Protected credentials and optional diagnostics
In short
Mailbox passwords and tokens are encrypted by the operating system — Windows DPAPI on the PC, the Android Keystore on the phone — and are never sent to Mailamber. Anonymous crash reports are off by default and, if you turn them on, contain no emails, addresses or credentials.
Where are mailbox passwords stored?#
- On Windows with DPAPI, Windows’ encryption system tied to your user account: only your user, on that PC, can decrypt them.
- On Android in the Keystore, the phone’s secure storage, separate from the mail database.
The same goes for “Sign in with Microsoft” tokens. Credentials are used only to connect to your provider and are never sent to Mailamber’s servers.
What about my Mailamber account password?#
On the server we only keep a hash of it (argon2id), never the plain password. On the PC the app remembers your sign-in only if you choose “Stay signed in on this PC (otherwise you'll sign in at every launch)”, and even then the session is encrypted with DPAPI.
Are connections encrypted?#
Yes. Mailamber uses TLS with the IMAP and SMTP servers (ports 993/465) or mandatory STARTTLS (port 587), and verifies the server’s certificate. If the certificate isn’t valid, the connection is refused with “Problem with the server TLS certificate.”. The unencrypted option exists only for test servers.
What are crash reports?#
Anonymous crash reports is an option that’s off by default, on the PC in Settings → Privacy & security and on the phone in Settings. If you turn it on, when the app hits an error it sends a technical report (error type, message, app and system version) to our diagnostics service, which we host ourselves. Before sending, email addresses, file paths containing your username and personal data are removed; email content, credentials, screenshots and app memory are never sent.