Cardinal

Privacy policy

Cardinal is an email client. Email is the most personal data most people own, so this page says exactly what happens to it — and to the far smaller amount of data this website sees.

Version 1.0 · In force since 2 August 2026

Status of this document

Cardinal has not been released yet. This policy describes two different things: the website you are reading, which exists and works exactly as described below, and the application, which is under development and is being built to the rules set out here. When the first public build ships, this page will be updated and the version number at the top will change.

Who is responsible

The controller for this website and for the Cardinal application, in the sense of Article 4(7) GDPR, is:

CODLAB UG (haftungsbeschränkt)
St.-Jakob-Straße 6
93161 Sinzing, Germany
Email: info@codlab.de

We have not appointed a data protection officer, because we are not required to under Article 37 GDPR. Write to the address above for anything concerning your data; a person reads it.

This website

This site runs no analytics, sets no measurement cookies, embeds no third-party scripts, and loads no fonts, icons or images from anyone else's servers. Opening a page here causes exactly one connection: to our own server. There is no consent banner because there is nothing to consent to.

Server logs

Like every web server, ours writes an access log. Each line contains the IP address of the connecting client, the date and time, the address requested, the HTTP status, the referring page if your browser sent one, and the browser identification string.

These logs exist to keep the server running and to notice attacks. They are rotated daily and deleted after 14 days. They are not used to build profiles, and they are never combined with any other data.

Legal basis: Article 6(1)(f) GDPR — our legitimate interest in operating a functioning, secure website.

Hosting

The site is hosted on servers operated by IONOS SE (Elgendorfer Straße 57, 56410 Montabaur, Germany) located in Germany. IONOS processes data on our instruction under a data processing agreement pursuant to Article 28 GDPR.

Cookies and local storage

This site sets no cookies at all. Not one — not for sessions, not for measurement, not from anybody else. That is why there is no cookie banner: there is nothing to ask you to allow. We verified it on the live site rather than assuming it.

One thing is stored on your device, and only if you ask for it: if you switch the site between the light and dark theme, that choice is written to your browser's local storage so the next page does not flip back on you. It is a single value, it never leaves your browser, and clearing your browsing data removes it.

Stored value Purpose When it is written
cardinal-theme Remembers whether you chose the light or the dark theme. Only when you press the theme button.

Legal basis: § 25(2) TDDDG — storage strictly necessary to provide the function you explicitly requested. The language you read in is not stored anywhere: it lives in the address of the page.

A few links point elsewhere: to PayPal if you decide to support the project, and to thunderbird.net and mozilla.org for the engine and the licence. These are ordinary links, not embedded widgets or scripts — nothing is loaded from those companies while you read this site, and they learn nothing about you unless you click.

If you do click through to PayPal, you are then on PayPal's site under PayPal's privacy policy, and the payment data you enter there is handled by them. We receive the amount, the date and the name and email address of the sender, because that is what a payment provider reports to the recipient. We use it to keep our books and for nothing else.

The Cardinal application

Cardinal is a desktop program built on the Thunderbird engine. It talks directly to your mail provider, the same way Thunderbird does. There is no Cardinal server in between.

Your messages, attachments, address book, calendars, account settings and passwords are stored in a profile folder on your own computer. We do not receive them, we cannot read them, and there is no account to create with us in order to use the program.

Two features are the only ones that can ever send anything outside your machine — the AI assistance and the diagnostics reports. Both are described below, and both are off until you switch them on.

Access to your Google account

If you add a Gmail account, Cardinal signs you in through Google's own OAuth screen. Your Google password is typed on Google's page and is never seen by Cardinal. What Cardinal receives is an access token, which is stored on your computer in the same protected store as your other account credentials.

What we request and why

Cardinal requests the Gmail scope (https://mail.google.com/) because that is what the underlying engine needs in order to read, write, send and organise your mail over IMAP and SMTP — the ordinary work of a mail client. Scopes for contacts or calendars are requested only if you add those services yourself, and only at that moment.

Limited Use

Cardinal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, and without exceptions:

  • Google user data is used only to provide the mail features you can see in the application.
  • It is not transferred to us or to anyone else, except where you explicitly direct it.
  • It is not used for advertising, profiling, or resale of any kind.
  • It is not used to train any machine learning or AI model, ours or anybody's.
  • No human at CodLab reads it. There is no mechanism by which we could.

Withdrawing access

You can revoke Cardinal's access at any time in your Google account under Security → Third-party apps, or by removing the account inside Cardinal, which deletes the stored token from your computer.

AI features

Cardinal can help you draft, summarise or translate a message. This is off by default and does nothing until you enter an API key for a provider you have chosen and pay for yourself.

  • The request goes from your computer straight to that provider. It does not pass through any server of ours.
  • What is sent is only the text you selected for the action you asked for — not your mailbox, not your address book, not your other messages.
  • The key is stored locally and is never transmitted to us.
  • What the provider then does with that text is governed by the contract between you and them, so choose one whose terms you accept.

Legal basis: Article 6(1)(a) GDPR — your consent, given by enabling the feature and triggering each action, withdrawable at any time by turning it off.

Diagnostics and crash reports

If you switch diagnostics on, Cardinal may send a report when something goes wrong: the version you run, your operating system and its version, the technical description of the error, and the sequence of internal steps that led to it.

A report never contains the content of your messages, your addresses, your attachments or your credentials. Reports are received and stored on a server in the European Union, are used solely to fix the defect, and are deleted after 90 days.

Legal basis: Article 6(1)(a) GDPR — your consent. The feature is off until you enable it, and turning it back off stops it immediately.

Processing Legal basis
Server access logs Art. 6(1)(f) — legitimate interest in a secure, functioning site
Theme preference in local storage § 25(2) TDDDG — strictly necessary for a function you requested
AI features Art. 6(1)(a) — consent
Diagnostics Art. 6(1)(a) — consent
Answering an email you send us Art. 6(1)(b) or (f) — replying to your request

How long anything is kept

  • Server access logs: 14 days, then deleted by rotation.
  • Diagnostic reports, if you enabled them: 90 days.
  • Correspondence you send us: as long as needed to deal with it, and for the retention periods German commercial and tax law imposes where they apply.
  • Everything else — your mail, your accounts, your keys — stays on your computer and is deleted when you delete it.

Your rights

Under the GDPR you have the right to obtain confirmation of what we process and a copy of it (Art. 15), to have it corrected (Art. 16), to have it erased (Art. 17), to have processing restricted (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on our legitimate interest (Art. 21). Where processing rests on your consent, you can withdraw it at any time with effect for the future (Art. 7(3)).

Write to info@codlab.de. We answer within one month, as the regulation requires. In practice the answer for most people is short, because the only thing we hold about a visitor is a log line that has usually already been deleted.

You also have the right to complain to a supervisory authority (Art. 77). The one responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.

Deleting your data

There is no account to close and no dashboard to hunt through. Concretely:

  • Uninstalling Cardinal and deleting its profile folder removes every message, account and key it held on your computer.
  • Revoking access in your Google account immediately invalidates the token Cardinal holds.
  • For diagnostic reports, or anything else you believe we hold, ask at info@codlab.de and we will delete it and confirm that we have.

Changes to this policy

We update this page when the product changes — most immediately with the first public release. The version and date at the top always say which text is in force. If a change ever widens what we process, we will say so plainly rather than quietly reissue the document.