Menekşe ("we") is a local macOS mail client. We operate no backend service. The only data Menekşe processes is the data you enter into the app on your own Mac.
English summary: Menekşe collects nothing and operates no backend. It stores account references, Keychain items, a local SQLite mail cache, drafts and LLM settings on your Mac only, and connects only to the IMAP, SMTP, OAuth and LLM hosts you configure.
What we collect
- Nothing. Menekşe contains no telemetry, no analytics SDK, no remote logging and no crash reporter that sends data to us.
- Apple may collect general crash logs from macOS itself; those are tied to your Apple ID account and never reach us.
What Menekşe stores on your Mac
- Account file:
~/Library/Application Support/Menekse/accounts.json — email address, provider and a reference key to the Keychain item. No password, OAuth token or message body.
- Keychain: IMAP app passwords or OAuth access/refresh tokens, and the public OAuth client ID used for refresh.
- Mail cache:
~/Library/Application Support/Menekse/mail-cache.sqlite — envelopes, the full-text search index and last-known message flags. Removing an account deletes the cached bodies.
- LLM configuration:
~/Library/Application Support/Menekse/llm.json — provider address, model name and a reference key to the API token. The token itself stays in the Keychain.
- Every file above is written owner-only (
0600); the mail cache applies the same mode to the SQLite database and its -wal/-shm sidecar files.
- Drafts: until sent or discarded, in
~/Library/Application Support/Menekse/drafts.json.
- Local outbox queue: outgoing messages stored while offline are deleted after delivery.
- Cloud sync state (once explicitly enabled in the future): a local metadata/outbox file scoped to your iCloud user section; the prototype enforces
0600 file and 0700 directory permissions.
What your Mac sends over the network
For mail operations Menekşe connects to the servers you configured for your account:
- IMAP to the host/port you entered, over TLS, to fetch and sync your mailbox.
- SMTP to the host/port you entered, over TLS, to deliver the mail you compose.
- When OAuth sign-in is selected: Google or Microsoft identity endpoints for sign-in and token refresh. Menekşe also requests your account email from the provider so it can identify the mailbox.
- The LLM provider address you entered, to get a response when you ask the AI. The request contains only the message envelope or quotation you selected.
Menekşe does not route traffic through a Menekşe-operated backend. OAuth requests go directly to Google or Microsoft, and only when you choose that sign-in method.
Remote resources in HTML email (images, tracking pixels, style sheets and frames) are blocked by default. You can allow remote resources for the open message; the choice resets when you open another message. Plain-text content stays readable without loading them.
The CloudKit sync contract and private-database transport are currently a development prototype and are not invoked by the app; this build sends no data to iCloud for Menekşe sync. Before sync is enabled the app will request the relevant iCloud container entitlement and show an explicit sync setting. The planned initial allow-list uses CloudKit encrypted fields for account references, message state, snooze metadata and saved searches; credentials, message bodies, attachments and draft bodies are excluded.
Children
Menekşe is not directed at children under 13 and does not knowingly collect data from them.
Your rights
You can remove all locally stored data by deleting the app and the directories listed above. Removing an account from the app deletes both the cache rows and the Keychain entry.
For requests beyond deletion (access, rectification, portability) write to halil@ertekin.me — with the local architecture we hold no server copy, so most of these requests are fulfilled by you on your own device.
Contact