This policy applies to the imail mobile apps published by MC Grup Toptan Gıda Teknoloji San. Tic. Ltd. Şti. — Android (package name: tr.com.imail.posta) and iOS (tr.com.imail.posta) — and explains what data the apps process and how. For the web services, the general Privacy Policy applies.
1. Data Collected and Processed
Account details: when you sign in, your email address and password are transmitted to our servers (encrypted with TLS). Your password is not stored on the device; a time-limited session token is stored instead.
Email, contacts and calendar data: by the nature of the service, your emails, contact records and calendar events are hosted on imail servers and moved between the app and the server over an encrypted connection. The app may temporarily cache message lists on your device for faster display.
Notification identifier: for push notifications (new mail), your device's Firebase Cloud Messaging (FCM) registration token is associated with your account on our server.
Preferences kept on the device: settings such as the app lock and calendar sync are stored only on your device.
2. Permissions
Notifications: used to show new mail notifications.
Calendar (optional): if you turn on "phone calendar sync", the app creates a calendar named "imail" on your device and manages only that calendar; other calendars on your device are never read or modified. If you turn the feature off, the imail calendar is removed from the device.
Contacts (optional): if you grant permission, contacts with an email address in your phone's address book are offered as suggestions while you write an email; this reading stays on your device and your address book is never sent to the server. Phone contacts are copied into your imail address book (on the server) only if you confirm it. Likewise, with your confirmation, your imail contacts can be written into your phone's address book under an "imail" account; if you turn that feature off, the imail contacts are removed from your address book (your own contacts are unaffected).
3. Sharing with Third Parties
Your data is never shared or sold to third parties for advertising or marketing. For push delivery, only the device registration token and the notification content (sender name and subject) are passed to Google Firebase Cloud Messaging. The app contains no advertising and no third-party marketing or tracking tools.
AI providers (only if you grant permission): if you enable the AI features described in section 5 below, only the content subject to that operation is transmitted to Google Gemini or NVIDIA. These features are off by default.
Crash reports (Android only): in the Android app, to improve stability, the device model, operating system version and the technical log at the time of a crash are sent to Google Firebase Crashlytics. These reports are not matched to your identity and never include your email content. The iOS app contains no crash reporting tool; on iOS, Firebase is used solely for push notifications (FCM).
4. Security
All network traffic is encrypted with TLS. Session tokens are stored hashed on the server side and invalidated when you sign out. Access to the app can additionally be protected with the optional biometric app lock.
5. AI Features (optional, off by default)
If your plan includes them, the app offers two AI features: translating incoming email into your language and a reply assistant that reviews the reply you have written. These features are off by default; they become available only when you grant permission by turning on the switch under Settings > AI inside the app. While the switch is off, the related buttons are hidden and none of your content is transmitted.
After you grant permission, content is transmitted only when you press Translate or AI, and only the content subject to that operation — the text of the email to be translated, or your reply draft together with the message you are replying to — is sent to the provider assigned to your plan (Google Gemini or NVIDIA) solely so the operation can be carried out. Your emails are not scanned in the background or processed in bulk; the content is not used for advertising and is not sold. Because these providers are located abroad, this constitutes a transfer outside Türkiye and relies on your explicit consent (KVKK art. 9). You can withdraw that consent from the same switch at any time; once withdrawn, the transfer stops entirely. Your grants and withdrawals are recorded together with their date. Your consent is tied to your account: the same switch applies to webmail and to the mobile apps. AI output can be wrong; no reply is ever sent automatically — you always approve the text before it goes out.
6. Data Retention and Deletion
When you sign out of the app, the session token and cache on the device are cleared and the session record on the server is invalidated. To have your account and your server-side data deleted entirely, write to info@mcgida.com; requests are handled within the periods set out in the legislation.
7. Children's Privacy
The app is intended for a general audience and does not knowingly collect data from children under 13.
8. Contact
For questions about this policy: info@mcgida.com