Zum Inhalt springen
SmartInboxPilot
FunktionenPrivatsphäreSupportAnrufen

SmartInboxPilot · Rechtliches

Datenschutzerklärung – SmartInboxPilot

DeutschEnglish
RECHTLICHESWebsite-DatenschutzApp-DatenschutzNutzungsbedingungenImpressumSupport

Stand: 23. Juli 2026

Diese Datenschutzerklärung gilt für die macOS-App SmartInboxPilot.

1. Verantwortlicher

Verantwortlich für die Datenverarbeitung im Zusammenhang mit dieser App im Sinne der Datenschutz-Grundverordnung (DSGVO) ist:

SeaSparks GmbH
Kirchenweg 1
20099 Hamburg
Deutschland

Vertreten durch die Geschäftsführer: Dominik Gorsler, Dr. Philipp Hägler
Telefon: +49 (40) 24859333
E-Mail: privacy@smartinboxpilot.com

Es ist derzeit kein Datenschutzbeauftragter benannt.

2. Grundsatz: local-first

SmartInboxPilot ist ein local-first E-Mail-Programm. Deine E-Mails, Konten, Einstellungen und lokalen Diagnoseprotokolle werden grundsätzlich auf deinem Mac verarbeitet und gespeichert.

  • SeaSparks betreibt keinen SmartInboxPilot-Server für Mail-Inhalte.
  • Es gibt kein zentrales SmartInboxPilot-Nutzerkonto bei SeaSparks.
  • Die App enthält kein Tracking, keine Telemetrie, keine Nutzungsanalyse und keine Werbung.

3. Welche Daten lokal auf deinem Gerät verarbeitet werden

DatenZweckSpeicherung
Zugangsdaten deiner E-Mail-Konten, insbesondere Passwörter oder App-PasswörterVerbindung zu deinem Mail-Anbieterim macOS-Schlüsselbund
E-Mail-Inhalte, Metadaten und AnhängeAnzeige, Suche, Offline-Zugriff, lokale Verarbeitunglokal verschlüsselte Datenbank (SQLCipher)
Einstellungen, Favoriten, Triage-Daten und AnsichtsoptionenNutzung der Applokal verschlüsselte Datenbank
Diagnose- und Absturzprotokollelokale Fehleranalyselokal auf deinem Gerät

Diese Daten werden nicht an SeaSparks übertragen, solange du sie nicht aktiv an uns sendest.

4. Netzwerkverbindungen und Empfänger

Damit SmartInboxPilot funktioniert, verbindet sich die App mit Diensten, die du selbst nutzt oder auswählst:

  1. Dein E-Mail-Anbieter (IMAP/SMTP)
    Zum Abrufen und Senden von Nachrichten verbindet sich die App direkt mit den Servern deines Anbieters. Welche Daten dort verarbeitet werden, richtet sich nach den Datenschutzbestimmungen deines Anbieters.
  2. Automatische Server-Erkennung
    Wenn du ein Konto einrichtest und die automatische Erkennung verwendest, kann die Domain deiner E-Mail-Adresse an einen Autoconfig-Dienst übermittelt werden, etwa an autoconfig.thunderbird.net oder autoconfig.<deine-domain>. Zusätzlich werden DNS-Abfragen über einen DNS-over-HTTPS-Anbieter durchgeführt, primär Cloudflare und ersatzweise Google. Führen diese Schritte zu keinem Ergebnis, wird zur Erkennung von Microsoft-365-Konten abschließend eine Abfrage an login.microsoftonline.com (Microsoft) gesendet. Bei allen genannten Schritten wird ausschließlich die Domain deiner E-Mail-Adresse übertragen – keine E-Mail-Inhalte und keine Zugangsdaten.
  3. Externe Inhalte in E-Mails
    Externe Bilder und Schriften in HTML-Mails werden standardmäßig blockiert. Wenn du das Nachladen ausdrücklich erlaubst, ruft die App die jeweilige Ressource direkt vom Fremdserver ab.
  4. Apple App Store / TestFlight
    Download, Kauf, Wiederherstellung, Updates und TestFlight-Bereitstellung laufen über Apple. Dabei verarbeitet Apple Daten nach seinen eigenen Datenschutzbestimmungen.

4.1 Anmeldung mit Microsoft (OAuth)

Verbindest du ein Microsoft-Konto (z. B. outlook.com, Hotmail, Live oder Microsoft 365), erfolgt die Anmeldung über das offizielle Microsoft-Login im Browser (OAuth 2.0). Ein Passwort wird dabei nicht in SmartInboxPilot eingegeben oder gespeichert; die Anmeldung erfolgt ausschließlich über OAuth.

  • Was gespeichert wird: ein von Microsoft ausgestelltes Zugriffs- und Auffrischungs-Token (statt eines Passworts). Diese Token liegen ausschließlich lokal in der macOS-Schlüsselbundverwaltung bzw. der verschlüsselten lokalen Datenbank; SeaSparks hat keinen Zugriff darauf.
  • Welche Berechtigungen: SmartInboxPilot fordert nur die minimal nötigen Rechte an – Postfachzugriff und Versand über die Microsoft Graph Mail API (https://graph.microsoft.com/Mail.ReadWrite, https://graph.microsoft.com/Mail.Send) und das Auffrischen der Anmeldung (offline_access). Ein darüberhinausgehender Zugriff auf dein Microsoft-Konto erfolgt nicht.
  • Wozu: ausschließlich, um deine Mails abzurufen und zu senden – wie bei einem klassischen Mailkonto. Die Analyse deiner Mails (Sortierung, Priorisierung, Antwortentwürfe) läuft lokal auf deinem Gerät; siehe Abschnitt 5.
  • Widerruf: Du kannst die Verbindung jederzeit beenden, indem du das Konto in der App entfernst und die Berechtigung von SmartInboxPilot in deinem Microsoft-Konto entziehst: für persönliche Microsoft-Konten unter https://account.live.com/consent/Manage, für Arbeits- oder Schulkonten unter https://myapps.microsoft.com.
  • Löschung: Entfernst du das Konto in der App, werden die Token und alle kontobezogenen lokalen Daten gelöscht (siehe Abschnitt 8).

5. KI-Funktionen

SmartInboxPilot kann optional KI-Funktionen für Antwortentwürfe, Textverbesserungen, Korrekturen, To-do-Beschreibungen und Klassifikationen bereitstellen.

  • Standardmäßig und bevorzugt laufen diese KI-Funktionen ausschließlich on-device über Apple Intelligence. Inhalte verlassen dafür nicht dein Gerät.
  • Die KI-Funktionen sind standardmäßig deaktiviert und müssen von dir aktiv eingeschaltet werden.
  • Lokale Lernmodelle: Die automatische Einsortierung (Zielordner), die Erkennung „Antwort erwartet", die Phishing- und die To-do-Einstufung lernen ausschließlich aus deinen eigenen Mails auf deinem Gerät. Diese Modelle verlassen dein Gerät nie, werden nicht mit anderen Nutzern zusammengeführt und mit dem Konto gelöscht. SeaSparks verwendet deine Mailinhalte nicht zum Training eigener oder fremder Modelle und beauftragt hierfür keine Unterauftragnehmer. Dies gilt auch für Postfächer, die du per Microsoft-Login verbindest.

5.1 Optionale Cloud-KI mit eigenem API-Schlüssel

Wenn dein Gerät die on-device-KI nicht unterstützt, kannst du optional einen eigenen, von dir gewählten KI-Dienst („Bring your own key") einrichten. Diese Funktion ist standardmäßig aus und wird nur wirksam, wenn du sie ausdrücklich aktivierst und dabei einen gesonderten Hinweis bestätigst.

  • Was übermittelt wird: Wenn du eine Cloud-KI-Aktion ausdrücklich auslöst (z. B. „Zusammenfassung erzeugen", „Antwort erzeugen" oder „Antwort korrigieren"), werden die für diese Aktion ausgewählten Inhalte der Nachricht (z. B. Betreff, Nachrichtentext, Thread-Verlauf) an den von dir konfigurierten Endpunkt gesendet, damit dieser den KI-Text erzeugt.
  • An wen: an den KI-Anbieter, dessen Endpunkt-Adresse und API-Schlüssel du selbst hinterlegst. Du gehst dieses Verhältnis direkt mit dem von dir gewählten Anbieter ein; es gelten dessen Vertrags- und Datenschutzbedingungen. Die Verbindung wird unmittelbar von deinem Gerät zu diesem Endpunkt hergestellt. SeaSparks betreibt für die Cloud-KI keinen eigenen Server, verwendet keinen Standardanbieter und leitet keine Inhalte über eigene Systeme.
  • Rechtsgrundlage: Deine ausdrückliche Einwilligung (Art. 6 Abs. 1 lit. a DSGVO), die du jederzeit durch Deaktivieren der Funktion in den Einstellungen widerrufen kannst.
  • Kein Zugriff von SeaSparks: Dein API-Schlüssel wird ausschließlich lokal in der macOS-Schlüsselbundverwaltung gespeichert und nicht an SeaSparks übertragen. SeaSparks erhält weder den Schlüssel noch die übermittelten Inhalte.

6. Wenn du uns kontaktierst

Wenn du uns per E-Mail kontaktierst oder uns freiwillig Diagnoseprotokolle, Screenshots oder sonstige Informationen sendest, verarbeiten wir die von dir übermittelten Daten, um dein Anliegen zu bearbeiten.

Das betrifft insbesondere:

  • Kontaktdaten wie Name und E-Mail-Adresse
  • Inhalt deiner Nachricht
  • freiwillig gesendete technische Informationen oder Log-Dateien

Bitte beachte: Von dir übermittelte Log-Dateien oder Screenshots können je nach Einzelfall auch personenbezogene Daten oder Ausschnitte lokaler Inhalte enthalten, etwa E-Mail-Adressen, Betreffzeilen oder technische Metadaten. Du entscheidest selbst, was du uns sendest.

7. Rechtsgrundlagen

Soweit überhaupt eine Verarbeitung personenbezogener Daten durch SeaSparks stattfindet, stützen wir sie auf folgende Rechtsgrundlagen:

  • Art. 6 Abs. 1 lit. b DSGVO, soweit die Verarbeitung zur Bearbeitung eines von dir angeforderten Support- oder Vertragsanliegens erforderlich ist
  • Art. 6 Abs. 1 lit. f DSGVO, soweit die Verarbeitung unserem berechtigten Interesse an einer funktionsfähigen, sicheren und supportfähigen Software dient
  • Art. 6 Abs. 1 lit. c DSGVO, soweit gesetzliche Aufbewahrungspflichten bestehen

Für die rein lokale Verarbeitung auf deinem Gerät empfangen wir grundsätzlich keine Daten.

8. Speicherdauer und Löschung

  • Lokale App-Daten bleiben auf deinem Gerät, bis du sie selbst löschst.
  • Wenn du ein Konto in der App entfernst, werden der lokale Zwischenspeicher, Einstellungen und zugehörige Schlüsselbund-Einträge auf deinem Gerät entfernt.
  • Beim bloßen Löschen von SmartInboxPilot.app werden lokale Daten und Schlüsselbund-Einträge nicht automatisch vollständig entfernt.
  • Kontakt- und Supportdaten, die du uns aktiv sendest, speichern wir nur so lange, wie es zur Bearbeitung deines Anliegens und zur Erfüllung gesetzlicher Pflichten erforderlich ist.

9. Deine Rechte

Dir stehen nach der DSGVO grundsätzlich die Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch zu. Außerdem hast du das Recht, dich bei einer Datenschutz-Aufsichtsbehörde zu beschweren.

Soweit Daten ausschließlich lokal auf deinem Gerät oder bei deinem Mail-Anbieter liegen, können wir dazu in der Regel keine inhaltliche Auskunft erteilen, weil wir diese Daten nicht bei uns speichern. Das gilt nicht für Daten, die du uns aktiv im Rahmen von Support- oder Kontaktanfragen übermittelst.

10. Datenübermittlung in Drittländer

SeaSparks übermittelt im Rahmen des normalen local-first-App-Betriebs keine personenbezogenen Mail-Inhalte in Drittländer.

Allerdings können im Rahmen der von dir genutzten Infrastruktur Drittlandbezüge entstehen:

  • bei deinem Mail-Anbieter
  • bei Apple
  • bei den genannten Autoconfig-, DNS-over-HTTPS- und Microsoft-365-Erkennungsdiensten
  • bei E-Mail-Kommunikation mit uns über die jeweiligen Mail-Anbieter
  • bei dem von dir selbst eingerichteten Cloud-KI-Anbieter (Abschnitt 5.1), falls dieser seinen Sitz oder seine Server in einem Drittland hat. Die direkte Verbindung zu diesem Anbieter stellst du mit deinem eigenen API-Schlüssel von deinem Gerät her. SeaSparks wählt weder den Anbieter noch dessen Standort und übermittelt keine Inhalte über eigene Systeme. Informationen über die Verarbeitung und mögliche Drittlandübermittlungen dieses Anbieters findest du in dessen Datenschutzinformationen.

Zur Transparenz: Die in Abschnitt 4 genannten Dienste Mozilla ISPDB, Cloudflare, Google und Microsoft werden von Anbietern mit Sitz in den USA betrieben. Bei der automatischen Server-Erkennung wird dabei nur die Domain deiner E-Mail-Adresse übermittelt, nicht die vollständige E-Mail-Adresse und nicht der Inhalt deiner Nachrichten.

11. Änderungen dieser Datenschutzerklärung

Wir passen diese Datenschutzerklärung an, wenn sich die App oder die rechtlichen Rahmenbedingungen ändern. Maßgeblich ist die jeweils veröffentlichte Fassung mit Datum.

12. Kontakt

Fragen zum Datenschutz kannst du an privacy@smartinboxpilot.com richten.

Last updated: 23 July 2026

This Privacy Policy applies to the macOS app SmartInboxPilot.

1. Controller

The controller responsible for data processing in connection with this app within the meaning of the General Data Protection Regulation (GDPR) is:

SeaSparks GmbH
Kirchenweg 1
20099 Hamburg
Germany

Represented by the managing directors: Dominik Gorsler, Dr. Philipp Hägler
Phone: +49 (40) 24859333
E-mail: privacy@smartinboxpilot.com

No data protection officer has currently been appointed.

2. Principle: local-first

SmartInboxPilot is a local-first e-mail application. Your e-mails, accounts, settings and local diagnostic logs are generally processed and stored on your Mac.

  • SeaSparks does not operate a SmartInboxPilot server for mail content.
  • There is no central SmartInboxPilot user account with SeaSparks.
  • The app contains no tracking, telemetry, usage analytics or advertising.

3. Which data is processed locally on your device

DataPurposeStorage
Credentials for your e-mail accounts, in particular passwords or app passwordsconnecting to your mail providerin the macOS Keychain
E-mail content, metadata and attachmentsdisplay, search, offline access, local processinglocally encrypted database (SQLCipher)
Settings, favourites, triage data and view optionsusing the applocally encrypted database
Diagnostic and crash logslocal troubleshootinglocally on your device

This data is not transmitted to SeaSparks unless you actively send it to us.

4. Network connections and recipients

For SmartInboxPilot to work, the app connects to services that you use or choose yourself:

  1. Your e-mail provider (IMAP/SMTP)
    To retrieve and send messages, the app connects directly to your provider's servers. What data is processed there is governed by your provider's privacy policy.
  2. Automatic server detection
    If you use automatic detection when setting up an account, the domain of your e-mail address may be sent to an autoconfig service such as autoconfig.thunderbird.net or autoconfig.<your-domain>. In addition, DNS lookups are performed via a DNS-over-HTTPS provider, primarily Cloudflare and Google as a fallback. If these steps yield no result, a final query is sent to login.microsoftonline.com (Microsoft) to detect Microsoft 365 accounts. In all of these steps only the domain of your e-mail address is transmitted — no e-mail content and no credentials.
  3. External content in e-mails
    External images and fonts in HTML e-mails are blocked by default. If you explicitly allow loading them, the app retrieves the respective resource directly from the third-party server.
  4. Apple App Store / TestFlight
    Download, purchase, restore, updates and TestFlight distribution are handled by Apple. Apple processes data under its own privacy terms.

4.1 Sign in with Microsoft (OAuth)

If you connect a Microsoft account (e.g. outlook.com, Hotmail, Live or Microsoft 365), sign-in happens through Microsoft's official browser login (OAuth 2.0). You do not enter or store a password in SmartInboxPilot; sign-in uses OAuth only.

  • What is stored: an access and refresh token issued by Microsoft (instead of a password). These tokens live locally only, in the macOS keychain or the encrypted local database; SeaSparks has no access to them.
  • Which permissions: SmartInboxPilot requests only the minimum needed — mailbox access and sending over the Microsoft Graph Mail API (https://graph.microsoft.com/Mail.ReadWrite, https://graph.microsoft.com/Mail.Send) and refreshing the sign-in (offline_access). No further access to your Microsoft account takes place.
  • Purpose: solely to retrieve and send your mail, like a classic mail account. Analysis of your mail (sorting, prioritising, reply drafts) runs locally on your device; see section 5.
  • Revocation: you can end the connection at any time by removing the account in the app and revoking SmartInboxPilot's permission in your Microsoft account: for a personal Microsoft account at https://account.live.com/consent/Manage, or for a work or school account at https://myapps.microsoft.com.
  • Deletion: removing the account in the app deletes the tokens and all account-related local data (see section 8).

5. AI features

SmartInboxPilot can optionally provide AI features for reply drafts, text improvement, corrections, to-do descriptions and classifications.

  • By default, these AI features run entirely on-device using Apple Intelligence.
  • No content leaves your device for this processing unless you explicitly enable the optional cloud-AI path described in section 5.1.
  • AI features are off by default and must be enabled by you.
  • Local learning models: automatic filing (target folder), the "reply expected", phishing and to-do classifications learn exclusively from your own mail on your device. These models never leave your device, are never merged with other users, and are deleted together with the account. SeaSparks does not use your mail content to train its own or third-party models and engages no processors for this. This also applies to mailboxes you connect via Microsoft sign-in.

5.1 Optional cloud AI with your own API key

If your device does not support on-device AI, you may optionally configure an AI service of your own choice ("bring your own key"). This feature is off by default and only takes effect after you actively enable it and confirm a separate notice.

  • What is transmitted: when you expressly trigger a cloud-AI action (for example, “Generate summary”, “Generate reply” or “Improve reply”), the content selected for that action (for example, subject, message text and thread history) is sent to the endpoint you configure to generate the AI text.
  • Recipient: the AI provider whose endpoint address and API key you enter. You enter into this relationship directly with the provider you choose; its contractual and privacy terms apply. The connection is established directly from your device to that endpoint. SeaSparks operates no server for cloud AI, uses no default provider and does not route content through its own systems.
  • Legal basis: your explicit consent under Art. 6(1)(a) GDPR, which you may withdraw at any time by disabling the feature in Settings.
  • No SeaSparks access: your API key is stored only in the macOS Keychain and is not transmitted to SeaSparks. SeaSparks receives neither the key nor the transmitted content.

6. If you contact us

If you contact us by e-mail or voluntarily send us diagnostic logs, screenshots or other information, we process the data you submit in order to handle your request.

This may include:

  • contact data such as your name and e-mail address
  • the content of your message
  • technical information or log files that you voluntarily send

Please note that log files or screenshots you send may, depending on the case, also contain personal data or excerpts of local content, such as e-mail addresses, subject lines or technical metadata. You decide what you send us.

7. Legal bases

To the extent SeaSparks processes personal data at all, we rely on the following legal bases:

  • Art. 6(1)(b) GDPR, where processing is necessary to handle a support or contractual request you asked us to handle
  • Art. 6(1)(f) GDPR, where processing serves our legitimate interest in a functional, secure and supportable software product
  • Art. 6(1)(c) GDPR, where statutory retention obligations apply

For the purely local processing on your device, we generally do not receive the data ourselves.

8. Storage duration and deletion

  • Local app data remains on your device until you delete it yourself.
  • If you remove an account in the app, the local cache, settings and related Keychain entries are removed on your device.
  • Simply deleting SmartInboxPilot.app does not automatically remove all local data or Keychain entries.
  • Contact and support data that you actively send to us is stored only for as long as necessary to handle your request and comply with legal obligations.

9. Your rights

Under the GDPR, you generally have rights of access, rectification, erasure, restriction of processing, data portability and objection. You also have the right to lodge a complaint with a data protection supervisory authority.

Where data exists only locally on your device or with your mail provider, we generally cannot provide substantive access to that data because we do not store it ourselves. This does not apply to data you actively send to us in the course of support or contact requests.

10. Transfers to third countries

SeaSparks does not transfer personal mail content to third countries as part of the normal local-first operation of the app.

However, third-country aspects may arise through infrastructure that you use:

  • your mail provider
  • Apple
  • the autoconfig, DNS-over-HTTPS and Microsoft 365 detection services named above
  • e-mail communication with us through the respective mail providers
  • the cloud-AI provider you personally configure (section 5.1), if that provider is established in, or processes data in, a third country. You establish the direct connection to that provider from your device with your own API key. SeaSparks neither chooses the provider nor its location and does not transmit content through its own systems. Refer to that provider's privacy information for its processing and potential third-country transfers.

For transparency: the Mozilla ISPDB, Cloudflare, Google and Microsoft services named in Section 4 are operated by providers based in the United States. During automatic server detection, only the domain of your e-mail address is transmitted, not the full e-mail address and not the content of your messages.

11. Changes to this Privacy Policy

We will update this Privacy Policy if the app or the legal framework changes. The version published with its date is the controlling version.

12. Contact

Privacy questions can be sent to privacy@smartinboxpilot.com.

Maßgeblich ist die jeweils veröffentlichte Fassung mit dem angegebenen Stand.

© SeaSparks GmbHWebsite-DatenschutzSecurity.txt