Good Steward. ← Back to site

Magpie App Privacy Policy

Effective August 2026 · Applies to the Magpie desktop application. For the Good Steward marketing sites, see the general Privacy Policy.

We keep this short and plain. Magpie is a personal, local-first tool — most of what you put into it stays on your own device. This page explains the few places data leaves your device, and why.

The short version

What Magpie stores, and where

Magpie’s core features save your data as ordinary files on your computer. We don’t operate a server that stores your content. This local data is not encrypted at rest by Magpie itself — it’s protected by your device’s own security (your operating-system account and any full-disk encryption you have enabled). Magpie also offers an optional backup, and if you set a passphrase for it, that backup copy is encrypted (AES-256-GCM).

Connecting a Google or Microsoft calendar (optional)

Connecting a calendar uses standard OAuth sign-in. It is not a partnership with, or an endorsement by, Google or Microsoft. Magpie requests permission only to:

That is the whole request: https://www.googleapis.com/auth/calendar.events on Google, and Calendars.ReadWrite on Microsoft Graph. Magpie asks for nothing beyond calendar events — not your email, your contacts, or your files. It uses calendar data solely to provide the in-app calendar features on your device: no advertising, no selling, no third-party transfer.

Connecting a mailbox (optional)

Magpie can read and send mail. Like the calendar, it talks to your mail provider directly from your computer — there is no Good Steward mail server in the middle, and no copy of your mailbox on our side. There are two ways to connect:

Where your mail sign-in is kept, plainly: Your Google tokens and your IMAP/SMTP app password are stored on your device, encrypted with AES-256-GCM. The key that unlocks them is held by Windows itself, tied to your Windows user account (DPAPI), rather than sitting in a file next to what it unlocks — so copying the folder to another computer, or reading it as a different user, gets nothing usable. What it does not defend against is software already running as you on your own machine, which Windows will happily unlock for. Treat it as exactly as safe as your Windows account is: use an app password rather than your main password, and revoke it in your provider’s settings if you stop using Magpie.

What mail data is kept on your device

To make search instant and the inbox quick, Magpie keeps a local cache in its data folder. This is real mailbox content living on your disk, so it is worth knowing exactly what it is:

None of it is transmitted to us or to anyone else. It is stored the same way as your notes — as ordinary files, not encrypted by Magpie, protected by your operating-system account and any full-disk encryption you have on.

Removing it

Disconnecting an account in Magpie removes its stored credentials. To remove the cached mail content as well, delete the mail folder inside Magpie’s data folder — Magpie rebuilds what it needs the next time you use it.

Uninstalling Magpie does not delete your data. That is deliberate, so an uninstall or a reinstall never destroys your notes — but it does mean the cached mail content, saved attachments and stored credentials stay on the disk until you remove that folder yourself. On Windows the data folder is %LOCALAPPDATA%\com.goodsteward.magpie. Delete it if you want Magpie gone completely.

Google and Microsoft data — Limited Use

Magpie’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In plain terms — and these apply equally to calendar data from Microsoft Graph:

Where your calendar sign-in is kept: The access token that lets Magpie talk to your calendar is stored on your device, encrypted at rest using AES-256-GCM. The encryption key is also stored locally on your device — never uploaded to or stored on any Good Steward server. You can disconnect a calendar any time from within Magpie, and from your Google or Microsoft account’s own connected-apps settings.

The optional AI features

A few Magpie features can use an AI model — rewriting or summarising text you have selected in a note, for example. They stay switched off until you enter your own AI provider key. Magpie ships with no shared or bundled key, so out of the box nothing is sent anywhere.

When you have set a key and use one of those features, the specific text you asked Magpie to work on is sent from your computer to the provider you configured, over an encrypted connection, solely to produce that result, and is governed by that provider’s own terms. Your key is stored on your device and is never sent to us.

Your calendar and your email are not part of this. Magpie does not send Google or Microsoft account data, or the contents of your mailbox, to any AI provider.

What we don’t do

Getting help

Support is handled in the open, through public GitHub Issues on the magpie-releases project. There is no support email and no guaranteed response time — it’s community, as-is support, not a service-level agreement.

Children

Magpie is not directed to children under 13, and we don’t knowingly collect their information.

Changes

If we update this policy, we’ll change the effective date above and note material changes before they take effect. If a future version of Magpie asks for additional Google or Microsoft permissions, this page will describe them before that version ships.

Questions or data requests: use GitHub Issues on magpie-releases, or the contact form on any Good Steward site.

This page describes our actual practices in plain language; it isn’t legal advice.