The short version
- Rondo is a mail app that runs on your iPhone, iPad and Mac. We don't run servers for your mail. Rondo talks directly to your mail provider (Google, Microsoft, iCloud, or whoever hosts your mail) and keeps what it downloads on your device.
- We don't collect anything about you. No accounts with us, no analytics, no advertising, no tracking, no crash reporting, no third-party SDKs that phone home.
- AI runs on your device when it can. When a feature uses an AI provider instead, it's one you chose, with your own key, and Rondo shows where each feature runs. Rondo sends mail to an AI provider only for features you use or turn on.
- Your sign-ins and keys stay in your device's Keychain and never sync anywhere.
The rest of this page explains each of those in detail.
Who we are
Rondo is made by World Dancing Inc. ("we", "us"). If you have a question about this policy or your data, email svkfoundry@gmail.com.
What Rondo stores, and where
Everything Rondo stores lives on your device, inside the app's own protected storage:
- Your mail: messages, their text and formatting, the names and addresses of senders and recipients, and attachment names and sizes. Attachments themselves download only when you open them.
- Things you create in Rondo: drafts, scheduled sends, reminders, labels, views, snippets, private notes, and the rules you set (for example, "always put this sender in Notifications").
- A search index of your mail, so search works offline and instantly.
- Settings, including your AI choices, your writing-voice description and any prepared replies.
- Sign-ins: the access tokens Google and Microsoft give Rondo, and any passwords, app passwords, API tokens or AI keys you enter. These are kept in the device's Keychain, never in files, and are set not to sync through iCloud Keychain.
Rondo has no servers of its own and doesn't use iCloud to sync its data. Nothing above leaves your device unless a section below says so.
Your mail accounts
Rondo connects to each account using that provider's own sign-in:
- Google (Gmail and Google Workspace). Rondo asks Google for one permission, to read, organize and send your mail (
gmail.modify). It never deletes mail permanently: deleted mail goes to Gmail's Trash. It uses that permission only to show your mail, to carry out the actions you take (archive, label, move, delete, send), and to run the Rondo features you use. - Microsoft (Outlook.com and Microsoft 365). Rondo asks for
Mail.ReadWrite,Mail.Send,User.Read(your name and address) andoffline_access(to stay signed in), for the same purposes. - iCloud, Yahoo, Fastmail, AOL, Zoho and any IMAP server. Rondo signs in with the password or app password you enter, over encrypted connections (TLS), and sends through that provider's SMTP server.
- JMAP (for example Fastmail). Rondo uses the API token you create and paste in.
Your mail provider's own privacy policy covers what it does with your mail on its servers.
AI features
Rondo's AI features include summaries, suggested replies, writing and rewriting, replies prepared in your writing voice, the Today digest, automatic labels, Tidy up and Ask your inbox. Each feature runs in one of two places, and Settings → AI shows which:
1. On this device. On devices with Apple Intelligence, Rondo can use Apple's on-device model. Mail used this way never leaves your device. 2. An AI provider you choose. You can connect Anthropic (Claude), OpenAI, Google Gemini, an OpenAI-compatible service (such as OpenRouter, Groq, Mistral, DeepSeek, xAI or Together), a model running on your own computer (such as Ollama or LM Studio), or your own endpoint. For Lens, you can also connect TypeSafe, whose Jev model doesn't write text: it answers questions you define about each email (yes or no, one of your categories, or a level on your scale). You bring your own key; Rondo doesn't include one. Requests go straight from your device to that provider, and that provider's terms and privacy policy apply to them. We never see them.
What gets sent depends on the feature:
- Summaries, replies, writing, and questions about one email: the conversation's subject and recent messages (sender names and addresses, dates and text).
- Ask your inbox: your question and short excerpts from the emails that match it.
- Automatic labels: each new email's sender, subject and first few lines, and the label descriptions you wrote.
- Tidy up: senders, subjects and dates of the inbox mail it's reviewing.
- Learning your writing voice: excerpts of emails you sent (quoted text is left out).
- Today digest: the senders, subjects and a short preview of unread mail.
- Lens (TypeSafe Jev), only for accounts you turn on: for each email it looks at, the sender, whether you were a direct recipient or copied, the subject, roughly when it arrived ("yesterday", "3 days ago"), how many messages the conversation has, whether you've replied, whether it's from a mailing list, how many attachments it has (never the files themselves), and up to 2,000 characters of the latest message with quoted replies removed. It also gets which of your addresses the email came to, whether the sender's domain passed your provider's checks (SPF, DKIM and DMARC, already recorded in the email), and how many earlier conversations you've had with that domain. Your questions go with it, along with your "About me" note and your inbox guide (your addresses and what each is for), if you filled them in. TypeSafe says it doesn't train on what it's sent; see its privacy policy for how long it keeps requests.
- Other Jev checks, only for accounts you turn on, each with its own switch in Settings → AI: when you send, the email you wrote, its subject and recipients (to look for a harsh tone, a wrong name, a password or a promise with no day). As you write, the last part of your draft, the subject, the recipients and the email you're replying to (to suggest one of your snippets), and the names of your signatures with what each is for (to pick one). When you ask your inbox, your question with excerpts of up to 30 matching emails, then each sentence of the answer with the excerpts it cites (to rank the emails and check the answer). When an assistant connected to Rondo wants to act, what it wants to do: the action, who it would go to and what it would say. None of this is kept by Rondo; it's asked and answered on the spot.
When it's sent:
- Most features run only when you ask: you click Summarize, Ask, Write, Learn my voice or Tidy up.
- Three features can run on their own after new mail arrives, and only if you set them up: automatic labels, when you've created labels with AI descriptions (importing labels from Notion Mail sets these up), prepared replies, which are off until you turn them on, and Lens questions set to answer new mail, for recent inbox mail in accounts you've turned on for TypeSafe.
- Private notes are never sent to an AI provider.
Rondo treats email text as untrusted: before any AI reads mail, Rondo removes hidden text, marks the email as content rather than instructions, and flags emails that try to give instructions to AI assistants. AI output is cleaned of images and disguised links before you see it.
We don't use your mail to train or improve any AI model, and Rondo doesn't send your mail anywhere to be used for training.
Assistants, Siri and Shortcuts
- Agent access (Mac). Rondo can let AI assistants on your Mac, such as Claude, work with your mail through a local connection (the Model Context Protocol). It's off until you turn it on, it only accepts connections from your own Mac with a secret token, and you choose what each account allows: nothing, reading, triage, or sending. Actions beyond reading ask you first by default, and sending always asks. Rondo keeps a log of what assistants did (the time, the assistant, the action and the account, never the content) on your Mac, and you can clear it.
- Siri and Shortcuts go through the same permissions.
Calendar and notifications
- If you allow it, Rondo reads your calendar to show upcoming events next to your mail and to share times you're free when you schedule, and it adds an event only when you tap "Add to calendar" on an invitation. Calendar data stays on your device.
- New-mail notifications are created on your device and show the sender, subject and a short preview. You can turn them off in Rondo or in your device's Settings.
Content inside emails
- Images in emails load when you open a message. As in most mail apps, this can let a sender know the email was opened, from roughly where, and on what kind of device. Scripts in emails never run.
- In shopping, receipt and package views, Rondo may show a product image from the email itself.
- Links open in your browser only when you tap them.
- Link check: to warn you about dangerous links, Rondo downloads public lists of known bad sites about twice a day: URLhaus from abuse.ch, and OpenPhish from GitHub if you turn it on. Only the lists travel; your mail is checked on your device. Like any download, those services can see your device's IP address. If you turn on Cloudflare in Link safety (it's off until you do), Rondo also asks Cloudflare's security DNS (1.1.1.2) about the site name in each link, the way a browser looks up a site before opening it: only site names like "example.com" go to Cloudflare, never your mail, and answers are kept on your device for a day. You can turn this off in Settings → Inbox → Link safety.
- Unsubscribe: when you ask Rondo to unsubscribe you from a sender, it uses the method the sender offers: a one-click web request, an unsubscribe email sent from your account, or the sender's web page.
What we don't do
- We don't collect, store or see your mail, contacts, or usage.
- We don't sell or share personal information, and we don't use it for advertising.
- Rondo contains no analytics, advertising, tracking or crash-reporting code. Its only third-party code library (GRDB, for the on-device database) runs entirely on your device.
Google user data
Rondo's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Rondo uses Gmail data only to provide and improve the mail features you see in the app.
- Gmail data is transferred to others only when you use an AI feature that runs with an AI provider you chose, and only to provide that feature to you.
- No person at World Dancing Inc. reads your Gmail data, and we can't: it never reaches us.
- Gmail data is never used for advertising, sold, or used to develop, improve or train generalized AI or machine-learning models.
Security
- Connections to mail and AI providers are encrypted (HTTPS and TLS).
- Sign-ins and keys are stored in the device Keychain. Mail is stored in the app's own sandboxed storage and protected by your device's encryption (on a Mac, when FileVault is on).
- On the Mac, Rondo runs in Apple's App Sandbox.
Deleting your data
- Remove an account (Settings → Accounts): Rondo deletes that account's mail, search index and sign-in from the device.
- Remove an AI key in Settings → AI.
- Delete Rondo from your device to remove everything it stored.
- Revoke Rondo's access at any time: for Google at myaccount.google.com/permissions, for Microsoft at account.live.com/consent/Manage (work accounts: myapps.microsoft.com).
Because we don't hold any of your data, there's nothing for us to delete on our side. If you'd like us to confirm that, email us.
Children
Rondo isn't directed at children under 13, and we don't knowingly collect information from anyone, of any age.
Changes
If we change this policy, we'll update this page and the date at the top. If a change affects what leaves your device, the release notes for that version of Rondo will say so.
Contact
World Dancing Inc. · svkfoundry@gmail.com