◂ BreezePRIVACY POLICY

Privacy Policy

LAST UPDATED 6 AUGUST 2026

This policy covers the Breeze desktop application for Windows and the website at breez3.com. It is published by Breeze, who can be reached at privacy@breez3.com.

The short version

  • ✓ Your email is stored on your own computer, not on a server we run.
  • ✓ There is no Breeze account, and no Breeze server holding your mail.
  • ✓ This website sets no cookies and runs no analytics.
  • ✓ We cannot read your email. We have no copy of it to read.

The rest of this page is the same thing, said carefully.

1. Information Breeze accesses

Breeze is an email client, so it necessarily handles the contents of your mailbox. It accesses the following, all of it only on your own device:

  • Message content — subjects, bodies, sender and recipient addresses, dates, labels and attachments of the messages in the accounts you connect.
  • Contact details — names, email addresses and profile pictures, used for recipient suggestions and sender avatars.
  • Basic Google profile — the address, name and avatar of each connected account, so accounts can be told apart.
  • Verification codes — detected by scanning incoming messages on your machine, and copied to your clipboard when you ask.
  • Your settings — preferences such as whether Breeze launches at startup.

Breeze does not collect, receive, transmit or store any of this. There is no Breeze server for it to reach. It is read from Google by the app running on your computer, and written to a database file on that same computer.

2. Google account access and Limited Use

You sign in with Google’s official OAuth flow. Breeze never sees or stores your Google password. These are the permissions it requests and what each is for:

PERMISSIONWHY IT IS NEEDED
gmail.readonlyRead your messages so they can be listed, searched and displayed, and so verification codes can be spotted.
gmail.modifyApply the changes you make — mark as read, star, archive, or move to trash.
gmail.sendSend the messages you write and reply to.
contacts.readonlySuggest addresses while you type a recipient, and show sender profile pictures.
userinfo.emailIdentify which account is signed in, so several can be kept apart.
userinfo.profileShow your name and avatar in the account switcher.

Breeze’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Breeze does not use Google user data to serve advertising, does not sell it, does not transfer it to third parties except as needed to provide the app’s features, and does not allow humans to read it.

You can withdraw Breeze’s access at any time from your Google Account’s security settings, without contacting us.

3. Where your data is stored, and for how long

Everything Breeze keeps is written to your own computer, in the application’s data folder under your Windows user profile:

  • Cached mail — a local database file, so messages open instantly and work offline.
  • Sign-in tokens — encrypted with the Windows Data Protection API (DPAPI), which ties them to your Windows user account so other users of the machine cannot read them.
  • Settings and drafts — stored in the same local database.

Retention: this data stays on your machine until you remove it. Because we hold no copy, we have no retention period to apply and nothing to delete on your behalf. Removing an account from Breeze deletes its cached mail and tokens; uninstalling the app and deleting its data folder removes everything.

4. What leaves your computer, and to whom

Breeze is deliberately quiet, but it is not hermetic. These are the only parties that receive anything, and what each receives:

  • Google— receives your mail requests, because that is where your mailbox already lives. This is the only party that ever receives message content. Governed by Google’s privacy policy.
  • Avatar lookup services— to show a picture beside a message, Breeze may request one, including from the Gravatar service. Where that happens, an irreversible hash of the sender’s address is sent rather than the address itself. This concerns people who email you, not your message content.
  • GitHub — receives a request when Breeze checks whether a newer version exists. This reveals your IP address and current version, as any download does, and contains nothing about you or your mail.
  • Microsoft — if you obtain or buy Breeze through the Microsoft Store, Microsoft handles distribution, licensing and payment under its own privacy statement. Breeze never receives or stores your payment details.

We do not sell personal information, we do not share it for advertising or cross-context behavioural advertising, and there are no advertising networks, trackers, analytics or telemetry in the app or on this site.

5. This website

The site is a set of static files with no database, no login and no server-side code running on your behalf. Cookies: none. Analytics: none.

The interactive demo stores one value in your browser’s local storage — breeze-sound, remembering whether you turned demo sound on. It never leaves your browser, and clearing your browsing data removes it. The email shown in the demo is fictional.

Hosting is provided by Cloudflare Pages, which processes the network requests needed to deliver the page and may keep short-lived operational logs, including IP addresses, for security and abuse prevention. We do not receive analytics from those logs.

6. How your information is secured

  • Connections to Google and to update servers use HTTPS.
  • Sign-in tokens are encrypted at rest with Windows DPAPI, scoped to your Windows user account.
  • Message HTML is sanitised before display, and rendered inside a sandboxed frame with its own opaque origin, so a hostile message cannot reach the rest of the app or your accounts.
  • Remote images are blocked until you choose to load them, which stops the tracking pixels most marketing mail carries.
  • Updates are signature-checked before they are applied, so a tampered update is rejected.
  • Because there is no central server holding user mail, there is no central database to breach.

No system is perfectly secure. The security of the data on your machine also depends on your own Windows account and device security.

7. Your rights and choices

Data protection laws — including the UK and EU GDPR, and California privacy law — give you rights to access, correct, export, restrict and erase personal information held about you, and to object to its processing.

Breeze holds no personal information about you, so in practice these rights are exercised directly and immediately by you:

  • Access and export — your mail is in your Google account and cached on your own disk; both are yours already.
  • Erase — remove the account in Breeze, or uninstall the app and delete its data folder.
  • Withdraw consent— revoke Breeze’s access in your Google Account security settings at any time.

If you believe we hold information about you and wish to exercise a right, write to privacy@breez3.com and we will respond within 30 days. You also have the right to complain to your local data protection authority.

8. Children

Breeze is not directed at children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect information from them. As we collect no personal information from anyone, there is none to remove; if you believe a child has provided information to us, contact privacy@breez3.com.

9. Changes to this policy

If this policy changes, the date at the top of the page changes with it. Material changes — in particular any change to what data is collected or who receives it — will be described here before the version that makes the change is released.

10. Contact

Questions about this policy, about what Breeze does with anything, or requests relating to your rights can be sent to privacy@breez3.com. We aim to reply within 30 days.