Effective July 16, 2026

Privacy, in plain language.

LensMail connects the installed app directly to Microsoft. It has no mailbox database or advertising system. Optional analytics apply only to visits to this public website.

Information LensMail accesses

After sign-in, LensMail may access Microsoft account profile information and Outlook message metadata, message bodies, recipients, folders, attachment indicators, Focused Inbox classification, read state, and drafts required for the feature the user chooses.

Delegated permissions are openid, profile, offline_access, User.Read, Mail.ReadWrite, and Mail.Send.

How information is used

Mailbox information is used only to display and manage the signed-in user's Outlook mailbox. User-requested actions are sent directly to Microsoft Graph. LensMail does not sell personal information, use mailbox content for advertising, or train AI models with mailbox content.

Storage and data flow

The public Client ID, tenant selection, access token, refresh token, and account label are stored in the installed app's local Even Hub/WebView storage. LensMail does not ask for a Microsoft client secret. Mail content is held only as needed in the running interface; LensMail has no application database or developer-operated mail backend.

Microsoft sign-in uses static pages at https://auth.lensmail.net. LensMail sends short-lived PKCE context to the start page in a URL fragment, which is not transmitted to the hosting server. The start page holds it in tab-scoped session storage and gives Microsoft only a random state value. The callback exchanges Microsoft's authorization code in the user's browser, clears the temporary state, and returns the result to the local app. The host has no persistent token store.

Optional website analytics

The public pages at lensmail.net use Google Analytics 4 only after a visitor selects Allow analytics. If permission is granted, Google Analytics may process the page URL and title, referring page, browser and device information, approximate location derived from the network address, and ordinary page-view or interaction data. LensMail does not provide Google Analytics with mailbox content, Microsoft account details, authorization codes, access or refresh tokens, typed setup values, or a LensMail user identifier.

Analytics is not loaded on auth.lensmail.net, so the Microsoft sign-in start and callback pages are outside this measurement. Google Signals, advertising storage, ad personalization, and user-provided data collection are disabled. LensMail uses measurement ID G-N8DF75RR1W.

The choice is stored in the browser's local storage. When analytics is allowed, Google Analytics may set first-party cookies such as _ga. A visitor can continue using every public page after choosing No thanks, can reopen Analytics settings at any time, and can withdraw permission; LensMail then disables analytics and attempts to remove its analytics cookies. Browser Global Privacy Control or Do Not Track signals keep analytics off. Previously collected aggregate records may remain subject to Google Analytics retention and deletion controls.

Voluntary project support

The LensMail website links to Eddie Rivera's Buy Me a Coffee page for optional contributions. The button artwork is hosted by LensMail, so viewing a LensMail page does not contact Buy Me a Coffee. Buy Me a Coffee receives information only after a visitor deliberately follows the external link and then processes any payment under its own privacy policy and terms. LensMail and Wevem MSP do not collect or store payment-card information. Information a supporter chooses to provide through Buy Me a Coffee, together with contribution records made available to the page owner, is handled through that service. Contributions do not affect app features or support eligibility.

External services and security

The installed LensMail app connects only to Microsoft identity, Microsoft Graph, and the LensMail callback domains declared in its Even Hub network permission. It uses Authorization Code with PKCE, validates OAuth state, limits callback age, and restricts callback returns to local LensMail origins. Microsoft and Even Realities process information under their own terms. Google processes consented public-site analytics under its Privacy Policy. Use of LensMail is also governed by the LensMail Terms of Service.

User choices and deletion

Users can clear Graph setup and locally stored sign-in information in LensMail, uninstall the app, and revoke consent through Microsoft. Mailbox actions already completed remain subject to Microsoft and organizational retention policies. Website visitors can change their separate analytics choice with the Analytics settings control displayed on public LensMail pages.

Children and changes

LensMail is intended for Microsoft 365 account holders and is not directed to children under 13. Material policy changes will appear on this page with a revised effective date.

Contact

Privacy, feedback, and support inquiries: support@lensmail.net.