OAuth tokens | Your operating system's secure credential store — Windows Credential Manager, the macOS Keychain, or the Android Keystore. Not in the database, and not in plain text. If you switch on server-side watching, a second encrypted copy is held on our server; see AxMail Cloud. |
| Attachments you save | Wherever you choose to save them. They then belong to you and are outside the app's control. |
| Settings and a local diagnostics log | Your device only. See Diagnostics and support. |
How long it is kept
Locally, for as long as you keep the account in the app. Removing an account deletes its messages, its cached attachments and its stored credentials; uninstalling AxMail removes everything.
On our server, only if you switched on AxMail Cloud: a stored login lives until you disconnect or remove the account, and is then deleted outright. The device record lives until the last of its mailboxes is disconnected. AI usage counters — numbers, no text — are kept for 90 days so the daily allowance works and we can see what the service costs. Write to us and we will delete any of it sooner.
The diagnostics log is capped at roughly 256 KB and older lines are discarded automatically as new ones are written.
Anything you email us is kept only as long as needed to deal with your request, and then deleted.
What leaves your device, and when
We think you should know every case where AxMail opens a connection to something other than your own mail provider. There are five. You control all of them, and none of them send anything to QNgin unless you ask.
1. Remote images in messages
Mail often contains images hosted on the sender's server. Loading them contacts that server, which lets the sender see that you opened the message and roughly when. AxMail loads remote images by default, because blocking them makes ordinary mail look broken. To stop this, turn on Settings → Security → Block remote images.
2. Sender pictures
To show a photo next to a sender, AxMail may ask Gravatar (Automattic) whether one exists for that address. The address is sent as an irreversible hash, and no reply simply means no picture is shown.
3. AxMail Cloud
AxMail Cloud is our own server, running on rented hardware in Nuremberg, Germany. It exists because two things cannot be done well on a phone alone: noticing new mail without keeping a connection open all day and flattening the battery, and running an AI model. It does nothing until you switch on one of the two features below, and each one asks for your agreement first and explains what it sends.
Registering the device. Turning on either feature creates
a record for this installation. It holds a public key the app generated, a
hash of its access token, the platform name (android,
windows), the app version, and — for push — the notification
token issued by Google. It does not contain your name or your email address.
There is no username, no password and no account to sign in to; the key is
the identity.
Server-side watching (optional). For your phone to be told instantly that mail arrived, something has to be watching the mailbox while the phone sleeps. If you choose this mode, our server needs to be able to sign in to that mailbox, so it stores:
- the mail server's address, port and security setting;
- the username you sign in with — usually your email address, held as typed, because it is needed to log in;
- the folder to watch;
- your password or OAuth token, encrypted. Each one is sealed with its own key, and that key is itself sealed with a master key that is not in the database and not in any backup. A stolen copy of the database is ciphertext and nothing else.
What the watcher actually does is narrow on purpose: it connects, waits, and when the mailbox says something arrived it notes the new message's number. It never fetches the message. It has no sender, no subject, no body and no attachment — and neither does the notification it triggers, which carries only "something arrived, in this mailbox". Your phone then downloads the message itself, directly from your provider, as it always has.
Switching back to an on-device mode, or removing the account, deletes the stored login from our server outright — the encrypted password and its key are destroyed together. There is no soft delete and no archive copy.
AI Copilot (optional). With this on, the AI features work without you needing an API key of your own. When you press Summarise, Translate, Suggest a reply, or ask for a tone change, the text concerned and your instruction are sent to our server, which forwards them to Google's Gemini API and returns the answer. The text is held in memory for that request only — not written to disk, not logged, not retained, and not used to train anything. What we do keep is a counter: which device, which day, which feature, how many requests and how many characters, so the daily allowance can be enforced. The counter holds no text.
Being straight about the limit of that promise: while your request is being handled it exists in the memory of a program we operate. We do not read it and nothing stores it, but this is a weaker guarantee than "we could not if we wanted to", which is what applies everywhere else in this policy. If that distinction matters to you, leave AI Copilot off, or configure the app with your own API key so the request goes straight to the provider.
4. Push notifications
Server-side watching delivers its ping through Firebase Cloud Messaging, Google's notification service, because on Android there is no other way to wake an app reliably. The message is data only: a type, an identifier for the mailbox, a folder name and a timestamp. No sender, no subject, no count, nothing about the message. Google sees that a notification was sent to your device, and that is all there is to see.
5. Diagnostics and support
AxMail keeps a small activity log on your device to make faults diagnosable — connection attempts, sync results, send failures and similar. It records the recipient addresses of messages you send, and error text that may quote a subject line. It stays on your device and is visible under Settings → Diagnostics → Activity log.
That screen also offers to email the log to us. If you use it, you are sending us those log lines — including those addresses — along with your own account address. Nothing is sent unless you press that button, and you can read the whole log on screen first. We use it only to investigate your problem, and we delete it afterwards.
The same applies to any support mail you send: we receive what you put in it, and use it only to answer you.
What we collect automatically
Nothing. AxMail contains no analytics, no telemetry, no crash reporting, no advertising identifiers and no tracking of any kind. We do not know how many people use AxMail, or who they are.
The one qualification: if you switch on AxMail Cloud, that installation necessarily has a record on our server, so we can count how many devices use the cloud features. The record carries no name and no email address, and we do not connect it to a person. Everyone who leaves the cloud features off stays entirely uncounted.
This website is the same: no cookies, no analytics, no third-party fonts or scripts. Loading this page contacts nothing but our own server.
Legal basis
Where QNgin does process personal data — the support mail and diagnostics you choose to send us, and anything AxMail Cloud receives once you switch it on — we rely on:
- Your consent (GDPR Art. 6(1)(a)), given by pressing send, or by agreeing to the dialog that explains what the cloud feature will store before it stores anything. You can withdraw it by disconnecting in the app, which deletes what was stored, or by asking us.
- Performance of a contract (Art. 6(1)(b)) for running the cloud features themselves: once you have asked for server-side watching, storing the login is what delivering it consists of.
- Our legitimate interest (Art. 6(1)(f)) in fixing faults in our own software, which we consider proportionate given that you chose to report the fault.
Processing on your own device, for your own mailbox, is not carried out by us and needs no legal basis from us.
Who else is involved
The companies below act for us, under contract, only to the extent the features you switched on require. Nobody else receives anything.
| Who | What for | Where |
|---|---|---|
| Hetzner Online GmbH | The machine AxMail Cloud runs on | Nuremberg, Germany |
| Google (Firebase Cloud Messaging) | Delivering the content-free "you have mail" ping | Google infrastructure; no message data is sent |
| Google (Gemini API) | Running the AI request you asked for, if AI Copilot is on | Google infrastructure, which may be outside the EEA |
| Automattic (Gravatar) | Sender pictures, from a hashed address | United States |
The last two can mean your data leaves the EEA. Gravatar sends only a hash, and the AI relay only sends what you asked about, when you asked. Both are features you can switch off, and the app is fully usable with neither.
Security
Credentials go into the operating system's secure credential store rather than the app's own database. Mail is transferred over TLS. Sign-in to Google and Microsoft uses OAuth with PKCE, so your password is never typed into AxMail or stored by it. On devices that support it you can require Windows Hello, Touch ID, a fingerprint or a device PIN to open the app.
A login held for server-side watching is encrypted with a key of its own, which is in turn sealed with a master key kept outside the database and outside every backup. Backups are therefore ciphertext by construction. Requests to the server are signed by the device's key and carry a one-time value, so a captured request cannot be replayed.
Being honest about the limits: the local database is protected by your device, not by separate encryption. Anyone with access to an unlocked, signed-in device can read your mail in AxMail, exactly as they could in any other mail app. Keep your device locked. And as noted above, an AI request necessarily exists in our server's memory while it is being answered.
Your rights
Under the GDPR you have the right to access, correct, erase, restrict, object to and port personal data held about you. If you have never switched on AxMail Cloud and never written to us, there is genuinely nothing to exercise them against, because we hold nothing.
If you have, write to post@qngin.com and we will act on it. Erasure you can also do yourself and immediately: disconnecting in Settings → Sync deletes the stored login from our server, and removing the account deletes everything belonging to it.
For the mail in your mailbox, those rights sit with your mail provider, since they hold it. For the copy on your device, you can exercise them yourself by removing the account or uninstalling the app.
If you are unhappy with how we have handled your data you may complain to your national supervisory authority — in Norway, the Norwegian Data Protection Authority (Datatilsynet).
Removing access
You can remove an account from AxMail at any time in Settings → Accounts, which deletes its local data and stored credentials.
You can also revoke AxMail's access from the provider's side, which works even if you no longer have the app installed:
- Google: Third-party apps & services
- Microsoft: Apps and services you've given access to
Children
AxMail is not directed at children under 13, and we do not knowingly collect anything from them — or, as set out above, from anyone.
Changes
If this policy changes we will update the date at the top of this page. If a change ever affects how your data is handled, we will say so clearly in the app before it takes effect, and ask for your agreement where the law requires it — as we do today before anything is sent to AxMail Cloud.
This version records the arrival of AxMail Cloud. Earlier versions of this policy said no server of ours received anything, which was true when they were written and stopped being true when the optional cloud features shipped. Nothing changes for anyone who leaves them switched off.
Contact
Questions about this policy, or about your data, go to post@qngin.com and a person will answer.