Privacy
Yab is a browser for the Mac. What you do in it stays on your Mac. This page says what little leaves it, where it goes and why, and what Yab does with your Gmail and Google Calendar when you connect them.
Updated October 9, 2026
What stays on your Mac
Your tabs, history, bookmarks, downloads and settings are kept on your Mac. Passwords, cards and addresses are kept in the macOS keychain. What the agents you connect learn about you is kept as notes on your Mac, which you can read, correct or delete. Yab has no account, and no server of ours can read your browsing. If you turn on Sync, what it carries goes to your other devices encrypted end to end (Sync, below).
Sync
Sync is off until you turn it on in Settings › Sync. Then your spaces and tabs, bookmarks, settings, the last two weeks of history, passwords, cards and addresses, the notes agents keep about you, your chats with agents from the last two weeks, your routines, form answers and custom icons go to your other Macs and your iPhone. History and passwords each have their own switch under What Syncs.
- End to end encrypted. Your first device makes a key, and each record is encrypted with it before it leaves the device, under a name the server can’t read. The key never reaches our server: a new device gets it from your iCloud Keychain, from a code you type on a device already in sync, or from your Recovery Key. Passwords and cards are encrypted a second time.
- Where. A server we run on Cloudflare keeps the encrypted records until you delete them. It can’t open them. It sees how many there are, their sizes and when they change, your devices’ names and models, and, as any web host does, the network address of each connection.
- Nothing from Gmail or Google Calendar. Your mail, and anything made from it, stays on the Mac it is on: chats where mail was given or read, notes written from mail, your splits and lists, your snippets, and what a routine on your mail has done. A task you start from your iPhone gets no mail at all, since its chat goes back to the phone. Yab 0.0.13 and earlier could sync your own chats and notes about mail, encrypted end to end; newer versions don’t, and remove from the server the ones they can tell came from mail. Delete Sync Data removes everything.
- Stopping it. Settings › Sync, Turn Off Sync: on one Mac, or Delete Sync Data, which stops it everywhere and removes everything from the server. Each device keeps what it has. Remove from Sync takes a device out at once.
Gmail and Google Calendar
Mail is off until you turn it on in Settings › Mail and connect a Google account. Here is exactly what Yab does with the Google user data it gets when you do.
What Yab accesses
With your permission, Yab asks Google for two scopes, and nothing more:
gmail.modify: your messages and threads with the files they carry, their labels, your drafts, and from your Gmail settings the addresses you send from and their signatures. With it Yab changes labels (archive, mark read or unread, star, move to Trash or spam, put your labels on or take them off, and make a new label when you ask) and sends the mail you choose to send. Yab never deletes mail permanently.calendar.events.readonly: the events of your primary calendar, read only. Google’s page lets you leave the calendar out.
It also reads your Gmail address, to know which account is yours.
How Yab uses it
Only to show you your mail and your meetings, and to do what you ask with them inside Yab:
- List and sort your mail, open threads, search them, archive, snooze, label, and write and send replies. A search looks on your Mac first and asks Gmail for what your Mac doesn’t keep.
- Open, preview and save the files mail carries, and attach your own.
- Sort new mail on your Mac with Apple Intelligence, by what it wants from you, with a line about each. Notifications, shown by macOS on this Mac, say who wrote and what they want, and Yab’s icon in the Dock counts what needs you.
- Offer a one-time code a site mailed you under the box that asks for it.
- Unsubscribe when you ask: Yab sends the one-click request the list’s mail names, to the list’s own address and with no cookie or sign-in of yours, or the unsubscribe mail the list asks for, or opens its page.
- Show your next meeting beside your tabs, list your free times when you offer them in a mail, and say what an invitation overlaps. When you answer an invitation, Yab sends your answer to its organizer as a mail, as mail apps do.
Senders you block, your snippets and the lists you make are kept on your Mac, not in Gmail, and Sync leaves them out.
Who else gets it
Nobody at Yab: we have no server that receives your mail or your calendar, and Sync leaves them out. When you use features that rely on the Claude or ChatGPT account you connected to Yab yourself, the text of the mails and files involved goes to Anthropic or OpenAI, under that account, only for those features: replies written ahead and split summaries, Do It, the questions you ask about your mail, and agents reading, searching or drafting your mail. If you give Yab’s mail tools to another AI app yourself (Settings › Developers), what it reads goes to that app’s provider. Agents never send mail on their own: sending is always yours.
Connecting Claude in Yab is what turns on replies written ahead and split summaries, and each has its own switch in Settings › Mail. Let agents work on your mail, in the same place, keeps agents out of it.
A mail you send, an answer to an invitation and an unsubscribe go to whom they are for, as with any mail app. We don’t sell Google user data, use it for ads, or transfer it to anyone else.
Pictures in a mail load from wherever its sender keeps them, as in most mail apps, so the sender’s server sees your network address. Yab leaves out the tiny hidden pictures senders use to learn when you opened a mail (Settings › Mail, Block tracking pixels).
Where it is kept and how it is protected
Mail and events go from Google’s servers straight to your Mac over encrypted connections, and are kept only there, inside your user folder, protected by your macOS account and FileVault if you use it:
- A database for each account: your mail, with the text of the last 30 days, of the newest threads in each list, and of every thread you opened or found. The rest stays in Gmail until you open or find it.
- The files mail carries, once opened, and those under 10 MB from the last 30 days ahead of time: 500 MB at most for all accounts together, the ones opened longest ago going first. Each is marked as a mail attachment, so macOS asks before an app or a script from it runs.
- Files you attach to a mail, copied beside its draft until it is sent.
- If you let agents search all your mail, the text of the last five years, in a database of its own. Yab indexes it on your Mac with Apple’s models, so agents can find mail by what it says.
- Your meetings, only in Yab’s memory while it runs, and in a chat when you ask about one.
The permission Google gives Yab (its refresh token) is kept in the macOS keychain.
How Google user data is protected
- In transit: every request to Google goes over HTTPS with TLS 1.2 or newer, and macOS checks Google’s certificates. Mail’s connections keep no cookies and no web cache on disk.
- Signing in: Google’s own page asks for your permission, with OAuth 2.0 and PKCE. Yab never sees your Google password, and asks only for the two scopes above.
- Keys: the refresh token is kept in the macOS keychain on this Mac only, never synced to iCloud, and only Yab can read it. The short-lived access token Google gives for each hour is kept in memory only, never written to disk, a log or a URL.
- At rest: mail, files and events are kept in your user folder, which only your macOS account can read, and which FileVault encrypts when it is on.
- No servers: no Google user data is stored on, or passes through, any server of ours, and Sync leaves it out, encrypted or not. Yab’s logs and daily activity never include it, and crash reports are trimmed so they don’t.
- Ending access: Disconnect revokes Yab’s token at Google and deletes the account’s data on your Mac at once; if Google can’t be reached, Yab keeps asking until it can.
If you find a security problem, write to serafimcloud@gmail.com and it will be looked at first.
How long it is kept, and deleting it
It is kept on your Mac while the account is connected, and less of it as it ages: text Yab no longer keeps goes once a day, and files past the 500 MB go, the ones opened longest ago first. Turning off Let agents search all your mail deletes its database at once.
Disconnect in Settings › Mail gives back Yab’s access at Google and deletes, at once, everything Yab kept of that account on your Mac: its mail, its files, its drafts and the files attached to them, its five years of text, and its notifications. You can also remove Yab’s access at myaccount.google.com/permissions.
Yab’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is never used to develop, improve or train AI or machine learning models, by us or for us. No person at Yab reads it, unless you send it to us yourself for help, or the law requires it.
What Yab sends to us
- Updates. Yab asks yetanotherbrowser.com whether there is a newer version, and downloads it from there.
- Daily activity. Once on each day you use it, a random ID for this installation lets us count the days Yab is active, and which Store boosts people keep. Yab for iPhone sends its own ID and says it is an iPhone, so the two are counted apart. No pages, searches or browsing history. Turn it off in Settings › About, Share daily activity, on your Mac and on your iPhone.
- Crash reports. Off until you say yes. When Yab quits unexpectedly, a trimmed report of where it stopped, its version and your macOS version. Nothing from your pages, and your home folder’s name is left out. On an iPhone, the report iOS keeps of the crash (MetricKit): where it stopped and where Yab recently stopped responding, the versions of Yab and iOS and the iPhone model. Settings › About, Send crash reports.
- Feedback. What you write and attach when you send us feedback, with Yab’s version and your macOS version. Files you attach are kept at an address only we know, until you ask us to delete them.
- Read statuses. Off until you turn them on for an account in Settings › Mail. Mail you then send from it carries an invisible image from yetanotherbrowser.com, named by a random token Yab makes for that mail. Each time the image loads, the site writes down the token, when it loaded, and whether Gmail’s image proxy, Apple Mail’s privacy protection or some other app loaded it. It never gets the addresses, subject or text of the mail, and keeps no IP address or anything else about whoever opened it. Only the Yab that sent the mail can ask about it, and each record is deleted after 90 days.
These are kept in a database and file storage run for us by Vercel and Neon, and are used only to make Yab work and to make it better. Vercel, which runs the site, sees the network address of every request, as any web host does, and keeps its request logs for a day at most; our own records keep no address.
This website
yetanotherbrowser.com counts its visits and downloads as numbers: for each day, the page shown or the disk image downloaded, and where the visit came from, either a tag in the link (such as ?ref=hn) or the name of the site that linked here. It sets no cookie and keeps no address or ID, so one visit can’t be told from another. While you read, the page keeps where you came from in its own memory, so the pages you go on to and the download count under the same source; nothing is stored in your browser.
Agents and AI
When you ask Claude or ChatGPT to do something in Yab, the pages it opens and what it reads there go to Anthropic or OpenAI under your own account, as with anything else you ask them. Commands on selected text use the model you choose, on this Mac or your own plan.
Websites
The sites you visit get what any browser sends them. Yab blocks most ads and trackers, and a private tab keeps nothing after it is closed.
Children
Yab is not made for children under 13 and we don’t knowingly collect anything from them.
Changes and contact
When this page changes, the date at the top does too. Questions, or a request to delete what we hold about you: serafimcloud@gmail.com, or Send Feedback in Yab.