Thunderbird Privacy Notice by Mozilla

Updated 16 December 2025

[application name] Privacy Notice

Last updated [effective date]

The [application names] applications (together, “[application name]”) allow users to privately integrate and manage their online communications. [application name variant] is a variant of The [application name] for Android. All references to “[application name]” or “[application name] for Android” apply equally to [application name variant].

This Privacy Notice explains what data [application name] collects and shares, and why. We also adhere to the [company name] Privacy Policy for how we receive, handle, and share information.

This privacy notice is for the most recent general release version of [application name] distributed by [corporation name] Corporation. If you obtain [application name] elsewhere, or are running an older version, your copy of [application name] may contain different privacy characteristics.

[application name] Collects Data To:

Improve Performance, Stability, and Functionality For Our Users

Interaction data: [application name] receives measurements about how you use [application name] and how well it’s working, such as, whether calendars and filters are being used, and how many email accounts a user has.

Technical data: [application name] also receives environment data from your device, such as, application version, hardware configuration, device operating system, and language preference. When [application name] sends technical data to us, your IP address is temporarily collected as part of our server logs.

We use this information to make better decisions on which features should remain included or need to be changed, identify improvements for new features we implement, and find other ways to improve [application name] for all our users. Read the telemetry documentation for [application name] Desktop or [application name] Mobile to learn how to opt-out of this data collection. [company name]’s data dictionary contains information on some of the data points collected.

Set-Up, Configure, and Process Your Email

[application name] collects your email domain and other technical data to set-up and configure your email account. Other information, like your name, your email messages, and your account’s address book are stored and processed locally on your device and never sent to us. Learn more here.

Email domain: [application name] receives your email address domain. Your full email address is never processed or stored on our servers (unless you choose to share it when you send a crash report).

Sending Email: When using [application name] to send an email, you can choose recipients from your contacts. You may optionally attach data such as photos, videos, and audio files to your message. This data is exchanged via your email server between you and the recipient of your email and is never shared with us.

Technical data: [application name] also receives information about the application’s version and device operating system. When [application name] sends technical data to us, your IP address is temporarily collected as part of our server logs.

Set Up and Configure Your Calendar (Desktop Only)

[application name] collects the domain for your email/calendar, as well as technical data to set up and configure your calendar. Other information, like your name, your calendar events, and event attendees are stored and processed locally on your computer and never sent to us. If you are using a remote calendar such as Google, Microsoft, or Apple, calendar content is solely shared with the respective calendar provider and anyone you specifically choose to send appointments to. Calendar contents and personal data are used only to display and enable you to use your calendar in [application name].

Set Up and Schedule Calendar Appointments with [application name] Appointment

With [application name] Appointment, you can allow others to schedule appointments on your calendar.

You can connect your Google, Microsoft, or Apple calendar to [application name] Appointment to assist with scheduling.

If you choose to connect your Apple Calendar, Microsoft 365, or Google Calendar to [application name] Appointment, we will receive basic information about your calendar invites such as the title, date, stated location, the name and emails of the attendees, and any text in the appointment to display them within [application name] Appointment and allow you to invite others to schedule time in your calendar. We will receive technical and interaction data about your interactions with this feature such as how many events you create, whether you have connected to a Google, Microsoft, or Apple account.

We will only use your data to provide and improve the [application name] Appointment service.

Review Crash Reports

[application name] Desktop

If [application name] crashes, we will ask you to share a report with more detailed information about the crash, but you always have the choice to decline. [application name] uses the information in the crash report to diagnose and correct the problem that caused the crash.

Sensitive data: Crash reports include a “dump file” of [application name]’s memory contents at the time of the crash, which may contain data that identifies you or is otherwise sensitive to you.

Webpage data: Crash reports include any active URLs at time of crash.

Add-on data: Crash reports include a list of all add-ons that you were using at the time of the crash, and the time since: the start-up of the program, the last crash, and the last install.

Technical data: Crash reports include data on why [application name] crashed and the state of device memory and execution during the crash. When [application name] sends technical data to us, your IP address is temporarily collected as part of our server logs.

Email address: If you choose, crash reports include your email address.

Read the full documentation here.

[application name] Mobile

Crash reports and related analytics may be collected by app store providers for apps distributed through their platforms. This data collection is carried out by the platform providers and may be shared with us subject to their terms. We do not control or manage the data collection practices of these third parties. To adjust your data preferences, please refer to the privacy settings and documentation provided by your app store provider.

Improve Security for Our Users Everywhere

Technical data for updates: To ensure you have the most up-to-date version of the product, [application name] Desktop checks for updates by periodically connecting to [application name]’s servers. Your application version, language, and device operating system are used to apply the correct updates. Learn more.

Technical data for add-ons blocklist: To help to protect you from any malicious add-ons, [application name] Desktop periodically checks for blocklisted add-ons. Your [application name] version and language, device operating system, and list of installed add-ons are needed to apply and update the add-ons blocklist. Learn more.

Install and Update Add-Ons (Desktop Only)

You can install add-ons for [application name] Desktop from [addons url] or from the [application name] Add-ons Manager, which is accessible by clicking on Tools > Add-ons. To keep your installed add-ons up to date—like add-on descriptions, download counts, and ratings—the [application name] application periodically connects to our servers to install any updates.

Search queries: If you enter keywords into the search field for the Add-ons Manager, those keywords will be sent to [application name] to perform the search.

Interaction data: We receive aggregate data about visits to the [application name] website and the Add-ons Manager in [application name], as well as interactions with content on those pages. Read about data practices on [company name] websites.

Technical data for updates: [application name] periodically connects to our server to install updates to add-ons. Your installed add-ons, application version, language, and device operating system are used to apply the correct updates. When [application name] sends technical data to us, your IP address is temporarily collected as part of our server logs.

Use of OAuth Information

OAuth is a secure authorization protocol that allows third-party applications to access resources without sharing login credentials. [application name] uses OAuth to connect with certain email or calendar providers that mandate or prefer its use, such as Google, Yahoo and Microsoft.

OAuth authentication and user data synchronization occur directly between [application name] and the respective service provider over an encrypted connection, without involving any [company name]-operated services. [company name] does not collect, access, retain, or store any sensitive information exchanged during this process.

Data protection on your device:

Login credentials are not stored on your device; instead, they are exchanged for OAuth tokens. These tokens, along with your email and calendar data, are secured within the application sandbox (on Android), the secure key storage (on iOS), or confined within your user profile (on Desktop). Additional security measures such as operating system level full disk encryption increase the security of your data.

Email and calendar data reside solely on your device for the duration required to operate [application name]. This includes sensitive user data associated with your Apple Calendar, Microsoft 365 or Google Calendar.

[application name] does not share OAuth tokens, email contents, calendar events, contact lists, or account details with third parties, except as necessary to provide the services requested by the user (e.g., sending an email or scheduling a calendar event).

Retention and deletion:

OAuth tokens are stored only as long as necessary to maintain the authorized connection.

When you remove an account, all associated sensitive user data and OAuth tokens are immediately deleted from your device.

On [application name] Desktop, the OAuth tokens are retained until manually deleted in the password manager.

If you revoke [application name]'s access to your account via your OAuth provider’s account settings (e.g., Google security settings), [application name] will be unable to refresh the connection. Locally stored data will remain on your device until you remove the account from [application name].

[application name] May Disclose Information To:

[company name] Affiliates: [application name] is a project of [corporation name] Corporation, a subsidiary of [company name] Foundation and an affiliate of [company name] Corporation, and as such, shares some of the same infrastructure. This means that, from time to time, your data (e.g., crash reports, and technical and interaction data) may be disclosed to [company name] Corporation and [company name] Foundation. If so, it will be maintained in accordance with the commitments we make in this Privacy Notice.

DNS servers, Standard Autoconfiguration URIs, and [company name]'s Configuration Database: To simplify the email set-up process, [application name] tries to determine the correct settings for your account by contacting [company name]’s configuration database as well as external servers. These include DNS servers and standard autoconfiguration URIs. During this process, your email domain may be sent to [company name]'s configuration database, and your email address may be disclosed to your network administrators.

Amazon Web Services: [application name] uses Amazon Web Services (AWS) to host its servers and as a content delivery network. Your device’s IP address is collected as part of AWS’s server logs.

Email address providers (Desktop Only Legacy): Prior to version 128, [application name] partnered with Gandi.net and Mailfence to allow you to create a new email address through [application name]. If you choose to use this feature, your email address search terms are sent to Gandi.net and Mailfence to return available addresses. In addition, your country location is also shared to provide the correct prices. You can learn more about Gandi.net’s and Mailfence’s data practices by reading their privacy notices.

Contact Us

If you want to make a correction to your information, or you have any questions about our privacy policies, please get in touch with:

[corporation name] Corporation
Attn: [company name] - Privacy
[street address]
[floor/suite]
[city, state/province, zip/postal code]
[country]
[compliance email address]

See here for Data Subject Access Requests. If you are under 13, we don’t want your personal information, and you must not provide it to us. If you are a parent and believe that your child who is under 13 has provided us with personal information, please contact us to have your child’s information removed.

For product support requests, please visit our forums.

About this template

What is this template?

Thunderbird Privacy Notice by Mozilla is a free, ready-to-use Data Protection & Privacy template you can open, customize, and download on GitLaw. It gives you a professionally structured starting point, so you never have to draft from a blank page. The wording is plain and modern, organized into clear sections that are easy to read, edit, and adapt to your own situation before you share or sign it.

When should you use it?

Reach for this Data Protection & Privacy template whenever you need a reliable agreement quickly and want to be sure the essentials are covered. It suits individuals, freelancers, startups, and established businesses alike. Instead of paying for a document drafted from scratch, you can start here, tailor the details to your arrangement, and have a polished draft ready in minutes. This version is drafted with United States of America and California (US) in mind, though you should always review the final wording against the laws that apply to you.

What's typically included?

A well-drafted Data Protection & Privacy usually sets out the parties involved, the scope of the agreement, and each side's rights and responsibilities. Expect sections covering key terms and definitions, how long the agreement lasts, how it can be ended, and what happens if something goes wrong. This template brings those building blocks together in a sensible order, so you can focus on the specifics rather than worrying about what to include. Open it to read the full document, then sign up to edit, negotiate, and e-sign it directly in GitLaw.

Jurisdiction
United States of America
California (US)
Source
M
Thunderbird Privacy Notice by Mozilla
from Mozilla
Document info
HTML document. Document created on Wed Dec 10th, 2025. Last updated on Tue Dec 16th, 2025.
This document is public
Licensed under CC BY-SA 4.0 (Attribution-ShareAlike).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
OLOpen Legal Library
Pocket Privacy Policy by Mozilla
OLOpen Legal Library
Firefox Better Web (beta) Privacy Notice by Mozilla
OLOpen Legal Library
Acceptable Use Policies Github Sexually Obscene Content (GitHub)
OLOpen Legal Library
Patent and Know-How Licence Agreement
OLOpen Legal Library
Privacy Policy by EasyLegalDocs
OLOpen Legal Library
Accounts Privacy Notice by Mozilla