App Privacy Policy
This policy applies to the Mac app warfta. It describes which data the app processes, which connections it makes and what MOJM receives from it. The website is covered by the privacy policy at warfta.eu/en/privacy.
Last updated: 10 October 2026
1. Controller
MOJM — Owner: Oliver Terp
Heinrich-Lübke-Str. 16, 42579 Heiligenhaus, Germany
Email: kontakt@mojm.de
2. The essentials first
warfta is an app that runs on your Mac. MOJM operates no server of its own for warfta. Your mail, calendars, tasks, contacts and credentials are stored on your Mac and transferred only between your Mac and the providers of your accounts — tasks also to Apple (iCloud), but only if you turn on sync (section 9). MOJM receives none of it — no content, addresses, account data or usage statistics.
3. Data on your Mac
- Mail and folders: headers, content and a search index are stored in a database in the app’s protected container. Attachments are loaded only when needed and kept in a cache of at most 512 MB.
- Drafts and outbox: drafts are saved locally and synced with your account’s drafts folder. Bcc recipients stay on the Mac.
- Events: calendars and events of the accounts for which you turn on the calendar are stored in the same database. If you turn off an account’s calendar, warfta deletes its calendar data on the Mac.
- Tasks: tasks, projects, areas and tags are stored in the same database. If you link a task to a mail, warfta stores a reference consisting of the Message-ID and the account address.
- Credentials: passwords and sign-in tokens — including the password of a CalDAV calendar — are stored in the Mac’s keychain, without syncing via iCloud.
- Settings: for example account colours, signatures, trusted senders and account pictures.
- Spotlight: so that macOS search can find them, warfta passes the subject, sender and preview of the latest 5,000 mails (excluding spam, trash and drafts) as well as open tasks (title, note, project, deadline) and active projects (title, note) to the system’s Spotlight index. For mails this is on by default and can be turned off in the settings under Privacy; the mails then disappear from the index. Tasks and projects can be excluded in the Spotlight settings of macOS.
- Widget, Shortcuts and Siri: for the “Today” widget, warfta writes today’s tasks and events (titles, times, deadlines) to a folder on the Mac shared by the app and the widget. Via Shortcuts and Siri, warfta provides today’s tasks, upcoming events and the number of unread mails on request.
- Notifications: warfta schedules reminders for tasks and events as local macOS notifications. A task’s note appears in them only if you turn that on.
- Files you create: task backups (
.warftabackup), saved mails (.eml) and exported mailboxes (.mbox) are written by warfta only to locations you choose. The daily task backup is off initially; when turned on, it places a file with all tasks, projects and areas in the chosen folder once a day and keeps the last 14. If that folder is in iCloud Drive, for example, the respective service syncs it, not warfta.
If you remove an account in warfta, the app deletes the associated local data. The mail stored with your provider is not affected.
4. Connections the app makes
- To your mail and calendar providers — Google, Microsoft, Apple (iCloud) or the IMAP/SMTP server you enter, and for the calendar of an IMAP account to the CalDAV server (iCloud, Fastmail, mailbox.org, Posteo or an address you confirm). Their processing is governed by the privacy terms of the respective provider.
- Events and invitations: if you create, change or delete an event with attendees, with Google and Microsoft the provider sends the invitation or message to those people. If you wish, the provider also sets up an online meeting (Google Meet or Microsoft Teams). If you answer an invitation in an IMAP account, warfta sends the answer as a mail via your outgoing mail server to the person who sent the invitation.
- “Later” folder: if you put a mail off until later, warfta creates a folder or label “Später” (“Later”) in your mailbox with the provider (if the name already exists: “Später (warfta)”) and moves the mail there.
- Signing in with Google and Microsoft takes place in a system sign-in window directly with the provider. warfta does not see your password.
- External images in mails are loaded by warfta only after you allow it. When they are loaded, the server delivering the image learns your IP address.
- Sender logos (BIMI and favicon) are loaded by warfta only if you turn this on. The server of the respective company then learns your IP address.
- Profile photos of colleagues from the Google Workspace or Microsoft 365 directory are loaded by warfta only if you turn this on for the account.
warfta embeds no analytics, advertising or tracking services and sends no usage or crash reports to MOJM.
5. Data from Google accounts
When you connect a Google account, warfta gains access to the following scopes. The data is processed exclusively on your Mac in order to provide you with the respective feature in the app.
- read, send, organise and delete Gmail (
gmail.modify), - your email address, your name and your profile photo, which warfta shows as the account
picture (
openid,email,profile), - optionally, only once you turn on the account’s calendar: view calendars and events, create,
change and delete events, invite attendees, create Google Meet meetings and answer invitations
(
calendar.events), and read the list of your calendars with names and colours (calendar.calendarlist.readonly), - optionally, if you turn this on, your organisation’s directory for profile photos (
directory.readonly).
warfta’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In detail: warfta does not transfer Google user data to MOJM or third parties, does not use it for advertising, does not sell it and does not use it to train AI models. No humans read this data — except you.
You can revoke access at any time by removing the account in warfta or by revoking the permission at myaccount.google.com/permissions.
6. Data from Microsoft accounts
For Microsoft 365 and Outlook.com, warfta uses Microsoft Graph with the permissions Mail.ReadWrite, Mail.Send, User.Read (your address and your profile photo), openid, profile, email and offline_access.
Optionally added: User.ReadBasic.All for profile photos of colleagues, if you turn
this on, and Calendars.ReadWrite, only once you turn on the account’s calendar — to
view, create, change and delete events, invite attendees, create Microsoft Teams meetings and
answer invitations. This data, too, is processed only on your Mac and not transferred to MOJM.
You can revoke access at account.microsoft.com.
7. Apple Intelligence
For summaries and reply suggestions, warfta uses Apple’s language model, which runs on your Mac. Mail content is not transferred to Apple, MOJM or third parties for this and is not stored by warfta. Mails in the spam folder are not processed. The feature can be turned off in the settings.
8. Contacts
warfta accesses the contacts of macOS only if you allow it — for sender pictures and address suggestions. The data stays on your Mac.
9. Syncing tasks via iCloud
warfta can sync your tasks between your devices via your private iCloud database (CloudKit). In the current version this feature is not yet turned on; it will come with a future version and will then only be active if you turn it on in the settings under Tasks. When turned on, warfta transfers your tasks, projects, areas and tags to the private database of your iCloud account; for mails, only the reference consisting of the Message-ID and the account address, no content. So that your other devices learn about changes, warfta uses Apple’s notification service (push). iCloud is provided by Apple; processing there is governed by Apple’s privacy terms. MOJM does not receive this data.
10. Your rights
Since MOJM receives no personal data from you via the app, most data lies solely in your hands and those of your mail provider. Your rights under Art. 15 to 21 GDPR towards MOJM remain unaffected; for this, write to kontakt@mojm.de. The competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen).