{"id":16501,"date":"2016-12-01T14:48:51","date_gmt":"2016-12-01T19:48:51","guid":{"rendered":"http:\/\/mjtsai.com\/blog\/?p=16501"},"modified":"2018-01-03T18:52:18","modified_gmt":"2018-01-03T23:52:18","slug":"spark-mail-stores-credentials-in-cloud","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2016\/12\/01\/spark-mail-stores-credentials-in-cloud\/","title":{"rendered":"Spark Mail Stores Credentials in Cloud"},"content":{"rendered":"<p><a href=\"https:\/\/sparkmailapp.com\/features\">Readdle<\/a>:<\/p>\n<blockquote cite=\"https:\/\/sparkmailapp.com\/features\"><p>Spark is much more than a mailbox. It&rsquo;s a smart, unified inbox which collects all of your emails and automatically categorizes them for easy processing.<\/p><\/blockquote>\n<p><a href=\"https:\/\/twitter.com\/olebegemann\/status\/804295125753069568\">Ole Begemann<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/olebegemann\/status\/804295125753069568\">\n<p>While everyone&rsquo;s raving about @sparkmailapp, remember that they store the credentials to your email(!) on their servers.<\/p>\n<\/blockquote>\n<p>Readdle&rsquo;s <a href=\"https:\/\/sparkmailapp.com\/privacy\">privacy policy<\/a>:<\/p>\n<blockquote cite=\"https:\/\/sparkmailapp.com\/privacy\"><p>In the event you delete your data from Spark, or revoke access to your data, or delete your Spark account, all your data, as well as your authentication\/password information, is completely and permanently deleted from our servers, and we, therefore, do not have access to any of your data anymore.<\/p><\/blockquote>\n<p><a href=\"https:\/\/twitter.com\/SparkMailApp\/status\/804384212631617536\">@SparkMailApp<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/SparkMailApp\/status\/804384212631617536\"><p>Credentials are stored in encrypted form on Amazon server. There&rsquo;s no way to access them in the original form<\/p><\/blockquote>\n<p>Presumably, whatever they&rsquo;re storing is enough to <a href=\"https:\/\/readdle.com\/blog\/2015\/06\/how-we-handle-your-account-information-in-spark\/\">access your mail<\/a>. Otherwise, what would be the point? This is a concern, not only because of privacy, but also because access to your e-mail account can (through password resets, in the absence of two-factor authentication) unlock all of your other accounts.<\/p>\n<p>My guess is that the main reason Readdle wants their server (rather than just the app running on your phone) to be able to access your mail account is for push notifications. My understanding is that Apple&rsquo;s Mail app gets special privileges to run in the background and use <a href=\"https:\/\/en.wikipedia.org\/wiki\/Push_email\">push<\/a> to detect when the IMAP or Exchange server has new messages. It also does background polling.<\/p>\n<p>Third-party iOS apps are not allowed to do either of these things, just as they cannot register for the <a href=\"http:\/\/mjtsai.com\/blog\/2016\/11\/27\/choosing-ios-default-apps\/\">mailto: protocol<\/a>. However, if Readdle&rsquo;s server can monitor the mail account for new messages, it can send an Apple Push Notification to wake up the iOS app. Alternatively, you can <a href=\"https:\/\/twitter.com\/kuba_suder\/status\/804310036407320576\">turn off<\/a> this feature. However, then you would not get background notifications of new mail, and it would probably use more battery power in the foreground.<\/p>\n<p>Previously: <a href=\"http:\/\/mjtsai.com\/blog\/2015\/07\/20\/fastmail-enables-imap-push-for-ios\/\">FastMail Enables IMAP Push for iOS<\/a>.<\/p>\n\n<p>Update (2018-01-03): See also: <a href=\"https:\/\/www.reddit.com\/r\/privacy\/comments\/5grsan\/do_not_use_the_spark_email_client_by_readdle\/\">Reddit<\/a> (via <a href=\"https:\/\/twitter.com\/DocterD\/status\/948687891886034949\">Dennis<\/a>).<\/p>","protected":false},"excerpt":{"rendered":"<p>Readdle: Spark is much more than a mailbox. It&rsquo;s a smart, unified inbox which collects all of your emails and automatically categorizes them for easy processing. Ole Begemann: While everyone&rsquo;s raving about @sparkmailapp, remember that they store the credentials to your email(!) on their servers. Readdle&rsquo;s privacy policy: In the event you delete your data [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"","apple_news_api_id":"","apple_news_api_modified_at":"","apple_news_api_revision":"","apple_news_api_share_url":"","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[91,28,150,14,424,31,1380,772,597,355,1074,1445,48],"class_list":["post-16501","post","type-post","status-publish","format-standard","hentry","category-technology","tag-appstore","tag-batterylife","tag-email","tag-emailclient","tag-imap","tag-ios","tag-ios-10","tag-ios-multitasking","tag-mobilemail","tag-privacy","tag-push-notifications","tag-readdle-spark","tag-security"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/16501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=16501"}],"version-history":[{"count":5,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/16501\/revisions"}],"predecessor-version":[{"id":20055,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/16501\/revisions\/20055"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=16501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=16501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=16501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}