Croftly · Legal documents
Privacy and legal information
Details of the professional providing Croftly and information about data processing in the app and website.
Last updated: September 29, 2026
1. Controller and contact
Croftly is the software developed and provided by Giuseppe Domenico La Fauci, an independent professional, VAT number 03758170835, with a business address at Strada Panoramica dello Stratto 1416 G9, 98168 Messina (Italy). The professional is also the data controller described in this policy.
To contact the developer or make privacy, data access, or deletion requests, write to support@croftly.com.
This policy covers Croftly for macOS, croftly.com, and the licensing and support services. The developer does not automatically receive your local Croft content or mailbox. If you organize other people’s data, you remain responsible for your use and any sharing you choose to perform.
2. Data we process
App content
Croftly processes the data you add to Lands, Crofts, and modules, including text, notes, keywords, dates, tables, relationships, file references, and other content required by the features you choose to use. Archives, extracted text and search indexes are stored on your Mac; the index may be integrated into macOS Spotlight search. If you export or share a Croft, or use synchronized folders, copies follow the destination and service you choose.
Linked files and folders
When you link files or folders, Croftly may store references and macOS security permissions needed to find them again. Original files remain in the location selected by the user and are not automatically uploaded to a Croftly server.
Connected mail accounts
Only when you connect a Google, Microsoft or IMAP account does Croftly access your email address, provider, selected folders and the messages needed for the requested features: identifiers, senders, recipients, subjects, dates, text and attachments. It stores local copies of imported messages and may download supported attachments into a cache, extracting their text for search. Content is used to view, organize, search and link mail to Crofts and for the on-device processing described below.
OAuth tokens and IMAP passwords are stored in the macOS Keychain. In the current version, the connection runs directly from the Mac to the mail provider; Croftly does not operate an intermediary server that stores the user’s mailbox.
Google and Microsoft sign-in takes place with the provider: Croftly receives authorized tokens, not your account password. Persistent access enables the updates you have enabled without signing in each time. For Gmail, Croftly requests only read access to mail and the basic information needed to identify the account. Croftly does not send, modify or delete Gmail messages, nor does it request permission to do so. Croftly’s mail browsing features do not send messages or delete originals on the server.
Purchases and licenses
When you use the purchase service, Paddle handles payment and transaction data under its privacy policy. Croftly receives purchase and subscription references and the email needed to issue and manage your license, not complete card details. License activation and validation send the license code, device identifier, Mac name and app version to the Croftly service to manage validity and device limits.
Website and support
The Contact us form collects your email address, topic, subject and message; Croftly and macOS versions are optional. The request is stored on the server with a ticket number, date and notification status. To handle support, the message is forwarded to the support mailbox and a confirmation is prepared for the sender through the email service. Further exchanges take place by email. Do not enter passwords, API keys or license codes in the form.
The public website does not require a Croftly account. Technical services may record IP address, date, time, requested page and browser information for security and operation. The form also uses derived identifiers to limit abuse. We do not include advertising profiling tools; the website may store functional preferences such as language.
3. Purposes and legal grounds
We use data only to:
- provide the requested app features and keep content organized on the device;
- authenticate and synchronize mail accounts you choose to connect;
- manage purchases, licenses and device activations;
- protect operation, diagnose errors, and prevent abuse;
- answer support requests and comply with legal obligations.
Purchases, licenses and support requests are processed to perform a contract or take steps you request before a contract. Tax and administrative requirements are based on legal obligations; technical protection and abuse prevention on legitimate interests in security. Optional integrations are enabled by your choice within the authorizations you grant, which you can revoke. Where processing requires consent, withdrawal does not affect the lawfulness of earlier processing.
4. External services and recipients
Google and Microsoft data
Croftly’s use of data received through Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google and Microsoft data is used exclusively for the visible, user-requested features described in this policy.
We do not sell this data, use it for advertising, commercial profiling or creditworthiness assessment, or transfer it to data brokers. It is not used to create, train or improve general-purpose AI models. The developer has no routine access to your mail; support can read only what you explicitly choose to send for a specific request.
Mail is not transmitted to Croftly’s licensing, payment or support services during synchronization. Any disclosure required for law or security is limited to what applicable law and provider policies permit. See the privacy policies of Google and Microsoft.
Apple Intelligence and external options
When available and enabled, natural-language search, summarization and comparison use the on-device Apple Intelligence model through the Foundation Models framework. Selected content, including relevant mail, is processed on your Mac to produce the requested response; Croftly does not send it to a remote AI service or use it to train models.
Web search is optional and requires your own Kagi API key, stored in the Keychain. Selecting Web or Both sends the search query and, when needed, page URLs for extraction to Kagi, together with connection data. Your mailbox and Croft archives are not automatically uploaded. However, text you enter in a query may contain personal information: choose what to include before starting a web search. See the Kagi privacy policy.
External OCR, if configured, processes files through your chosen folder and tools installed on your Mac. A synchronized or shared folder is also subject to the relevant service’s rules.
Online service providers
Scaleway hosts online application services and databases; Cloudflare provides DNS and website delivery or protection services; OVHcloud operates the support mailbox. These providers may process data needed for their respective functions. Paddle handles purchases under its privacy policy. Google, Microsoft and Kagi receive data for the integrations you choose to use, under their respective terms.
Some providers may process data outside the European Economic Area. Processing on our behalf is subject to GDPR safeguards, such as adequacy decisions or standard contractual clauses where required; contact support@croftly.com for information. Connected services’ policies also describe their transfers.
5. Retention and security
Local content and imported mail copies remain on your Mac until you delete them using the app’s tools. The Mail filter’s time window controls import, not automatic deletion of historical messages. Moving only the app to Trash or revoking consent on a provider’s website does not necessarily delete data already stored on your Mac or in the Keychain.
Support tickets and correspondence are retained to handle the request, follow-up and related rights; they are deleted when these purposes end, unless retention is legally required. License data remains necessary while a license is valid and to handle later requests or disputes; records subject to tax obligations follow statutory periods. Technical logs follow security needs and the respective services’ retention periods. Contact us for the period applicable to a specific request or to request deletion.
Remove an account and delete local copies
In Croftly → Settings → Mail, choose Remove… beside the account and confirm. Croftly stops using the account and deletes its Keychain credentials, imported messages, attachments in the app-managed cache, extracted text and search index entries. It also removes notes and relationships associated with deleted messages. Cleanup includes modules in Trash; modules, manual rows and other accounts remain available.
This does not delete your mailbox or original messages at Google, Microsoft or your IMAP provider, and cannot be undone. If cleanup fails, Croftly reports the error and keeps access suspended: repeat Remove to finish. Exports, shared Crofts, separately saved attachments, copies in external OCR folders and backups remain under your control and must be managed at their respective destinations. Only opaque local technical identifiers without content or credentials remain, to prevent earlier activity from restoring a removed account.
Revoking OAuth consent is separate from local deletion. Use your Google account connections, personal Microsoft account permissions, or Microsoft My Apps for work or school accounts, subject to your organization’s rules. These links are also available in Mail settings. After revocation, remove previously imported copies in the app as well.
We use measures proportionate to the nature of the product, including the macOS Keychain for authentication secrets and system security mechanisms for access to external files. No system can guarantee absolute security; users should protect their Mac, keep the system updated, and maintain backups.
6. Rights and choices
You can edit or delete local content in the app and follow the mail procedure above. For data processed by the developer, you may request access, rectification, erasure, restriction, portability or objection where provided by law, by writing to support@croftly.com. Include the relevant email or ticket number, without passwords or keys. We may request only the information needed to verify your request. The developer cannot remotely delete your local archives.
You may complain to the Italian Data Protection Authority or your country’s competent authority. Integrations are optional: not connecting mail or enabling web search limits only the corresponding features.
7. Children and changes
Croftly is not directed to children who cannot validly accept these terms under applicable law. We may update this policy when the product or legal requirements change; the date above identifies the current version.