IzoMailer Privacy Policy
Effective date: 10 October 2026
IzoMailer is an email app for Android and Linux. This policy explains what happens to your data when you use the app and, if you choose to connect it, the optional Tasks service.
Short version: your email goes only between your device and your own email provider. We never receive it. The app has no ads, no analytics and no tracking. Only if you connect the optional Tasks service does the app send data to us, and then only the tasks you create.
Who we are
IzoMailer and the Tasks service at tasks.koli-bg.com are provided by Hristomir Kotzev, Sofia, Bulgaria ("we", "us"). Contact: admin@koli-bg.com.
The app
Your mail account
You sign in with your email address, your mail provider's server settings and a password (usually an "app password" from your provider).
- The address, your name and the server settings are stored in the app's private storage on your device.
- The password is stored on your device only: on Android in the app's private storage, which other apps cannot read; on Linux in the system keyring.
- The password is sent only to your mail provider's servers, over an encrypted connection, to sign in. It is never sent to us.
Your email
- The app downloads your email directly from your provider (IMAP) and keeps a copy of recent messages on your device, so it opens quickly and search works offline. Email you send goes directly through your provider (SMTP).
- All connections to your provider are encrypted (TLS).
- We never receive, read or store your email. Your provider's own privacy policy applies to the data on its servers.
- On Android, uninstalling the app deletes everything it stored on the device. Your email stays with your provider.
Notifications
New-mail notifications are created on your device by the app's own connection to your provider. No push service is involved (no Firebase Cloud Messaging), and no notification content leaves your device. While it watches for new mail, Android shows a permanent "Watching for new mail" notification. This is required for an app that keeps a connection open in the background.
Images and links in emails
HTML emails are cleaned before they are shown, and images loaded from the internet are blocked by default, because senders use them to track when and where an email was opened. If you choose to load images for an email or a sender, your device requests them from the sender's servers, which then see your IP address, as with any web page. Your choice to always load images from a sender or domain is stored on your device. Links open in your browser.
No analytics, no ads, no tracking
The app contains no analytics, advertising, crash reporting or tracking code, and it does not send usage data anywhere.
Permissions
- Internet: to talk to your mail provider (and Tasks, if you connect it).
- Notifications: to tell you about new mail.
- Foreground service: to keep the connection to your provider open in the background, so new mail arrives right away.
- Files: only the files you pick yourself when you attach or save a file.
The optional Tasks service
Tasks turns emails into tasks in shared workspaces. It is off unless you connect it under ⋯ → Tasks settings. If you enter the address of another Tasks server, that server's operator is responsible for your data instead of us.
What we receive
- Your Tasks account: you sign in on tasks.koli-bg.com through our sign-in service (oauth.koli-bg.com). We receive an account ID, your email address and your name.
- API token: you create a token on tasks.koli-bg.com and paste it into the app. The app keeps it on your device like your mail password. The server stores only a fingerprint (hash) of it, never the token itself.
- When you create a task from an email: the subject and text you write, the status, and a link back to the email: its Message-ID, sender name and address, subject and date. The email's text and attachments are copied into the task only if you tick "Copy email content" (off by default).
- Files you attach to a task.
- Workspaces you create or join: their names and members.
How it is stored and protected
- All traffic is encrypted (TLS).
- The database runs on our server in Germany (EU), hosted by Hetzner Online GmbH.
- Attachments are encrypted with a separate key per workspace before they are stored with Bunny (BunnyWay d.o.o., Slovenia, EU; storage region in the EU). Bunny only ever holds encrypted files.
- Server logs record what kind of request was made, when, its result and your account ID. They never contain task content, file names, email links or tokens. Unexpected server errors are reported to our own error tracker with the request type and an ID only, without user data or content.
- Database backups are kept for 30 days.
How long we keep it
Until you delete it: a task, a workspace (owners) or your whole account. Deleted data disappears from backups within 30 days. Deleted attachments become unreadable immediately, because their workspace key is deleted with them.
Deleting and exporting your data
On tasks.koli-bg.com, after signing in:
- Delete my account deletes your account, your tokens, your memberships and every workspace where you are the only member. Tasks you created in workspaces shared with others stay there, shown as "Deleted user".
- Your account data can be exported with your API token
(
GET /api/v1/me/export), and workspace owners can export a workspace with all its tasks and attachments (GET /api/v1/workspaces/{id}/export).
You can also ask us at admin@koli-bg.com to export or delete your data.
Legal basis (GDPR)
We process Tasks data to provide the service you signed up for (Article 6(1)(b) GDPR) and keep minimal logs for security and to run the service (our legitimate interest, Article 6(1)(f)).
Your rights
If you are in the EU/EEA or the UK, you have the right to access, correct, delete, restrict and export your personal data, and to object to its processing. Contact us at admin@koli-bg.com. You can also complain to your data protection authority (in Bulgaria: the Commission for Personal Data Protection).
Because your email never reaches us, requests about your email itself go to your email provider.
Children
IzoMailer is not directed at children under 16, and we do not knowingly collect their data.
Changes
If this policy changes, we will update this page and the date at the top. We will announce important changes in the app's release notes.
Contact
Hristomir Kotzev, Sofia, Bulgaria, admin@koli-bg.com