Culvert is a personal email client for Gmail and Outlook. This policy explains what Culvert accesses, why, and where it goes. There is no Culvert server — your messages, settings, and everything Culvert figures out about your mail are stored only in a local database on your device.
When you connect a Google or Microsoft account, Culvert asks for permission to read, organize, and send mail on your behalf, using each provider's own official sign-in screen — Culvert never sees or stores your email password. Specifically:
Google (Gmail API):
gmail.readonly — to sync your messagesgmail.modify — to mark messages read, archive them, move them to
trash, and report spam/phishing, mirroring the same actions Gmail's own app offersgmail.send — to send and reply to messages you write in CulvertMicrosoft (Graph API):
Mail.ReadWrite — to sync, archive, and report spam the same wayMail.Send — to send and reply to messagesUser.Read — your basic profile (name and address), to identify the
connected accountCulvert's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Everything Culvert does with your mail after fetching it happens locally: sorting messages into categories, marking VIP senders, local search (including archived messages), and flagging messages with a mismatched sender domain as possibly suspicious. None of that reads your message content off your device, calls any Culvert server, or uses a cloud AI service — there's no server to send it to.
If you enable "Notify on new mail," Culvert checks for new messages in the background and shows a local system notification. This check happens directly against Gmail or Graph on the schedule you set in Settings; no separate push service is involved.
If you turn on App lock, Culvert asks Android to verify you using whatever screen lock you've already set up — fingerprint, face, PIN, or pattern. That verification is handled entirely by your device's own operating system; Culvert only receives a yes-or-no answer and never sees or stores any biometric data itself.
Email signatures (including any images you add) are stored only in Culvert's local app storage on your device. Exporting a backup copies Culvert's local database to a location you choose, using Android's own file picker — Culvert doesn't upload that file anywhere itself.
Culvert has no user accounts of its own, no analytics or tracking SDKs, and shows no ads. It does not sell or share your data with third parties, and doesn't run your mail through any AI or cloud service to sort, summarize, or analyze it. The only network requests Culvert makes are the Gmail/Graph API calls described above.
Signing in and syncing mail relies on Google's and Microsoft's own services, which have their own privacy policies covering how they handle your account:
Your synced mail, settings, and signatures live in local app storage until you clear them or uninstall Culvert, at which point they're gone. Culvert doesn't yet have a built-in "disconnect account" option; to revoke Culvert's access to your Google or Microsoft account directly, remove it from your account's own security settings (Google's Third-party access page, or Microsoft's App access page).
Culvert is not directed at children under 13, and Culvert does not knowingly collect personal information from anyone under 13.
If this policy changes, the updated version will be posted at this same address with a new "last updated" date above.
Questions about this policy or your data? Reach out at jlamp606@gmail.com.