# Vantage Aegis Mail Data Use Notice

**Version:** 1.2.4  
**Effective date:** July 28, 2026

## What Aegis Mail connects to

- Gmail and Google Workspace use browser-based OAuth 2.0 with PKCE and the read-only Gmail API scope `https://www.googleapis.com/auth/gmail.readonly`.
- Outlook and Microsoft 365 use browser-based OAuth 2.0 with PKCE and delegated Microsoft Graph permissions `User.Read`, `Mail.Read`, and `offline_access`.
- Yahoo Mail, iCloud Mail, Fastmail, and custom accounts use strict TLS IMAP with an app-specific password when required by the provider.

Aegis does not request permission to send, delete, archive, label, or modify mail through its Gmail or Microsoft connection.

## Data handled on the device

Vantage stores the connected account identity, provider, synchronization status, and encrypted authorization material in local application state. OAuth access and refresh tokens and advanced IMAP app passwords are protected using operating-system credential protection where available. They are excluded from Vantage projects, Marketplace requests, connected AI context, and Continuity transfers.

Recent messages requested by the user are parsed locally. Remote images are blocked by default, scripts and active HTML are not executed, attachments are not opened automatically, and extracted links are inspected by Threat Ledger before opening.

## Provider processing

Google, Microsoft, Yahoo, Apple, Fastmail, or the selected custom provider processes sign-in and mailbox traffic under that provider’s own terms and privacy policies. Ordinary network metadata is visible to the provider and network intermediaries as required to complete the connection.

## Disconnecting and deleting

Removing an account from Aegis deletes its locally stored account authorization and requests token revocation when the configured provider supports it. Removing the account does not delete messages at the provider. Messages already imported into Vantage, synchronized folders, backups, or exported files remain until the user deletes those copies.

## Publisher configuration

Google and Microsoft require That1Dev to register public desktop OAuth applications before release. The public client identifiers are embedded in the installer; no provider client secret is embedded. End users do not configure an OAuth application, token, endpoint, or redirect URI.

## Contact

Privacy and account-removal questions: **cbusinessact@proton.me**
