It might not be required for applications that run locally, but they don't tell you whether or not it will be required until after you've already done the work to create the app.
The exact wording from the FAQ is:
"Local Data Storage: Local client applications don't need to undergo a security assessment because data is run, stored, and processed only on the user's device. Local client applications that only allow user- configured transmissions of Restricted Scope data from the device may be exempt from this requirement."
Keep in mind that any email client that allows you to reply to (or forward) an email would count as transmitting restricted scope data from the user's device.