Hark
Privacy, as architecture

A Gmail client that never sees your mail

A private email client is a claim you should be able to check. This page is the architecture behind Hark’s version of the claim — your mail never touches our servers — in enough detail to do that, including the small set of things that do reach us, the third parties a message can touch, and the settings that decide each one.

The shape of it

Two parties: your Mac and Google. Hark runs on the first and talks to the second through Google’s Gmail, Calendar, Tasks and People APIs, over TLS, from your machine. There is no third party in that path. We do not operate a server that syncs, relays, indexes, backs up or “speeds up” your mail, so there is no copy of it in our infrastructure to be breached, subpoenaed or leaked.

This is not a policy choice that could be quietly reversed in a later version; it is how the app is built. The sync engine lives in the app, and putting a server in the path would mean rebuilding it around one.

Where your data lives, exactly

What does reach us, and when

In ordinary use — reading, writing, organising, looking at your week — nothing about your mail. Four things involve a server of ours, and each has a trigger you control:

One more, later: a billing account, if you subscribe once the beta ends. It is a separate identity from your Google account — an email address of your choosing, or a Google sign-in through a client that has no access to Gmail — and the full list of what it stores is in the privacy policy.

The third parties a message can touch

Email is not a closed system, and a client that showed you nothing from outside Google would be showing you a lot of broken messages. These are the outside connections a message can cause, and the setting that governs each:

How to check it yourself

You do not have to take this page’s word for it. An outbound firewall on your Mac shows every host an app talks to. With Hark in ordinary use you should see accounts.google.comduring sign-in and Google’s API hosts (googleapis.comand its subdomains) for mail, calendar, tasks and contacts, and Google’s image host (in practice lh3.googleusercontent.com) for contact photos. You should see updates.harkmail.app when it checks for updates, and logs.harkmail.apponly when you send a report (or, if you switched crash reports on, after a crash). With External images set to Ask, you should see no sender’s server until you ask for the pictures. If you ever see something else, we want to know: support@souplin.com.

Hark asks Google for the narrowest permission that implements each feature — for example, it does not request the permission that would allow it to delete mail permanently, so the app can only ever move a message to Trash — and its use of Google data is bound by Google’s Limited Use policy. The permissions, and what each is for, are listed on the help page.

Questions

Does Hark store my email on its servers?

No. There is no Hark server that receives, relays or stores mail, calendar, contacts or tasks. The app talks to Google directly from your Mac, and the only copy outside Google is the cache on your own disk.

Can the people who make Hark read my mail?

No — there is nothing on our side to read. The one way anything from your mailbox can reach us is if you attach a screenshot to a bug report yourself. Attach nothing, and nothing of your mail leaves your Mac. A bug report does carry the name-or-email field, pre-filled with your signed-in address, unless you clear it.

Is the local cache encrypted?

By your Mac, not by us. The cache sits in your Application Support folder, readable only by your user account, and FileVault encrypts it at rest along with everything else on the disk. Hark does not add a second layer of its own — if FileVault is off, turning it on is what protects the cache.

What happens when I sign out?

Three things: Hark tells Google to revoke its access to your account, deletes the tokens from your Keychain, and removes that account’s local cache. Signing out is not just forgetting a password; the grant at Google goes too.

Do images in emails give away that I opened them?

They can, in any client. With the default setting Hark loads a message’s remote images directly from wherever the sender put them, which shows the sender’s server your IP address and the time. Set External images to Ask before displaying in Settings › General and nothing loads until you say so.

Hark is in a private beta.

We let people in a few at a time. Leave your address and we’ll email you when there is a seat.

Join the waitlist

Or see the app — the window on the home page is the real interface, and you can change its accent and theme from the page.