Privacy policy
The short version. Exora connects your PC to your mail server and nothing else. There is no Exora account and no service in between, so your messages, calendars and contacts never reach us. Diagnostics are off until you turn them on, and even then they never contain message content.
Your mail
Exora is a mail client, not a mail service. It talks directly to the servers you configure — your organisation's Exchange server, Microsoft 365, Gmail, or any IMAP/SMTP host. Messages, calendar events, contacts, tasks and attachments are stored locally on your device and are never transmitted to us or to any third party.
Your credentials are stored on your device and encrypted at rest using Windows data protection. Where your server supports OAuth, Exora holds a token rather than your password.
Remote images and tracking pixels in messages are blocked until you choose to load them, so simply reading a message does not tell the sender that you read it.
Diagnostics
Exora can send diagnostic reports to help find and fix faults. This is off by default. Nothing is sent unless you switch it on in Settings › About, and switching it off stops it immediately.
What a report contains when diagnostics are on
| Included | Why |
|---|---|
| Error message, exception type and stack trace | The fault itself — without it there is nothing to fix |
| The last few log lines before the fault | What the app was doing when it went wrong |
| App version, release channel, build, and app edition | Tells us which build to reproduce against |
| Windows version | Many faults are specific to one Windows build |
| Your mail server's address and reported version | Where the diagnostic value concentrates. Exchange version, hybrid setups, proxy and certificate faults are all specific to a particular server |
| The domain part of your email address |
Lets several reports from one organisation be recognised as related. The part
before the @ is removed first, so you@example.com is
recorded as <user>@example.com
|
| A random installation identifier | Groups reports from the same installation. It is generated on your device, is not derived from anything about you, and is not linked to any account |
| A once-a-day heartbeat | Tells us roughly how many installations are on each version, so we know when an old build can stop being supported |
What is never included
- Message content, previews, or subject lines
- Attachments, or any message identifiers that could be used to fetch one
- Contact names, calendar entries, or folder contents
- Passwords, tokens, or any credential
- File paths from your PC, which would carry your Windows username
- Your full email address — the part identifying you is removed before the report is stored
This removal happens on your device, before a report is written to disk, so a report waiting to be sent is already stripped. If the connection to us fails, the report simply stays on your machine and is discarded after a few days.
Sending logs manually
Settings › About also has a button that sends your local log files to us. This is a separate, deliberate action: it asks for confirmation each time and works regardless of the diagnostics setting, because you are choosing to send it right then.
Unlike the automatic reports, this archive is not stripped — it is the raw log, which is what makes it useful when a report alone has not been enough. It contains your account addresses, your mail server address, and folder names. It does not contain message content or your password. Only send it if you are comfortable with that, and only when troubleshooting something with us.
How long we keep it
Diagnostic reports are deleted after 90 days. Manually uploaded log archives are deleted after 30 days. Neither is sold, shared, used for advertising, or combined with anything else — there is no advertising business here to feed.
This website
This site sets no cookies, runs no scripts, and loads nothing from third parties — no analytics, no fonts, no trackers, no content delivery networks. Nothing here follows you.
Like any web server, it records requests in a log — the address of the requesting machine, the page requested, and the time — which is used to keep the site running and to spot abuse.
Children
Exora is a business productivity tool and is not directed at children. We do not knowingly collect information from anyone under 13.
Changes
If what Exora collects ever changes, this page changes with it, and the wording inside the app changes at the same time. The date at the top tells you when it last did.
Contact
Questions about this policy, or a request to delete diagnostic data associated with your installation identifier: privacy@exora.email.