Canary Mail
Canary · Productivity · US · canarymail.io
services/canary-mail.yamlVendor data-handling terms
“Your data including that from Google services, is not used to develop, improve, or train generalized/non-personalized AI and/or ML models. / Personalised ML models - including for prioritization are created, trained and stored on-device. / However, we have opted out of data sharing - your data will not be used to train or improve 3rd party models.”
“Data associated with a specific email is deleted as soon as the notification for that email is delivered to your device. / All data is cleared from our server when notifications are disabled on Canary Mail for iOS or Android or when you switch from Push to Fetch mode, in which case all data is stored locally only and new emails are fetched directly from your device.”
The policy does not name the location of the push-notification server.
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| canarymail.io | app | observed |
Assessment
Reasoning: Mail content is processed and stored on the device, personalisation models are trained locally, and third-party model providers are contractually excluded from training. The remaining exposure is the AI writing features that send message text to a model provider at request time, and the push service, which briefly holds message data with no stated location.
Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Training, on-device processing, and notification retention terms verified against the Canary Mail privacy policy.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.