Skip to content
Northstar Mailby TreeByte Software

Northstar Mail legal

Privacy without fine-print surprises.

This policy explains exactly what Northstar Mail accesses when you connect a Google account, why each permission is needed, what stays on your computer, and how to remove access.

Effective September 8, 2026

1. Scope and who we are

Northstar Mail is a Windows desktop email client developed by TreeByte Software. This policy applies to Northstar Mail and its Google account integration. TreeByte Software can be contacted at support@treebytesoftware.com.

Northstar is local-first. It connects directly from your PC to the provider APIs you authorize. TreeByte does not operate a Northstar mail relay, hosted mailbox, or cross-device content-sync service.

2. Google user data Northstar accesses

Northstar asks only for the permissions used by the features described below. Google displays and controls these permissions during sign-in.

Permissions are requested in stages. Initial Google sign-in requests identity access and Gmail access. Calendar and Contacts permissions are not part of that first connection. Northstar requests Calendar access only when you choose Grant access in Calendar, and Contacts access only when you choose Grant access in People. Approving one feature does not grant access to the other.
Account identityopenid · email · profile

Reads your Google account identifier, email address, and basic profile information so Northstar can identify and label the connected account.

Gmailgmail.modify

Downloads, displays, and searches mail; sends messages you compose; and applies the mail changes you request, such as read state, archiving, or moving messages to Trash.

Primary calendarcalendar.events.owned

Reads events and permits the event changes you request in calendars you own, including creating and editing events in the calendar view.

Contactscontacts

Reads contacts for the people view and permits contact changes you request, including creating contacts.

3. How Google user data is used

Northstar uses provider data only to provide features you request:

  • Identify and distinguish each Google account you connect.
  • Synchronize and display Gmail inbox messages in the desktop client.
  • Search messages that Northstar has made available to the client.
  • Send messages and synchronize mail changes you request.
  • Display calendar events and apply event changes you request.
  • Display contacts and apply contact changes you request.
  • Maintain the authorized connection in the background using an OAuth refresh token.

Google user data is not used to build advertising profiles, deliver ads, train artificial-intelligence or machine-learning models, score users, or create unrelated analytics products.

4. Local storage and security

Northstar loads and processes message, calendar, and contact content in the desktop app on your PC. That provider content is not uploaded to a TreeByte Northstar cloud service, and Google remains its system of record. Local account settings and protected OAuth credentials are stored in your Windows profile so the configured connection can continue to work.

Local data can persist between app sessions. Northstar uses an encrypted SQLite mailbox cache, locally protected saved compose drafts, and a persistent local semantic-search index to support its mail features. These local copies are not a TreeByte-hosted mailbox. Saved drafts are protected with Windows DPAPI; your Windows account and device protections also matter for local files and backups.

Northstar displays sanitized email content in a dedicated Microsoft WebView2 renderer profile stored in your Windows profile. When remote images are allowed, WebView2 may store image responses, HTTP cookies, and related site data locally between app sessions. This renderer data is used only to display messages and is not uploaded to TreeByte.

Google OAuth access and refresh tokens are encrypted locally with the Windows Data Protection API (DPAPI), tied to your Windows user. Network requests to Google use HTTPS. Your device security, Windows account, disk protection, backups, and other software can also affect the security of locally stored data.

TreeByte personnel cannot browse your Google provider content through a Northstar server because no such content service exists. If you choose to include personal or message information in a support email, that copy is treated as support correspondence rather than automatic app telemetry.

5. Remote images and message tracking

Email messages can contain images hosted by the sender or another third party. Northstar lets you decide whether to load those remote images. If you load them, your PC requests each image directly from its remote host; the request is not proxied through a TreeByte image server.

The remote host can receive information normally included in a web request, such as your IP address, request time, browser-engine information, and any unique tracking identifier embedded in the image URL. This can allow a sender or image provider to infer that a message was viewed. You can keep remote images blocked, and Northstar can remember your image-loading preference.

Subject to WebView2's browser rules, an image host may set or receive cookies, and Northstar may reuse a cached image. Cookies, cached responses, and identifiers in image URLs can let a host correlate views across messages or connected accounts. When any configured account is removed, Northstar clears the shared renderer's cookies, site data, browsing history, and disk cache. If cleanup cannot finish immediately, remote images remain blocked and Northstar retries the cleanup before loading them again.

6. Sharing, advertising, and Google Limited Use

Google API Limited Use disclosure. Northstar Mail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

TreeByte does not sell, rent, or trade Google user data. Northstar does not transfer Gmail content, calendar events, contacts, or OAuth tokens to advertising networks, data brokers, or analytics vendors. That data is not used for personalized or non-personalized advertising.

A remote-image request you explicitly allow is a direct connection from your PC to the sender's or image host's URL, as described above. It is user-controlled message rendering, not a transfer by TreeByte to a TreeByte advertising or analytics vendor.

We may disclose information only when required by applicable law or when necessary to investigate a concrete security threat. Because Northstar processes provider data locally instead of routing it through a TreeByte content service, TreeByte ordinarily does not possess that provider content to disclose.

7. Retention and deletion

Mail, calendar, and contact content is processed locally, with the persistent mail cache, saved drafts, and search data described above. Removing an account clears its local account record, protected credentials, mailbox cache, and in-memory mail, calendar, and contact data, and queues removal of that account's persistent search data. Northstar also clears shared email-renderer browsing data. This can discard cached remote images for other connected accounts, but it does not remove or change those accounts. It does not delete mail, events, or contacts retained by Google.

Saved compose drafts may remain separately until you discard or delete them. Account removal is not a promise to erase all app files or device backups. Remove unwanted saved drafts separately and manage backups through your Windows or backup-provider controls.

Removing a local Northstar account and revoking a Google authorization are separate actions. To withdraw the Google grant, open Google Account third-party connections, select Northstar Mail, and remove its access. Revocation prevents the stored grant from being used again; remove the account in Northstar as well to clear the local account record and protected credentials.

TreeByte does not maintain a hosted Northstar mailbox account or cloud copy of your Google content. For help removing local data or support correspondence you sent voluntarily, follow the data-deletion instructions.

8. Your choices and controls

  • Connecting a Google account is optional.
  • You choose which account to connect through Google's sign-in screen.
  • You can remove a configured account from Northstar at any time.
  • You can revoke Northstar's Google grant from your Google Account.
  • You control Windows account access, device backups, and disk protection.

9. Website logs, children, and policy changes

The public TreeByte website may generate ordinary hosting and security logs such as IP address, browser type, request time, and error information. Those website logs do not contain the Gmail, calendar, contacts, or OAuth data stored by Northstar on your PC.

Northstar is not directed to children under 13, and TreeByte does not knowingly collect children's Google user data through a Northstar cloud service. We may revise this policy as the product or legal requirements change. The effective date at the top identifies the current version.

10. Contact

Questions about Northstar privacy, permissions, or local data deletion can be sent to support@treebytesoftware.com. Please do not include email content or OAuth credentials in your request.