Privacy Policy
Vireo is a free, open-source email client that runs on your own device. This policy explains what information Vireo handles, how it is used, and the choices you have. It applies to the Vireo desktop application and to this website, vireo.hyprlab.co. Vireo is developed by Hyprlab (“we,” “us”).
The short version
- Vireo runs locally on your device and talks directly to your email providers.
- We operate no servers that receive, store, or process your email or account data.
- We collect zero telemetry — no analytics, tracking, or usage reporting.
- Your credentials and access tokens are stored on your device in your operating system’s secure keyring.
- We do not sell, rent, or share your data with anyone.
Information Vireo accesses
To function as an email client, Vireo accesses the email accounts you choose to connect. Depending on how you sign in, this may include:
- Account credentials or OAuth tokens — used to authenticate with your email provider (for example, via Google or Microsoft OAuth, or an IMAP/SMTP username and password).
- Your email content and metadata — messages, folders, contacts you correspond with, attachments, and message flags — so Vireo can display, search, compose, send, and organize your mail.
Vireo requests only the access needed to send and receive your email on your behalf. This information is read from, and written to, your email provider directly by the app on your device.
How Vireo uses this information
Information is used solely to provide email functionality that you initiate — retrieving and displaying your mail, sending messages you compose, and keeping folders in sync. It is never used for advertising, profiling, or any purpose unrelated to operating your mailbox.
Google user data
If you connect a Google account, Vireo uses Google OAuth to obtain access to your Gmail mailbox (IMAP/SMTP) so it can display and send your mail. Vireo accesses this data only on your device and only to provide the app’s email features at your direction.
Limited Use disclosure. Vireo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Vireo does not transfer or sell Google user data, and does not use it for advertising or any purpose other than providing the email client’s user-facing features.
How your data is stored
- Credentials and OAuth tokens are stored in your operating system’s secret service / keyring, not in plaintext on disk.
- Cached mail (folders, message summaries, and bodies) is stored locally on your device to enable fast startup and offline reading.
- None of this data is transmitted to us or to any third party. It stays between your device and your email provider.
Sharing and disclosure
We do not receive your email or account data, so we have nothing to sell or share. Vireo does not send your data to any third party. Your email naturally travels between your device and the email and identity providers you choose to use (such as Google or Microsoft), whose own privacy policies govern their handling of it.
Data retention and deletion
Because your data lives on your device, you are in control of it:
- Remove an account in Vireo to delete its stored credentials and cached mail from your device.
- Uninstalling Vireo removes its locally cached data.
- You can revoke Vireo’s access to a Google account at any time from your Google Account permissions page (and the equivalent settings for other providers).
Telemetry
Vireo collects no analytics, no usage statistics, and no crash telemetry. The app does not phone home.
Children’s privacy
Vireo is not directed to children under the age of 13, and we do not knowingly collect personal information from them.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with a revised “Last updated” date.
Contact
Questions about this policy or your privacy? Email [email protected].