Privacy
Privacy policy — MaksIT.Postclient
Last updated: 2026-09-21
This notice is for MaksIT.Postclient (Postclient), a desktop mail client for PEC, REM, and IMAP. It is the privacy policy URL for the Microsoft Store listing.
Controller: MaksIT. privacy@maks-it.com.
GDPR and the Italian Privacy Code apply.
Postclient is not a PEC provider, not a qualified trust service provider, and not hosted webmail.
Data the app processes on the device
- Mail (headers, bodies, attachments, PEC/REM evidence) via IMAP/POP3/SMTP to servers you configure.
- Local archive:
.emlfiles and SQLite (mail.db), including optional on-device embedding index. Mail is not uploaded to MaksIT for hosting or advertising. - Account settings and secrets next to config (DPAPI on Windows; restrictive file mode on Linux/macOS) — passwords, Hub JWT / refresh token, mailbox tokens. Not stored in plaintext
settings.json. - Practice labels, rules, folder-store paths — local only.
You (or your organisation) are typically the controller of mailbox contents. MaksIT is controller only of Hub-held data described below and of support correspondence.
Identity Hub (Gmail and Microsoft 365)
Optional sign-in uses Identity Hub at https://identity.maks-it.com (covered application MaksIT.PostClient). Hub is a confidential OAuth client: products receive a Hub JWT, not raw IdP tokens. Mailbox access uses a short-lived mailbox token (XOAUTH2).
Hub processing (account identifiers, login audit, vaulted mailbox refresh tokens, cookies for the OAuth round-trip) is described in the Hub Privacy statement. Legal bases there include contract (Art. 6(1)(b)) and legitimate interests for security logs (Art. 6(1)(f)).
Google and Microsoft are independent controllers for their sign-in and mailbox APIs.
Other independent parties
- PEC/REM/IMAP operators (Aruba, InfoCert, Namirial, Poste, Google, Microsoft, custom hosts) process mail under their terms.
- Optional meaning index: model weights may download from Hugging Face (
onnx-community/embeddinggemma-300m-ONNX) when you enable that feature. Vectors stay inmail.db. Mail is not sent to Hugging Face as a product feature.
What we do not do
MaksIT does not read your messages for advertising, does not sell mail content, and does not operate a cloud mailbox. HTML display uses the OS web engine on the device.
Retention
Local mail until you delete folders, apply retention in Settings, or uninstall. Hub login audit and OTC periods are those published on the Hub privacy page (defaults: audit ~180 days, one-time codes minutes). Vaulted Hub mailbox refresh tokens until replaced or the identity is removed.
Your rights
Device data: delete archives, disconnect accounts, uninstall. Hub-held data: Hub privacy + privacy@maks-it.com. Revoke Google/Microsoft apps in those account settings. Complaint: Italian Data Protection Authority.
Product page: MaksIT.Postclient.