Privacy
Last checked against the app on 2026-10-11.
Junto is a mail, contacts and calendar app that runs on your Mac. It is made by Katapult Labs (KATAPULT INC). In short: your data stays on your Mac. Junto has no server of its own, and nothing you read or write in Junto is sent to Katapult Labs.
What Junto accesses
Only the accounts you connect, and only to show them to you and to carry out what you do in the app.
Google accounts
When you sign in with Google, you are asked to allow:
- Gmail (read, compose, send and modify): to copy your messages, labels and drafts to your Mac; to apply what you do (archive, mark read, star, snooze, move to trash); to save your drafts; and to send the messages you send.
- Google Contacts (see, edit and download): to show your contacts in People and to save edits you make back to them.
- Google Calendar (your list of calendars, read-only; and your events): to show your calendars and to save the events you create, change or answer.
- Your email address: to know which account you signed in with.
Other sources you can connect
- iCloud Contacts, with your Apple ID and an app-specific password you create for Junto.
- The Contacts app on your Mac, after macOS asks for your permission.
Where your data is kept
- Mail, contacts, calendar events, your settings and a history of the changes made in the app are stored in a database on your Mac, in
~/Library/Application Support/junto. Attachments are downloaded only when you open or save one, into a cache in the same folder. - Sign-ins (Google access tokens) and passwords (iCloud app-specific passwords) are kept in your Mac's Keychain, never in a file.
- The app writes operational logs (sync status and errors, which can name your accounts) on your Mac. They are not sent anywhere.
Where your data goes
- Only to the services you connect, directly from your Mac: Google's Gmail, People and Calendar APIs and Google sign-in for Google accounts; Apple's iCloud contacts server for iCloud.
- Not to Katapult Labs. Junto has no analytics, no crash reporting, no advertising and no tracking, and it requires no account with us. We never see your mail, contacts or calendars, and we don't sell or share them.
- Updates. Released versions of Junto check for a new version at launch and once a day by downloading a small file from GitHub, where Junto's releases are published. Like any download, that request reveals your IP address to GitHub; it carries nothing about your mail or accounts. You can turn it off in
config.toml(check_for_updates = false). - Pictures in email. By default Junto does not load images from the web inside messages, so opening an email doesn't tell its sender that you read it. If you ask it to show them (for one message, or always for a sender you choose), your Mac downloads them from wherever the sender put them, which lets that server see your IP address and that the message was opened. Links you click open in your browser.
Agents and the command line
Junto includes a command-line tool, jt, that reads and changes the same data on your Mac, so that you can let scripts or AI agents of your choosing work on your mailbox. They run under your control: what such a tool does with your data is up to it and to you, not to Junto. Everything they change through Junto is recorded in Activity, where you can review or undo it.
Google user data
Junto's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide Junto's features to you, on your Mac; it is not transferred to Katapult Labs or anyone else, not used for advertising, and not read by people.
Removing your data
- Removing an account in Junto's Settings stops syncing it, deletes the mail, contacts and events it brought to your Mac, and deletes its saved sign-in or password from the Keychain. The history of past actions in Activity is kept.
- To remove everything, quit Junto and delete
~/Library/Application Support/juntoand the Keychain items namedjunto. - You can revoke Junto's access to your Google account at any time at myaccount.google.com/permissions.
Contact
Questions about this policy: junto@katapultlabs.ai.