Privacy
Updated 21 September 2026
Clementine connects directly to your Google accounts and stores a mail cache on your Mac. GoldenBerry Software does not run a mail-sync server. Optional cloud AI sends relevant content to the provider you choose.
The short version
- Your mail lives on your Mac. Clementine talks directly to Google's APIs from your device.
- We run no servers that store your email or its contents.
- AI is opt-in. Choose a local model on Apple silicon or a cloud provider with your own key.
- Your mail is never used to train any model.
- Usage analytics are optional and off by default, and never include your mail. No ads, no trackers.
Email storage and Gmail access
Clementine reads and sends mail by talking straight to Google's Gmail API from your device. Messages, drafts, and attachments are stored locally on your Mac. We do not route your mail through our servers, and we keep no copy of it.
Your Google connection
You connect each account with Google's official sign-in (OAuth), so Clementine never sees your password. Beyond Gmail itself, each permission is optional: Calendar, Contacts, and Gmail Settings are separate choices you can turn on at connect time or later, and off again at any time. You can also revoke Clementine's access entirely from your Google Account security settings.
What Google user data Clementine accesses
- Account identity: the email address, name, and profile photo of each Google account you connect.
- Email messages: the messages in your mailbox, including headers, content, attachments, labels, and drafts.
- Gmail settings: your signatures, your verified send-as addresses, your filters, and your vacation responder.
- Calendar: events on your calendars and your free and busy times.
- Contacts: your saved Google Contacts, and the addresses Google keeps under "other contacts" for people you have written to.
How Clementine uses that data
- Account identity labels each connected account inside the app, so you can tell your accounts apart.
- Email messages are downloaded into a local cache on your Mac so the app can show them, search them, and work offline. Your own actions in the app change your mailbox: reading, sending, archiving, labelling, moving to trash, and permanently deleting mail when you empty the Trash.
- Gmail settings make replies leave from the address the mail arrived at, with that address's own signature, and let you view, edit, and delete your filters and your vacation responder inside the app.
- Calendar shows your day beside a meeting invitation, and can type your free times into a message as text. When you answer an invitation, your reply is written onto the event on your own calendar, and the event is added there if Google has not already done so.
- Contacts power recipient autocomplete in the compose window. They are read, never changed.
Who we share Google user data with
Nobody, in the ordinary case. Clementine talks to Google's APIs directly from your Mac, and we run no servers that receive, store, or relay your Google data, so there is nothing on our side to share, transfer, or disclose. We never sell it, never give it to advertisers or data brokers, never use it to train models, and no one at GoldenBerry can read it.
Two transfers happen only at your direction. The app sends data to Google itself, because that is how it reads and sends your mail. And if you turn the optional AI features on, the text needed for the request you invoked is sent to the AI provider you configured with your own key, under that provider's privacy policy, or processed by a model running locally on your Mac, in which case nothing leaves the device.
Clementine's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How Google user data is protected
- Sign-in happens through Google OAuth. Clementine never sees or stores your password.
- Access tokens are stored in the macOS Keychain, encrypted by the operating system.
- Every connection to Google and to any AI provider uses TLS encryption in transit.
- The local mail cache lives in the app's own container on your Mac, protected by your macOS user account and by FileVault disk encryption when you have it enabled.
- Removing an account from Clementine deletes its local cache and its tokens from your Mac. Data is kept only while the account stays connected.
- Revoking access from your Google Account cuts the app off immediately.
Optional local and cloud AI
Configure your AI provider and choose which features to use. Summaries and drafts run when requested; Auto Labels can classify incoming mail automatically once enabled. A local model processes content on your Mac without an API key. If you choose a cloud provider, the text needed for a request goes directly to that provider using your key. GoldenBerry does not relay those requests, and your mail is never used to train a model.
The CLI and agents
The clem CLI and MCP server run locally on your Mac and act with the permissions you have granted the
app. They only do what you allow, and they leave an auditable record. Nothing runs in the background unless you set
it up.
Usage analytics, only if you say yes
During setup, Clementine asks whether it may collect anonymous usage data: which features get used, how long things take, and when something breaks. It never includes your mail, who you write to, or what you search for, and no Google user data is ever part of it. It is off unless you say yes, it stays off if you skip the question, and you can change your mind any time in Settings. When enabled, these events go to PostHog, processed in the EU.
What Clementine does not do
The app contains no advertising and no third-party trackers. It does not phone home with your inbox, your contacts, or what you read.
Payments
Stripe processes licence payments. Cool Beans manages licence delivery and activation. We receive purchase and licence information, including your email address, but not your full card details. Payment information is handled under Stripe’s privacy policy.
This website
This site uses PostHog in the EU to measure page views, download-link clicks and signup request outcomes. Analytics identifiers stay in page memory; we do not persist them in cookies or browser storage. We do not record sessions or automatically capture clicks, page text or form values. Event URLs exclude query strings and fragments; limited campaign labels and the referring domain help us understand how visitors find the site. Analytics is disabled on the licence page and when your browser sends Do Not Track or Global Privacy Control. The website serves its fonts directly from our own domain.
If you join the waitlist, we store the email address you give us so we can send your beta invite. You can ask us to remove it at any time.
Newsletter and purchase follow-ups
If you sign up for Clementine tips and updates, we store your address at Resend to send the introductory guides and product news you requested. Buying a licence starts a separate, short series with activation help, licence information and a request for feedback. These emails include an unsubscribe link; purchase follow-ups stop if your licence is disabled. Your Gmail messages are never included in these mailing lists.
Your rights
If you are in the EU or UK, you have the right to access, correct, delete, and export your personal data. Because your mail and settings live on your device, you can export or delete them yourself at any time. For the waitlist, newsletter or purchase email address we hold, contact us and we will act within 30 days.
Children
Clementine is not directed at children under 13, and we do not knowingly collect personal information from them.
Changes
If we change this policy, we will update the date above and, for material changes, note it on this page.
Contact
GoldenBerry Software OÜTartu mnt 67/1-13b, 10115 Tallinn, Estonia
hello@clementine.email
You may also contact the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) if you have a concern we have not resolved.