openid · email · profileReads your Google account identifier, email address, and basic profile information so Northstar can identify and label the connected account.
Northstar Mail legal
This policy explains exactly what Northstar Mail accesses when you connect a Google account, why each permission is needed, what stays on your computer, and how to remove access.
Effective July 26, 2026
Northstar Mail is a Windows desktop email client developed by TreeByte Software. This policy applies to Northstar Mail and its Google account integration. TreeByte Software can be contacted at support@treebytesoftware.com.
Northstar is local-first. It connects directly from your PC to the provider APIs you authorize. TreeByte does not operate a Northstar mail relay, hosted mailbox, or cross-device content-sync service.
Northstar asks only for the permissions used by the features described below. Google displays and controls these permissions during sign-in.
Northstar uses provider data only to provide features you request:
Google user data is not used to build advertising profiles, deliver ads, train artificial-intelligence or machine-learning models, score users, or create unrelated analytics products.
Northstar loads and processes message, calendar, and contact content in the desktop app on your PC. That provider content is not uploaded to a TreeByte Northstar cloud service, and Google remains its system of record. Local account settings and protected OAuth credentials are stored in your Windows profile so the configured connection can continue to work.
Northstar displays sanitized email content in a dedicated Microsoft WebView2 renderer profile stored in your Windows profile. When remote images are allowed, WebView2 may store image responses, HTTP cookies, and related site data locally between app sessions. This renderer data is used only to display messages and is not uploaded to TreeByte.
Google OAuth access and refresh tokens are encrypted locally with the Windows Data Protection API (DPAPI), tied to your Windows user. Network requests to Google use HTTPS. Your device security, Windows account, disk protection, backups, and other software can also affect the security of locally stored data.
TreeByte personnel cannot browse your Google provider content through a Northstar server because no such content service exists. If you choose to include personal or message information in a support email, that copy is treated as support correspondence rather than automatic app telemetry.
Email messages can contain images hosted by the sender or another third party. Northstar lets you decide whether to load those remote images. If you load them, your PC requests each image directly from its remote host; the request is not proxied through a TreeByte image server.
The remote host can receive information normally included in a web request, such as your IP address, request time, browser-engine information, and any unique tracking identifier embedded in the image URL. This can allow a sender or image provider to infer that a message was viewed. You can keep remote images blocked, and Northstar can remember your image-loading preference.
Subject to WebView2's browser rules, an image host may set or receive cookies, and Northstar may reuse a cached image. Cookies, cached responses, and identifiers in image URLs can let a host correlate views across messages or connected accounts. When any configured account is removed, Northstar clears the shared renderer's cookies, site data, browsing history, and disk cache. If cleanup cannot finish immediately, remote images remain blocked and Northstar retries the cleanup before loading them again.
TreeByte does not sell, rent, or trade Google user data. Northstar does not transfer Gmail content, calendar events, contacts, or OAuth tokens to advertising networks, data brokers, or analytics vendors. That data is not used for personalized or non-personalized advertising.
A remote-image request you explicitly allow is a direct connection from your PC to the sender's or image host's URL, as described above. It is user-controlled message rendering, not a transfer by TreeByte to a TreeByte advertising or analytics vendor.
We may disclose information only when required by applicable law or when necessary to investigate a concrete security threat. Because Northstar processes provider data locally instead of routing it through a TreeByte content service, TreeByte ordinarily does not possess that provider content to disclose.
Mail, calendar, and contact collections are held in the running app as needed to present Northstar's features. Removing an account clears its locally stored account record, protected credentials, and in-memory mail, calendar, and contact data. Northstar also clears the shared email-renderer browsing data described above. This can discard cached remote images for other connected accounts, but it does not remove or change those accounts. It does not delete mail, events, or contacts retained by Google.
Removing a local Northstar account and revoking a Google authorization are separate actions. To withdraw the Google grant, open Google Account third-party connections, select Northstar Mail, and remove its access. Revocation prevents the stored grant from being used again; remove the account in Northstar as well to clear the local account record and protected credentials.
TreeByte does not maintain a hosted Northstar mailbox account or cloud copy of your Google content. For help removing local data or support correspondence you sent voluntarily, follow the data-deletion instructions.
The public TreeByte website may generate ordinary hosting and security logs such as IP address, browser type, request time, and error information. Those website logs do not contain the Gmail, calendar, contacts, or OAuth data stored by Northstar on your PC.
Northstar is not directed to children under 13, and TreeByte does not knowingly collect children's Google user data through a Northstar cloud service. We may revise this policy as the product or legal requirements change. The effective date at the top identifies the current version.
Questions about Northstar privacy, permissions, or local data deletion can be sent to support@treebytesoftware.com. Please do not include email content or OAuth credentials in your request.