Privacy Policy
This policy covers maniTLab.org and desktop software published by Manish Jagdish Thatte under the maniTLab name — including correspondence clients that connect to email and calendar providers such as Google and Microsoft.
Who is responsible
Manish Jagdish Thatte, Nashik, Maharashtra, India. Contact: manish@manitlab.org.
The website (maniTLab.org)
The site is a static publication. It does not require an account, does not sell advertising, and sets no cookies. It is hosted by Cloudflare, and its source is kept in a private repository on GitHub. As of 30 August 2026 the only other company involved in running it is Migadu, which carries the mail. There is no third-party analytics vendor, no mailing-list vendor and no form vendor: the measurement described below is Cloudflare's own, and Cloudflare is already the host.
The visitor number in the footer. It is counted by this site's own code. When a page asks for the count, the server derives a short one-way hash of your IP address, your browser's user-agent string, the date, and a secret it keeps to itself. That hash is stored for the day so you are counted once rather than once per page, and rows from earlier days are deleted; it cannot be turned back into an IP address, and because the date is part of it, one day's hash cannot be matched to another's. No cookie is set. If the request fails or you block it, the footer simply shows no number.
Page measurement. Since 1 September 2026 each page loads Cloudflare Web
Analytics, a small script served from
static.cloudflareinsights.com that reports page-load timing and the URL
visited back to Cloudflare. It is cookieless, it sets no identifier of any kind, and it
does not follow you to other websites — there is no profile and nothing to opt out of
beyond blocking the script, which nothing on the site depends on. Cloudflare is the
host, so this adds no new company; it replaced a self-hosted counter that was removed on
30 August 2026. It is used to see which pages are read and how quickly they load.
Server logs. Cloudflare records request metadata for the site in the ordinary course of serving it, and shows it to Manish Jagdish Thatte in aggregate — counts of requests, paths and countries. That is a by-product of hosting rather than anything placed on the page, and unlike the measurement script above it involves no code running in your browser.
The contact form. The name, email address, subject and message you type are stored in this site's own database and emailed to manish@manitlab.org, so a reply is possible. That content is used only to answer the enquiry, and it is never used for a mailing list — there is no mailing list. The form is protected by Cloudflare Turnstile, which checks that a browser rather than a script is submitting it and which, unlike a CAPTCHA, does not profile you or ask you to label photographs.
Desktop software and mail / calendar access
Some software published under this name — including the corMani correspondence client — can connect to your email and calendar accounts when you add them. Access is by OAuth (or, where a provider still allows it, an app password you create yourself).
- What is accessed. Mailboxes, folders, message content and flags; calendar events where you grant calendar scopes; and the identity of the account you signed in with.
- Where it is stored. On the computer where you run the application. OAuth tokens and passwords are kept in the operating system keyring on that machine. Mail and calendar data are kept in a local database on that machine.
- What is not done. Mail and calendar content are not uploaded to maniTLab servers. There is no cloud copy operated by Manish Jagdish Thatte. Data are not sold, rented, or used for advertising.
- Who can see it. You, on your machine. Provider APIs (Google, Microsoft, or an IMAP/SMTP host you name) see the traffic they already handle for any mail client. Nobody else receives a feed of your messages from this software.
- Revoking access. Remove the account inside the application, and revoke the app at the provider (for Google: Google Account → Third-party access). Deleting the local store removes the cached mail on that computer.
Google user data
When you authorise Google access, the application uses Google user data only to provide the mail and calendar features you asked for on that device — reading and sending mail, listing folders, and reading or writing calendar events you choose to sync. Use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Google user data are not transferred to other apps, are not used for serving advertisements, and are not used for creditworthiness or lending decisions.
Children
The site and the software are not directed at children under 13, and no personal information is knowingly collected from them.
Changes
If this policy changes, the new text will be posted at this URL with an updated effective date. Material changes that affect how mail or calendar data are handled will be described in the software release notes as well.
Contact
Privacy questions: manish@manitlab.org. See also the Terms of Service.