Dispatch

Privacy Policy

Effective August 3, 2026 · BM Interactive Group

Dispatch is a mail and calendar client for macOS, iPhone and iPad. It signs in to your own Google account and works out of a copy of your mail held on your own device. This policy describes exactly what stays there, what leaves, and what we can and cannot see.

The short version

Your mail, calendar, files and tasks are fetched from Google straight to your device and cached there. We operate no mail server and keep no copy of your mailbox.

Two things do leave, and both are described in full below: the optional Assistant, which sends selected text from your mail directly to Google under a key you own — not through us — to write your daily brief or answer a question; and push notifications on iPhone and iPad, which use a relay that is told your email address and nothing else.

Who we are

Dispatch is made by BM Interactive Group, which is the data controller for the limited processing described here. You can reach us at contact@bminteractivegroup.com.

What Dispatch accesses, and why

Dispatch asks for access to your Google account when you sign in. You can see and revoke this at any time at myaccount.google.com/permissions.

DataUsed for
Gmail messages, threads and labels Showing, searching, reading, sending, replying, archiving and labelling your mail
Google Calendar events and calendars Showing your calendar, creating and editing events, RSVPs and scheduling
Google Drive files Browsing, opening, sharing and attaching your files
Google Tasks Showing and completing your tasks
Contacts Name and address autocomplete when you write mail or invite guests
Basic profile Showing which account you are signed in as

Where your data is stored

On your device. Dispatch keeps a local cache — a database file in the application's private storage — so the app is fast and works offline. On macOS it lives in your user Library; on iPhone and iPad it lives in the app's sandbox and is protected by the system's file encryption.

Your Google sign-in is handled by Google's own OAuth flow. Dispatch never sees your password. The resulting tokens are stored in the operating system's keychain.

The Assistant, and what it sends

This is the one feature that sends your mail content off your device.

The Assistant is off by default. It does nothing, and sends nothing, until you turn it on and accept its consent screen. Turning it off again stops all of it immediately.

When the Assistant is on, two things can send data off your device:

Your daily brief

Once a day, Dispatch sends a digest of your recent mail and calendar — sender names, subject lines, short snippets, and meeting titles and times — so the Assistant can write a summary of your day.

Questions you ask

When you ask the Assistant a question, or type a question into the search bar, it searches your mailbox and sends the text of the few messages it needs to read in order to answer — up to roughly 1,500 characters per message. It sends only what that question requires, not your mailbox.

Attachment files are never sent unless you separately allow attachment reading in Settings, which is a distinct, off-by-default permission.

Where it goes

Straight from your device to Google. The Assistant runs on a Google Gemini API key that you create and that belongs to you, and requests go directly to Google's Gemini API. They do not pass through any server we operate, and we never see them.

Your key is stored encrypted on your device — in the macOS keychain, or the iOS keychain — and is never sent anywhere except to Google, as the credential on your own requests. Removing it in Settings deletes it and turns the Assistant off.

What Google does with the request is governed by your own agreement with them: their Gemini API terms do not permit paid-tier API content to be used to train Google's models. Because you hold the key, the usage limits and any billing are yours too, which is also why nothing you ask is metered or logged by us.

Push notifications on iPhone and iPad

If you enable notifications, Dispatch asks Google to tell a small relay service we operate when something changes in your inbox. That notice contains your email address and a change number — no sender, no subject, no message content. The relay's only job is to wake your phone.

The notification you actually see is assembled on your device, by the app fetching the message with your own credentials. The sender and subject on your lock screen never passed through our systems.

We store your device's push token and your email address for as long as notifications are enabled, so we know which device to wake. Turning notifications off or signing out removes it.

Zoom

If you connect Zoom, Dispatch creates and updates meetings on your behalf. Zoom meeting IDs and join links are stored on the calendar events themselves. Zoom tokens are stored encrypted on your device. This is optional and off until you connect it.

Limited Use disclosure

Dispatch's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Concretely, that means:

What we do not do

Retention and deletion

To ask us to delete anything we hold, write to contact@bminteractivegroup.com.

Children

Dispatch is not directed at children under 13 and we do not knowingly collect their data.

Changes to this policy

If we change how data is handled, we will update this page and change the effective date above before the change takes effect. Material changes to what leaves your device will also be surfaced in the app.