Privacy Policy
Mail Toolbox for Gmail™
Privacy Policy — Mail Toolbox for Gmail™
Last updated: 19 August 2026
Public copy: https://mailtoolbox.xeviora.com/privacy Contact: privacy@xeviora.com
The short version
Exporting a conversation, taking notes and counting unread mail all happen inside your browser. None of that reaches us.
The AI features are different, and we want to be plain about it: they are switched off until you sign in and press a button, and when you do, the text of that one conversation is sent to our server and on to our AI provider so it can be processed. We do not store the message text after the response is returned, and we do not use it to train any model.
What the extension reads
The extension runs only on the mail site it supports. When you ask it to export, summarize or annotate a conversation, it reads that conversation the way your browser already can — through the mail service's own printable view of the thread, and through the unread feed the site publishes to your signed-in session.
It does not use the mail provider's developer API and never asks you to authorize an application against your account. There is no OAuth screen, no access token, and nothing for you to revoke afterwards. It reads the page you have open, using the session you are already signed in to.
It does not read pages on any other website.
Permissions and why they are needed
| Permission | Why |
|---|---|
storage |
Keeps your own settings (page size, filename template, which formats a batch export produces, notification interval and labels) and your notes, in your browser's local extension storage. |
unlimitedStorage |
Notes and cached conversation text for a heavy mailbox can exceed Chrome's default 5 MB extension-storage quota. This permission removes that cap; it does not widen what the extension can read. |
alarms |
Schedules the periodic unread check at the interval you set. Without it the count would only update while a mail tab is focused. |
notifications |
Shows the desktop alert for new unread mail, and only if you turn that feature on. |
contextMenus |
Adds the right-click entry that exports or summarizes the conversation under the cursor. |
https://mail.google.com/* |
The only site the extension runs on. Needed to place its controls in the interface and to read the conversation you act on. |
https://mailtoolbox.xeviora.com/* |
Our own server. Used to check whether you are signed in and to run AI requests. Because this host is listed, Chrome attaches our own site's session cookie to those requests, which is why the extension itself stores no credentials of any kind. |
That is the complete list. The development build additionally lists http://localhost:3002/* so the extension can talk to a local server; the published build strips it, and it is not present in the package you install from the Chrome Web Store.
AI features
AI is opt-in twice over: the feature is off until you enable it, and each run needs you to click. When you run one, the text of that single conversation travels over HTTPS to our server, which forwards it to our AI provider, receives the result and returns it to you. We keep run metadata (which task, when, how much it cost you in credits) for 90 days for troubleshooting and billing accuracy. We do not keep the message text, and neither we nor our provider use it to train models.
If you never sign in, no email content ever leaves your browser.
Notes
Notes live in your browser's local extension storage and stay on that device on the Free plan. On paid plans you can turn on cloud sync, which stores your note text on our server so it appears on your other devices. Sync is off unless you enable it, and deleting a note deletes it from both places.
Account data
You only have an account if you create one. If you do, we store your email address and either a hashed password or the identifier from the provider you signed in with. Payment is handled by our payment processor; we never see or store your card details.
Cookies
One cookie: your login session on our own site, scoped to that site only. No advertising cookies, no cross-site tracking, no third-party analytics inside the extension.
Who else is involved
Vercel (hosting), Neon (database), OpenRouter and the model providers it routes to (AI processing), and Paddle (payments). Each receives only what it needs to do its job, and none of them receives your email content except the AI provider handling a run you started.
How long we keep things
Account data is kept while your account exists. AI run metadata is kept for 90 days, then deleted. Deleting your account deletes your account data and any synced notes.
Your rights
You can access, export or delete your account data at any time from your account page, or by writing to us. If you are in the EEA or UK you have the rights granted by the GDPR, including access, rectification, erasure and portability.
Changes
If this policy changes materially we will update the date above and note the change on the page linked at the top.